# The Ad Tech Middleman That Handed Hackers 1,800 Websites at Once
You watched yourself copy the correct wallet address. You saw it on screen. You triple-checked. Then you pasted — and sent funds to an address you never intended.
That's not a phishing story. That's what a well-engineered address-replacement attack does, and it's what happened to anyone who transacted with cryptocurrency while visiting a site running Adform's tracking script on July 27, 2026.
## One File, Thousands of Attack Surfaces
Adform is an advertising technology company. Its trackpoint-async.js script — served from s2.adform[.]net — is used by roughly 1,800 clients to track ad performance. Because Adform's own documentation describes the tracker as deployable "unconditionally across an entire website," a single compromised file on Adform's CDN became a live weapon inside an unknown number of customer sites without the attackers ever touching those sites directly.
That's the supply chain leverage point. You don't breach 1,800 companies separately when you can breach the vendor they all trust.
Adform says it detected the intrusion on July 27, pulled the malicious code, notified clients, and contacted authorities. Independent researcher Kevin Beaumont says he saw malicious activity via Adform across the previous week. That one-week gap matters enormously for exposure estimates — and as of publication, it remains unreconciled.
## What the Code Actually Did
Max Maass published a captured copy of the tampered script on July 27. Two malicious blocks had been appended to the legitimate library, their replacement strings obfuscated behind a six-byte XOR key.
The first block runs an HTTP request to 84.32.102[.]230:7744 on page load, sending the hostname and path of the page the visitor is viewing. Whether that telemetry actually reached the operator isn't confirmed by the captured sample, but the plumbing was there. The block then watches for copy events and polls the clipboard every four seconds, rewriting any matching Bitcoin, Ethereum, or Tron address it finds.
The second block is what separates this from a run-of-the-mill clipboard hijacker. It walks the document's text nodes and rewrites wallet addresses in input, textarea, and contenteditable elements in real time. It hooks the value setter on input fields — meaning even programmatic writes, the kind your password manager or autofill might perform, get rewritten in transit. It intercepts copy, cut, paste, and input events.
Beaumont put it plainly: "Even if you notice the address is wrong and recopy the wallet, it keeps replacing it."
That persistence is by design. Clipboard monitoring alone is a known threat that security-aware users have learned to work around. Hooking the DOM value setter closes that escape hatch.
## Zero Detections, Open Questions
At the time of discovery, the malicious file and its associated URLs returned no detections on VirusTotal. This is not unusual for a freshly deployed supply-chain implant — but it underscores a structural problem with detection pipelines that treat third-party ad scripts as ambient noise rather than high-risk execution surfaces.
Adform's incident notice offers an important but carefully phrased statement: the company found "no evidence that the code transmitted visitors' IP addresses or information about websites they visited," followed immediately by: "Technical analysis indicates that such transmission may have been possible." Both things are true. The gap between them is where defenders should spend their attention.
What Adform has not published: a list of indicators of compromise. No hashes, no domains to block, no IPs to watch for. The company filed with authorities and told clients to clear their caches. That is reasonable initial containment. It is not sufficient for defenders who need to audit their own exposure.
The unanswered questions include how the attacker gained write access to Adform's deployment path, how many downstream sites actually carried the compromised file, and whether any funds were successfully diverted. None of these have answers yet.
Adform advises users who may have been affected to clear their browser cache — the altered file may still be served from local cache even after the fix was pushed — and to verify any wallet address independently before sending a transaction.
## HackWire Analysis
This attack fits a pattern that the security industry keeps relearning: the highest-leverage supply chain targets are not the ones with the most sensitive data. They're the ones with the widest distribution.
Ad tech tracking scripts check every box. They're deployed across enormous customer bases, they run with full DOM access, they're rarely audited by the sites that embed them, and their network requests are treated as expected noise by most enterprise firewalls. Magecart understood this a decade ago with payment skimmers. This campaign applies the same principle to crypto theft.
The technical implementation here is notably sophisticated for what might initially read as a commodity crypto stealer. Hooking value setters and intercepting input events, not just clipboard events, shows the authors anticipated defenders who advise "manually retype the address." The XOR obfuscation is light but sufficient to delay automated detection — and it worked: zero VirusTotal hits at discovery time.
The timeline dispute is the most underreported detail in this story. If Beaumont's broader observation window is accurate, the exposure period may be seven or more times longer than Adform's public notice suggests. Every affected site's transaction logs from that window deserve a review. Operators who embedded trackpoint-async.js site-wide — as Adform's own documentation suggests is a valid deployment pattern — should treat this as a potential compromise of every crypto transaction processed during the disputed window, not just July 27.
For defenders: third-party script inventory is not a one-time exercise. The question "what JavaScript runs on our pages and where does it come from?" needs a continuous, auditable answer. Subresource Integrity (SRI) hashing on third-party scripts would have surfaced this modification immediately. Very few organizations use it for ad tech because the scripts update frequently and ad vendors don't publish expected hashes. That convenience trade-off is looking expensive right now.
— HackWire Editorial
---