Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Adform Script to Alter Crypto Wallets

Hackers Exploit Adform Script to Alter Crypto Wallets

Posted on August 1, 2026 By CWS

Security Breach in Adform’s JavaScript

On July 27, 2026, Adform, a prominent advertising technology company, encountered a significant security breach involving one of its JavaScript files. The attackers managed to alter the script, turning it into a tool capable of modifying cryptocurrency wallet addresses on websites using the affected code. This incident highlights the vulnerabilities in digital advertising networks.

Immediate Response and Notifications

Adform promptly reacted to the breach by removing the malicious code and notifying its clients. The company also reported the incident to relevant authorities. Users who accessed websites with the compromised script on the affected day risked inadvertently copying altered Bitcoin, Ethereum, or Tron wallet addresses. Adform advised users to clear their browser cache and verify wallet addresses before executing any transactions.

The altered script was designed purely for rewriting wallet addresses and did not install additional software or persist beyond an open browser session. Affected interactions included direct input into form fields, not just clipboard copying. This broadens the potential impact of the attack significantly.

Technical Details of the Attack

The malicious script, identified as trackpoint-async.js, was distributed from Adform’s s2.adform[.]net. The breach allowed attackers to infiltrate multiple sites without compromising each individually, marking it as a classic supply-chain attack. The script’s ability to operate across various sections of websites amplified its reach.

Security researcher Kevin Beaumont noted ongoing suspicious activity associated with Adform over the preceding week, although Adform’s public timeline specified July 27 as the key date. The script’s malicious components included obfuscated code blocks that monitored clipboard events and attempted to replace cryptocurrency addresses with rogue ones. The script also engaged in HTTP requests to a specific IP address, though it remains unclear if this data reached the attackers.

Ongoing Investigation and Impact

Despite Adform’s efforts, many questions remain unanswered, such as the number of websites that hosted the compromised script, visitor exposure, and the method used by attackers to breach Adform’s systems. Additionally, no evidence has been found of IP address transmission or detailed visitor tracking, although the technical possibility existed.

Adform’s 2025 report indicated the company served 1.5 billion ads daily across 180 countries. However, specific figures regarding the breach’s reach or financial losses remain undisclosed. The lack of conclusive data on the attack’s scope challenges efforts to gauge user exposure accurately.

While Adform has not identified the perpetrators, the incident underscores the critical need for robust security measures in digital advertising frameworks to prevent similar breaches in the future.

The Hacker News Tags:Adform, browser security, crypto wallets, Cryptocurrency, Cybersecurity, data breach, digital security, hacking news, incident response, JavaScript, Malware, online privacy, supply chain attack, Technology, web security

Post navigation

Previous Post: Hotel Wi-Fi Exploited to Distribute Surveillance Trojan
Next Post: Critical Ruby on Rails Vulnerability Patched

Related Posts

Managing Shadow AI Tools Efficiently in the Workplace Managing Shadow AI Tools Efficiently in the Workplace The Hacker News
Critical PHP Composer Vulnerabilities Patched Critical PHP Composer Vulnerabilities Patched The Hacker News
How to Detect Phishing Attacks Faster: Tycoon2FA Example How to Detect Phishing Attacks Faster: Tycoon2FA Example The Hacker News
CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users The Hacker News
Enhancing Incident Response: Key Operational Essentials Enhancing Incident Response: Key Operational Essentials The Hacker News
Security Flaws in AI Tool Pose Major Risks Security Flaws in AI Tool Pose Major Risks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations
  • Hackers Target VMware vCenter Flaw for Remote Access
  • North Korean Hackers Exploit Fresh Windows Vulnerability
  • LiteLLM Malicious Releases Impact Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations
  • Hackers Target VMware vCenter Flaw for Remote Access
  • North Korean Hackers Exploit Fresh Windows Vulnerability
  • LiteLLM Malicious Releases Impact Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark