The record
Written from the 1 report below. Nothing here is unsourced.
- Attackers compromised a JavaScript file served by ad-tech company Adform, turning it into a tool that rewrote Bitcoin, Ethereum, and Tron wallet addresses copied or typed by visitors on websites using the script.
- Adform detected the incident on July 27, 2026, removed the malicious code, notified clients, and reported it to authorities, telling people to clear their browser cache and verify wallet addresses before sending funds.
- Because the file was a shared tracking resource deployed across many customer sites, the incident is a supply-chain compromise that could affect visitors on downstream sites Adform does not directly control.
- Key details remain unknown, including how many sites and visitors were exposed, how attackers got in, whether any funds were diverted, and how long the attack actually ran, since a researcher reported malicious activity over the past week while Adform cites only July 27.
What to watch next
- How many websites and visitors actually received the altered file, a count Adform has not published.
- Whether Adform reconciles the July 27 affected date with the researcher's claim of roughly a week of malicious activity.
- Publication of indicators of compromise and any findings on how attackers reached Adform's deployment path or whether funds were diverted.
Coverage1
1 report
English national1
All filed from India
Named India · Bitcoin · Ethereum · Tron · Adform · Kevin Beaumont · Max Maass
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
