
Adform, a Denmark-based advertising technology company, confirmed that attackers altered a JavaScript file distributed through its platform, turning it into a tool that substituted visitors’ cryptocurrency wallet addresses with one controlled by an outside party. The company said it detected the intrusion on July 27, 2026, stripped out the malicious code and alerted the clients whose sites had carried it.
Adform operates a full-stack advertising system spanning demand-side and supply-side platforms, ad servers and campaign management tools, and its 2025 annual report states the company counted roughly 1,800 customers and helped display 1.5 billion ads a day across more than 180 countries last year.
The tampered file, trackpoint-async.js, is loaded from Adform’s own domain and can be set to run on a single page, across select sections of a site, or sitewide, according to the company’s implementation documentation. Because so many unrelated websites pull the same script from Adform’s servers, a single alteration there gave the intruders reach into those sites without needing to breach any of them directly.
Independent security researcher Kevin Beaumont identified the tampering and published his findings, stating that the injected code monitored visitors’ clipboards and swapped in a substitute address whenever it detected a pattern matching a Bitcoin, Ethereum or Tron wallet. Beaumont wrote that the substitution was persistent, saying, "Even if you notice the address is wrong and recopy the wallet, it keeps replacing it." He also reported that neither the file nor the domains and IP address tied to it triggered any detections when checked against VirusTotal. A separate captured copy of the script was published by Max Maass on July 27.
A review of a captured sample found two malicious segments appended to the legitimate script, with their replacement text scrambled using a six-byte XOR cipher. One segment watched for clipboard copy actions, checked clipboard contents roughly every four seconds and replaced any matching wallet address. That segment also attempted to send the visitor’s hostname and page path to an outside server at the IP address 84.32.102[.]230 on port 7744 each time a page loaded.
The second segment scanned the page’s text content directly, altering wallet addresses inside input fields, text boxes and editable page elements, then repositioning the cursor so the change would not be obvious. It also intercepted copy, cut, paste and typing actions, and it hooked into the underlying code that handles text entry so that even addresses inserted by other scripts on the page would be rewritten. Both segments carried hardcoded substitute addresses for the three cryptocurrencies, and Beaumont said those substitute addresses appeared to change over time.
Adform’s account of the incident says the company has not found evidence that the code sent visitors’ IP addresses or browsing details off the page, though it added in its notice that "technical analysis indicates that such transmission may have been possible." The company also said the code showed no signs of being built to install additional software on a visitor’s device or to persist beyond the time an affected page stayed open.
Adform is advising anyone who visited a site carrying the affected script on July 27 to clear their browser cache, since the altered file could still be stored locally even after the company’s fix, and to double check any cryptocurrency wallet address before completing a transfer.
Adform said it has notified affected clients directly with further guidance and reported the incident to authorities. The company has not disclosed how many websites carried the tampered script, how many visitors were exposed, how its systems were initially compromised, whether any funds were diverted, or who was behind the intrusion. Its public incident notice does not include technical indicators of compromise.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543