Adform Ad-Tech Supply Chain Wallet Swap Attack
Summary
On July 27, 2026, advertising technology company Adform confirmed that its JavaScript tracking script 'trackpoint-async.js', served from s2.adform.net and embedded across approximately 14,000 customer websites, had been modified by unknown attackers to intercept and replace Bitcoin, Ethereum, and Tron wallet addresses in users' clipboards and on-page form fields. The attack was discovered by security researcher Kevin Beaumont and removed the same day, though some reports indicate the malicious code may have been active for at least one week prior to public disclosure. No confirmed financial losses have been disclosed and the attackers' identity and initial access method remain unknown.
Connected Entities
1 entities · 10 linked investigationsCommunity submissions
- Under reviewincriminatingWayback pending8/4/2026, 4:19:33 PM
“The Hacker News July 28 report confirming scope of the Adform JS supply-chain attack affecting ~1,800 enterprise clients and ~30% of the global DSP ad market”
— avoid-scout
Timeline(5 events)
2026-07-20
Alleged earliest possible start date of compromise, based on researcher Kevin Beaumont's observation that malicious activity extended approximately one week before the official July 27 detection date. Exact start date unconfirmed.
IT-Connect / Kevin Beaumont (DoublePulsar)2026-07-27
Adform's official detection date. Security researcher Kevin Beaumont identifies and discloses the compromise. Security researcher Max Maass preserves a copy of the compromised trackpoint-async.js script. Adform removes malicious code and notifies affected clients.
BleepingComputer / The Hacker News / DoublePulsar2026-07-27
Adform reports the incident to authorities (agencies not identified). Company advises customers and users to clear browser cache and verify wallet addresses before any cryptocurrency transactions.
TEISS / SC Media2026-07-30
Multiple security outlets including BleepingComputer, WebProNews, and SC Media publish detailed coverage of the incident. Kevin Beaumont's DoublePulsar write-up noted as a primary disclosure source.
BleepingComputer2026-08-01
Additional security outlets including The Hacker News and CyberSecurityNews publish further analysis. No confirmed losses or attacker attribution published.
The Hacker NewsDecision Log
- #1publish⛓ pending8/4/2026, 12:11:06 PMhash: EjBwvGungW6WSyGXKirXQK51CZoAgrWWikCCrRu9RNA
10 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/4/2026, 12:10:53 PM
last updated: 8/4/2026, 6:22:47 PM
avoid.net — verified advice for a post-truth world