# The Ad Script Hiding in Plain Sight That Drained Crypto Wallets for a Week


When you copy a Bitcoin address from a website, you assume what you pasted is what you copied. For anyone who visited a site running Adform's tracking code on or after July 26, 2026, that assumption was wrong.


Adform — one of Europe's largest adtech companies, whose demand-side and supply-side platforms underpin a substantial chunk of the continent's digital advertising infrastructure — had its core JavaScript tracking library quietly compromised. The malicious version sat on Adform's own servers, served to every downstream customer site, silently watching what users copied to their clipboards.


The attacker wasn't subtle about the goal. The payload targeted Bitcoin, Ethereum, and TRON addresses specifically. Copy one to your clipboard, and the script swapped it with an address the attacker controlled. Paste it into your wallet app or an exchange withdrawal form, and your funds went somewhere you never intended.


## A Week in the Dark


Security researcher Kevin Beaumont discovered the compromise. The malicious code was injected into trackpoint-async.js, a JavaScript tracking library served from s2.adform.net and loaded by every website that uses Adform's platform. The malicious payload was appended in obfuscated form at the end of the legitimate library — a clean technique that minimizes the diff and makes casual inspection unlikely to catch anything.


Beaumont's analysis found the oldest archived copy of the compromised script dated to July 26 at 23:29 GMT. Adform says it detected "suspicious activity" on July 27. That means the script ran hot for roughly a week before being pulled.


The breadth of exposure is the thing that should make adtech executives uncomfortable. Beaumont put it plainly: if you visit a site that embeds trackpoint-async.js, that site is compromising your device — through no fault of the site's own. The trust relationship flows upstream. A single poisoned dependency in Adform's CDN becomes a zero-click payload on every publisher using the platform.


The attacker also built in a secondary data exfiltration path. Other malicious Adform-hosted scripts were observed communicating with an external server — 84.32.102[.]230:7744 — sending victim IP addresses, the referring website URL, and the path the user was on. That's a visitor profiling operation running alongside the clipboard theft. Two revenue streams from one compromised library.


## Zero Detections, Zero Days of Warning


Beaumont ran the malicious script through VirusTotal. Not a single antivirus engine flagged it.


That's not surprising, but it is clarifying. Clipboard-hijacking JavaScript that ships inside a legitimate, signed CDN asset, modifying strings in memory while the page is open, leaves almost no footprint that signature-based tools are designed to catch. There's no executable dropped. No persistence mechanism. No registry modification. The script lives in the browser tab and dies when you close it — and in that window, it can redirect a cryptocurrency payment worth any amount.


Adform's own characterization — "the code was not designed to install software on a user's device or establish persistence" — is technically accurate and practically beside the point. A heist that completes in the browser tab, before you close it, doesn't need persistence.


## The Adtech Trust Problem Nobody Wants to Solve


This incident follows a pattern that the security industry keeps encountering and then failing to address structurally. In 2024, the Polyfill.io supply chain attack exposed tens of millions of websites after the domain was acquired by a Chinese company and repurposed to serve malicious JavaScript. The mechanism was nearly identical: a trusted CDN resource, embedded universally, turned into a payload delivery system. The victim count scaled with the platform's market share.


Adform is not Polyfill. This was likely an intrusion rather than an ownership transfer. But the structural exposure is the same: modern websites load dozens of third-party scripts from external CDNs, granting each of them full access to the page DOM and the user's clipboard, with no sandboxing and minimal monitoring.


The adtech ecosystem is particularly exposed because script injection is the product. Publishers embed these tags because they need the ad serving functionality, and the script has to run with broad access to the page to do its job. That's not a flaw in any one vendor's implementation — it's the architecture of digital advertising, and it makes every adtech CDN a high-value target for exactly this kind of attack.


## What Defenders Actually Need to Do


Adform's guidance — clear your browser cookies — is the minimum, and it probably isn't sufficient for users who executed a cryptocurrency transaction during the exposure window. If you copied and pasted a wallet address on any Adform-served site between July 26 and July 27, check your transaction history.


For security teams:


  • Subresource Integrity (SRI) matters here. If publishers had been loading trackpoint-async.js with an integrity attribute, a modified script would have been blocked by the browser. Most don't. Push your vendors on this.
  • Content Security Policy with a strict script-src directive limits what external scripts can phone home to. The exfiltration to 84.32.102[.]230:7744 would have been blocked by a properly deployed CSP.
  • Third-party script inventory and monitoring is not optional at this point. Tools that baseline JavaScript behavior and alert on changes to served assets from CDN hosts are the detection layer that caught zero events here while the attack ran for a week.

  • The broader problem is that the security posture of your website is now a function of the security posture of every vendor in your tag stack. Adform, Google, Meta, and a dozen others have near-universal JavaScript execution rights on publisher pages worldwide. That's a very large attack surface with very little visibility.


    ---


    ## HackWire Analysis


    The Adform compromise is another data point in what is becoming an undeniable pattern: the ad supply chain is the new software supply chain for web attacks, and it is significantly less monitored.


    The comparison to Polyfill.io is instructive but incomplete. The Polyfill attack was relatively slow — the malicious behavior was erratic enough that researchers caught behavioral anomalies over time. The Adform payload was surgical: clipboard hijacking with crypto-specific targeting, plus passive telemetry. It's designed to run cleanly and quietly, and it did — a full week with zero AV detections before a researcher caught it manually.


    What's missing from most coverage of this incident is the second payload: the IP and referrer data being sent to 84.32.102[.]230:7744. That's not a crypto theft tool. That's a reconnaissance operation. The attacker was building a database of users, their browsing behavior, and which publisher sites they visit. Whether that data was sold, used for targeted follow-on attacks, or simply stockpiled is unknown. But it was being collected, and that dimension hasn't received enough attention.


    For defenders, the practical calculus has shifted. You cannot audit every third-party script your ad vendors serve. What you can do is enforce SRI for all external scripts where possible, deploy CSP headers that restrict script communication to known domains, and instrument your own monitoring to detect unexpected outbound connections from browser sessions. The attacker's C2 address — 84.32.102[.]230:7744 — on a non-standard port is exactly the kind of anomaly that network egress monitoring would surface. Most publisher security programs don't have that coverage on client-side traffic.


    The adtech industry needs to treat CDN integrity as a security control, not an afterthought. Versioned, signed, immutable assets with SRI enforcement should be the standard, not the exception. Until that happens, attacks like this will keep running for a week before someone notices.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)