TechNewsReel
Live

Adform Supply Chain Attack Swaps Crypto Wallet Addresses on Customer Sites

Attackers compromised a shared JavaScript file to divert Bitcoin, Ethereum, and Tron payments to malicious wallets.

TechNewsReel Newsroom · August 1, 2026

Advertising technology firm Adform recently neutralized a supply-chain attack that weaponized a shared JavaScript file to steal cryptocurrency from unsuspecting users. The incident underscores the precarious nature of third-party script dependencies, as a single compromise at the provider level can propagate malicious code across thousands of downstream websites.

Attackers compromised a specific file named 'trackpoint-async.js' served by Adform. The modified script functioned as a browser-side tool designed to identify and replace legitimate cryptocurrency wallet addresses with those controlled by the attackers. Specifically, the malicious code targeted Bitcoin, Ethereum, and Tron addresses. The script rewrote these addresses in real-time, whether the user typed them directly into form fields or copied them to the clipboard.

The Mechanics of the Breach

Adform integrates scripts into numerous third-party websites to manage advertising operations. By poisoning this shared resource, attackers executed a supply-chain maneuver, turning Adform's infrastructure into a delivery mechanism for the malware. Any user visiting a customer site that loaded the compromised script was potentially exposed to the address-swapping logic.

Industry Implications

This attack is particularly dangerous because it manipulated the user interface at the point of transaction. Because the swap happened instantly within the browser, users had no visual indication that the destination address had been altered. Given that cryptocurrency transactions are irreversible, such a silent redirection leads to the total loss of funds. Adform stated that the code operated only while the active page was open and did not establish long-term persistence on the user's device, though the immediate financial impact remains severe.

Current Status

Adform detected the incident on July 27, 2026, and has since removed the malicious code from its servers. The company has notified affected clients and reported the event to the relevant authorities. Security researchers continue to monitor for similar patterns of script poisoning as attackers increasingly target the trust relationship between web publishers and their third-party service providers.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.