Attackers compromised Adform's JavaScript infrastructure and injected malicious code designed to intercept and replace cryptocurrency wallet addresses in real time. The attack operated at the browser level, meaning victims copying wallet addresses from affected websites received attacker-controlled addresses instead of legitimate ones. This technique harvests cryptocurrency directly from users without requiring credential theft or traditional malware installation.

Adform, a major advertising technology platform serving thousands of websites, discovered the compromise on July 27, 2026. The company removed the poisoned script, notified customers, and filed reports with law enforcement. The incident affected anyone who visited Adform-instrumented sites on July 27 and subsequently copied Bitcoin wallet addresses.

This supply-chain attack exemplifies a growing threat vector. Compromising widely-used third-party scripts gives attackers leverage over countless downstream websites simultaneously. Users visiting legitimate sites remain exposed because they trust the content and instructions they see in their browsers. The malicious code operated transparently, requiring no additional social engineering or exploit delivery.

The financial impact depends on transaction volume. Each cryptocurrency transfer to a poisoned address represents a direct loss. Unlike traditional fraud, cryptocurrency transactions are irreversible. Recovery requires identifying the attacker's wallet and pursuing legal channels, which often prove ineffective across jurisdictions.

Organizations relying on third-party scripts face escalating risks. Content delivery networks and advertising platforms represent attractive targets because compromising them cascades across entire client networks. Adform's detection speed limited exposure, but the incident demonstrates that even established vendors can be penetrated.

Users should verify wallet addresses through independent channels rather than copying them directly from websites. Organizations should implement subresource integrity checks and monitor third-party script behavior. Content Security Policy configurations can limit script capabilities, though they do not prevent wallet-address swapping once code executes in the browser context.

The attack underscores why cryptocurrency users must treat address verification