Adform Script Swapped Crypto Wallet Addresses on Websites

Brendan Smith
Brendan Smith - Cybersecurity Analyst
7 Min Read
Adform page script changing a copied cryptocurrency wallet address before transfer confirmation.
The compromised Adform tracking script could replace Bitcoin, Ethereum, or Tron recipient addresses while an affected page was open.

A compromised Adform tracking script could replace Bitcoin, Ethereum, and Tron wallet addresses while a website page was open. Adform says it detected and removed the malicious code on July 27, 2026. The company found no evidence that it installed software or persisted after the page closed. Anyone who used cryptocurrency on an affected page should clear the browser cache and verify the destination recorded in every transfer made on or after July 27 until that cache was cleared.

The incident matters because a visitor did not need to install a wallet app, browser extension, or executable. A website that loaded the affected Adform resource could run the altered JavaScript in the visitor’s browser as part of its normal page code.

What happened to the Adform script

Security researcher Kevin Beaumont identified malicious code in trackpoint-async.js, a shared tracking resource served from s2.adform.net. The code looked for wallet-address formats used by Bitcoin, Ethereum, and Tron and replaced a matching address with one controlled by the attacker. The captured sample could act on copied text and addresses shown or entered on a page, so copying the same destination again was not a reliable fix while the page remained open.

Adform’s official notice says the company contained the incident, removed the code, notified affected clients, and reported the event to authorities. Its investigation is still open. Adform has not published a complete list of affected websites, the number of exposed visitors, how the deployment path was compromised, whether any transfer was diverted, or who operated the attack.

The data-transmission boundary is also unresolved. Adform says it found no evidence that visitors’ IP addresses or page information were transmitted, although its technical analysis indicates that transmission may have been possible. That possibility should not be reported as confirmed theft of browsing data.

Were you affected?

What you did Risk and next step
Opened a site using the affected Adform code The page could have loaded the altered script, but Adform did not find an installed payload or persistence. Close affected tabs and clear the browser cache.
Copied or entered a crypto address but did not send No blockchain transfer occurred. Clear the cache, reopen the payment flow from a trusted source, and compare the full recipient address again.
Sent Bitcoin, Ethereum, or Tron while the page was open Open the completed transaction in your wallet or a trusted explorer and compare the actual destination with the recipient’s full address.
The recorded destination is wrong Save the transaction ID, destination, amount, time, page, and screenshots. Contact any identifiable receiving exchange or service immediately and report the incident through the appropriate authority.
Downloaded or ran a file Adform did not describe file delivery as part of this incident. Treat that download as a separate exposure and investigate its source and device impact.

Why checking before copy was not enough

A wallet password or seed phrase was not required to redirect a payment. The malicious code changed the destination presented to the user before approval. The address on the final confirmation screen and the destination recorded after broadcast are therefore the important values—not only the text that looked correct before it was copied.

Compare the entire destination, including middle characters, against the recipient’s trusted receive screen or a verified address-book entry. The Gridinsoft guide to verifying a crypto wallet before sending money explains why a familiar beginning and ending are not enough.

This incident also differs from a locally installed clipper. Silent Swap used a forced browser extension that could remain on the computer; Adform says its altered code worked only while an affected page was open. Do not assume that opening an affected page exposed passwords or seed words, and do not rotate a seed phrase solely for that reason.

What to do now

  1. Close affected pages and clear browser cache. Adform specifically recommends clearing cached website code. Clearing only cookies is not the same action.
  2. Review relevant transfers. Check Bitcoin, Ethereum, and Tron transactions made on or after July 27 until the cache was cleared. Compare the full on-chain destination, not a shortened history label.
  3. Stop if the address changes. Do not retry from the same open page. Reopen the recipient’s trusted source in a fresh session and verify the destination on another trusted screen when practical.
  4. Escalate a wrong transfer quickly. Preserve the transaction ID and contact an identifiable exchange or service that controls the recipient address. Blockchain transfers usually cannot be reversed, and anyone promising guaranteed recovery for an upfront fee may be running a second scam.
  5. For website owners, follow Adform’s client notice. Clear relevant site or delivery caches, preserve logs, confirm that the current resource is clean, and assess whether visitors need a dated notification.

If funds went to an unexpected address, use the broader online-scam evidence and reporting checklist. A malware scan is not a substitute for transaction review in this case because the confirmed Adform behavior was browser-side and temporary.

References

  1. Adform. “Security Incident — Company Update.” Adform, published July 31, 2026, accessed August 1, 2026. official incident notice.
  2. Kevin Beaumont. “Adform Compromised to Serve Crypto Stealer via Supply Chain Attack.” DoublePulsar, published July 31, 2026. primary technical analysis.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?