:

ADFORM AD SCRIPT HIJACKED TO STEAL CRYPTOCURRENCY

INDUSTRY DESK2 MIN READ
FRI, JUL 31, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Advertising platform Adform fell victim to a supply-chain attack that injected malicious code into its ad scripts, redirecting cryptocurrency wallet addresses from users' clipboards to attacker-controlled accounts.

Adform, a major online advertising firm, discovered that attackers compromised its ad delivery system to distribute cryptocurrency-stealing malware across websites using its platform. The attack worked by intercepting data copied to users' clipboards. When visitors to affected websites copied cryptocurrency wallet addresses, the compromised script would replace them with addresses controlled by the attacker. Users pasting what they believed were legitimate wallet addresses would unknowingly send funds to criminals instead. This type of supply-chain attack is particularly effective because it compromises infrastructure trusted by many downstream users. Websites relying on Adform's ad services unknowingly served malicious code to their visitors without direct involvement in the attack. The scope of exposure remains significant given Adform's position serving thousands of publishers globally. Any website using Adform's advertising scripts during the compromise window potentially affected users. Adform has not disclosed the exact number of affected sites or users, or the total financial losses from the attack. The company has stated it remediated the compromised scripts and is investigating the incident. Supply-chain attacks targeting advertising and analytics platforms have become increasingly common. Criminals exploit the trust relationship between platforms and their users, using legitimate services as distribution channels for malware. This incident highlights the security risks inherent in relying on third-party ad platforms. Users should exercise caution when copying and pasting sensitive information like cryptocurrency addresses, and consider using alternative verification methods when possible. Adform has not announced specific security improvements in response to the attack.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.

1H AGOSecurity Desk

A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.

3H AGOIndustry Desk

A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.

8H AGOIndustry Desk

Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.

11H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.