Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Overview
On July 27, 2026, cybercriminals compromised a JavaScript file used by Adform, an advertising technology company, to alter cryptocurrency wallet addresses on customer websites. This malicious code could redirect users' copied Bitcoin wallet addresses to the attackers' wallets, potentially resulting in significant financial losses for affected users. Adform quickly identified the breach, removed the harmful script, and informed its clients about the incident. They also reported the attack to relevant authorities. This incident raises concerns about the security of third-party scripts and the potential for similar attacks that target users' financial transactions online.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Adform JavaScript, cryptocurrency wallet addresses
- Action Required: Adform removed the malicious code and notified affected clients.
- Timeline: Disclosed on July 27, 2026
Original Article Summary
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin,
Impact
Adform JavaScript, cryptocurrency wallet addresses
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on July 27, 2026
Remediation
Adform removed the malicious code and notified affected clients.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.