Adform Ad-Tech Supply Chain Wallet Swap Attack
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·EVodXt…4NpLSummary
On July 27, 2026, advertising technology company Adform confirmed that its JavaScript tracking script 'trackpoint-async.js', served from s2.adform.net and embedded across approximately 14,000 customer websites, had been modified by unknown attackers to intercept and replace Bitcoin, Ethereum, and Tron wallet addresses in users' clipboards and on-page form fields. The attack was discovered by security researcher Kevin Beaumont and removed the same day, though some reports indicate the malicious code may have been active for at least one week prior to public disclosure. No confirmed financial losses have been disclosed and the attackers' identity and initial access method remain unknown.
Connected Entities
4 entities · 60 linked investigations- Ethereum→mentioned with→Bitcoin(60%)
- Adform Ad-Tech Supply Chain Wallet Swap Attack→mentioned with→Bitcoin(65%)
- Adform Ad-Tech Supply Chain Wallet Swap Attack→mentioned with→Ethereum(65%)
- Adform Ad-Tech Supply Chain Wallet Swap Attack→mentioned with→TRON(65%)
Community submissions
- Under reviewincriminatingWayback pending8/4/2026, 4:19:33 PM
“The Hacker News July 28 report confirming scope of the Adform JS supply-chain attack affecting ~1,800 enterprise clients and ~30% of the global DSP ad market”
— avoid-scout
Timeline(5 events)
20 July 2026
Alleged earliest possible start date of compromise, based on researcher Kevin Beaumont's observation that malicious activity extended approximately one week before the official July 27 detection date. Exact start date unconfirmed.
IT-Connect / Kevin Beaumont (DoublePulsar)27 July 2026
Adform's official detection date. Security researcher Kevin Beaumont identifies and discloses the compromise. Security researcher Max Maass preserves a copy of the compromised trackpoint-async.js script. Adform removes malicious code and notifies affected clients.
BleepingComputer / The Hacker News / DoublePulsar27 July 2026
Adform reports the incident to authorities (agencies not identified). Company advises customers and users to clear browser cache and verify wallet addresses before any cryptocurrency transactions.
TEISS / SC Media30 July 2026
Multiple security outlets including BleepingComputer, WebProNews, and SC Media publish detailed coverage of the incident. Kevin Beaumont's DoublePulsar write-up noted as a primary disclosure source.
BleepingComputerAugust 2026
Additional security outlets including The Hacker News and CyberSecurityNews publish further analysis. No confirmed losses or attacker attribution published.
The Hacker NewsDecision Log
- hash: 3vjfXGUgCPXCGm2s9mrAMHfPT2ZC85FXTHrkuHUzFZJB
- hash: BkUPpXiKrg3MuAEdJnjnqGbYbZ8aeicDexTs2Vjs4H3x
- hash: EjBwvGungW6WSyGXKirXQK51CZoAgrWWikCCrRu9RNA
This investigation is cryptographically anchored to the Solana blockchain (3 events). 11 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/4/2026, 12:10:53 PM
last updated: 8/26/2026, 11:05:00 AM
3 viewsavoid.net — verified advice for a post-truth world