Hackers Tampered With Adform's Script to Redirect Crypto Payments

Β·
Listen to this article~5 min
Hackers Tampered With Adform's Script to Redirect Crypto Payments

Hackers modified Adform's JavaScript to swap crypto wallet addresses, redirecting Bitcoin payments to attackers. Learn how the attack worked and how to protect yourself.

If you've ever copied a cryptocurrency wallet address from a website, you probably assumed it was safe. Most of the time, it is. But a recent attack on advertising technology company Adform shows just how fragile that trust can be. Attackers managed to modify a JavaScript file served by Adform, turning it into a browser-side tool that silently rewrites cryptocurrency wallet addresses. That means anyone who visited an affected site on July 27, 2026, and copied a Bitcoin address could have accidentally sent funds to a hacker's wallet instead. Adform caught the breach on the same day, removed the malicious code, notified affected clients, and reported the incident to authorities. The company acted quickly, but the damage window was realβ€”and it's worth understanding how this happened and what it means for you. ### How the Attack Worked The attack wasn't a hack of a single website. Instead, it targeted a third-party script that many sites rely on for advertising services. By compromising that one file, the attackers effectively poisoned every site that loaded it. Once the script ran in a visitor's browser, it monitored the page for cryptocurrency wallet addresses. When it found one, it swapped it with the attacker's address. The user would copy what they thought was the correct destination and unknowingly send funds elsewhere. This is a classic supply chain attack, and it's particularly nasty because the victim has no way to detect the swap. The page looks normal, the address looks real, and the transaction goes through without a hitch. ### Why This Matters for Crypto Users If you've ever sent Bitcoin or another cryptocurrency, you know that transactions are irreversible. Once funds leave your wallet, there's no chargeback, no dispute process, and no customer service line to call. That's the whole point of decentralized finance, but it also means you bear the full responsibility for every transfer. Here's what makes this attack so dangerous: - It doesn't require you to install malware or click a suspicious link - It happens entirely in your browser, so your device remains clean - It targets a moment of trust, when you're copying an address you've verified - It can affect any site using the compromised script, not just crypto platforms ### What You Can Do to Protect Yourself While this specific attack has been neutralized, similar ones will happen again. The good news is that you can take a few simple steps to dramatically reduce your risk. **Always verify the full address before sending.** Don't just check the first few and last few characters. Compare the entire string against a known source, like your exchange or wallet app. **Use a hardware wallet or trusted app for address generation.** Many wallets now generate addresses locally on your device, which makes browser-based tampering much harder. **Send a small test transaction first.** If you're moving a large amount, send a tiny amount to confirm the address works before committing the full sum. **Keep your browser and extensions updated.** Attacks like this often exploit outdated software, so staying current helps close known vulnerabilities. ### The Bigger Picture This incident is a reminder that the web is built on trust, and that trust can be broken in ways you don't expect. Advertising scripts, analytics trackers, and other third-party tools are everywhere, and each one represents a potential entry point for attackers. For professionals working with antidetect browsers or managing multiple online identities, this kind of attack is especially relevant. A compromised script on any site you visit could expose your activity or redirect your transactions, regardless of how careful you are with your setup. The takeaway? Stay vigilant, verify everything, and never assume that a familiar website is automatically safe. The tools we use to protect our privacy are only as strong as the weakest link in the chainβ€”and sometimes that link is a JavaScript file you didn't even know was there.