Skip to main content
AVOID.NET

Adform Ad-Tech Supply Chain Wallet Swap Attack

avoid.net/adform-ad-tech-supply-chain-wallet-swap-attack6/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·EVodXt…4NpL

Summary

On July 27, 2026, advertising technology company Adform confirmed that its JavaScript tracking script 'trackpoint-async.js', served from s2.adform.net and embedded across approximately 14,000 customer websites, had been modified by unknown attackers to intercept and replace Bitcoin, Ethereum, and Tron wallet addresses in users' clipboards and on-page form fields. The attack was discovered by security researcher Kevin Beaumont and removed the same day, though some reports indicate the malicious code may have been active for at least one week prior to public disclosure. No confirmed financial losses have been disclosed and the attackers' identity and initial access method remain unknown.

Connected Entities

4 entities · 60 linked investigations
Organizations
Protocols
Adform Ad-Tech Supply Chain Wallet Swap Attack
Tokens
Bitcoin
Relationships
  • Ethereummentioned withBitcoin(60%)
  • Adform Ad-Tech Supply Chain Wallet Swap Attackmentioned withBitcoin(65%)
  • Adform Ad-Tech Supply Chain Wallet Swap Attackmentioned withEthereum(65%)
  • Adform Ad-Tech Supply Chain Wallet Swap Attackmentioned withTRON(65%)
Have evidence about Adform Ad-Tech Supply Chain Wallet Swap Attack?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

Timeline(5 events)

20 July 2026

Alleged earliest possible start date of compromise, based on researcher Kevin Beaumont's observation that malicious activity extended approximately one week before the official July 27 detection date. Exact start date unconfirmed.

IT-Connect / Kevin Beaumont (DoublePulsar)

27 July 2026

Adform's official detection date. Security researcher Kevin Beaumont identifies and discloses the compromise. Security researcher Max Maass preserves a copy of the compromised trackpoint-async.js script. Adform removes malicious code and notifies affected clients.

BleepingComputer / The Hacker News / DoublePulsar

27 July 2026

Adform reports the incident to authorities (agencies not identified). Company advises customers and users to clear browser cache and verify wallet addresses before any cryptocurrency transactions.

TEISS / SC Media

30 July 2026

Multiple security outlets including BleepingComputer, WebProNews, and SC Media publish detailed coverage of the incident. Kevin Beaumont's DoublePulsar write-up noted as a primary disclosure source.

BleepingComputer

August 2026

Additional security outlets including The Hacker News and CyberSecurityNews publish further analysis. No confirmed losses or attacker attribution published.

The Hacker News
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 11 of 12 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/4/2026, 12:10:53 PM

last updated: 8/26/2026, 11:05:00 AM

3 views

avoid.net — verified advice for a post-truth world