CybersecurityAugust 1, 2026· via The Hacker News

Hackers hijack Adform ad script to steal crypto wallet addresses

Hackers hijack Adform ad script to steal crypto wallet addresses

Image : The Hacker News

A malicious JavaScript file distributed by advertising technology provider Adform was altered to replace cryptocurrency wallet addresses on customer websites, enabling attackers to divert payments to their own accounts. The company detected the incident on July 27, 2026, removed the compromised code, and alerted affected clients while reporting the breach to authorities. Anyone who copied a Bitcoin, Ethereum, or other wallet address on a site using the tainted script that day may have unwittingly sent funds to the wrong destination.

The attack underscores the risks of third-party code in digital advertising, where a single compromised library can cascade across thousands of websites. Adform, which serves ads on major publisher sites, confirmed the incident affected its global script distribution network. While the full scope of compromised transactions remains unclear, security researchers warn that similar supply-chain attacks have previously netted attackers millions in stolen cryptocurrency.

A familiar but evolving threat

Supply-chain attacks on ad tech are not new, but the method grows more sophisticated as attackers target widely used JavaScript libraries. By injecting malicious code into a legitimate ad script, hackers bypass traditional website defenses that focus on individual domains. The incident follows a pattern seen in past malvertising campaigns, where compromised ad servers delivered malware or phishing pages to unsuspecting users.

What changed this time

Unlike prior attacks that relied on fake ads or redirects, this campaign weaponized a core component of Adform’s infrastructure. The attackers did not need to breach each customer site individually; instead, they altered the script at the source, affecting every site loading it. Such an approach maximizes reach and minimizes detection, making it a potent tool for financially motivated cybercriminals.

Why it matters

This incident reveals how fragile the digital ad ecosystem remains, where a single compromised script can turn thousands of websites into unwitting accomplices in theft. For businesses relying on third-party ad tech, the attack is a reminder to audit supply-chain dependencies and implement runtime integrity checks on externally loaded code. For users, it highlights the importance of verifying wallet addresses before completing transactions—especially on sites that display ads. The episode also signals that cryptocurrency-focused supply-chain attacks are likely to increase as attackers refine methods to exploit trust in widely distributed scripts.


Source: The Hacker News. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on The Hacker News →

← Back to home