type: incident ยท created: 2026-08-01 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Summary
Attackers modified a JavaScript file served by Adform, the advertising technology company, turning it into a browser-side tool that rewrites Bitcoin, Ethereum, and Tron addresses. Anyone who visited an affected site on July 27 may have pasted a different address.
Key Details
- Date: 2026-08-01
- Source: The Hacker News
- Reliability: Tier 2/4 โ Established cyber journalism
- Affected Company: Adform (advertising technology)
- Attack Method: Modified JavaScript file served by Adform's infrastructure
- Impact: Rewrites Bitcoin, Ethereum, and Tron addresses โ both pasted clipboard addresses and those entered directly into form fields
- Date of Compromise: July 27, 2026
- Duration: Code operated only while the page was open (no persistence)
Related
- Coldcard Hardware Wallet Flaw Linked To 70 Million Bitcoin Theft In 41 Minutes โ Another cryptocurrency theft incident