Skip to main content
Sign in

Audit log

Every state-changing event for Adform Ad-Tech Supply Chain Wallet Swap Attack: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-04 12:11:06Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    EjBwvGungW6W…CrRu9RNAsha256 → base58
    verifying row…
    canonical bytes (17411 B) ▸
    {"actor":"system:backfill","investigation_id":"8e56f9fb-fabd-445a-85fa-6b1a284eb4e8","kind":"publish","page_slug":"adform-ad-tech-supply-chain-wallet-swap-attack","published_at":"2026-08-04T12:11:05.995Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Adform Ad-Tech Supply Chain Wallet Swap Attack","sections":[{"content":"Adform, a Copenhagen-headquartered digital advertising technology company with approximately 1,800 direct customers and an estimated 14,000 businesses reachable through its platform, confirmed on July 27, 2026 that its shared JavaScript tracking script had been trojanized in a supply chain attack. The compromised file, 'trackpoint-async.js', is distributed from Adform's own CDN at s2.adform.net and is embedded by customer websites as a standard ad-tracking integration. By modifying this single shared resource, the attackers gained the ability to execute malicious code across all downstream sites that loaded the script without directly breaching those sites. Adform's 2025 annual report cited approximately 1.5 billion daily ad displays across more than 180 countries. The attack represents a classic supply chain compromise: exploiting the trust relationship between a widely-deployed third-party vendor and its customers.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html"},{"credibility":2,"name":"Online ad firm Adform's script compromised to steal cryptocurrency — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/"}]},{"content":"Attackers injected a malicious payload into 'trackpoint-async.js' using obfuscated code that employed XOR encryption to conceal the replacement wallet address strings. The injected code operated through two distinct mechanisms. First, it registered event listeners for clipboard copy, cut, paste, and input events and also polled the clipboard every three to four seconds, replacing any detected Bitcoin, Ethereum, or Tron wallet address with an attacker-controlled alternative. The polling interval was intentional: if a user noticed the substitution and re-copied the correct address, the script would overwrite it again on the next poll cycle. Second, the code walked the document's text nodes to rewrite wallet addresses rendered directly in web page content, including values in input fields, textareas, and contenteditable elements, while maintaining cursor position to avoid visual disruption. Additionally, the payload beaconed victim data — including IP address, page hostname, and URL path — to an attacker-controlled command-and-control server at IP address 84.32.102.230 on port 7744. Adform stated that 'technical analysis indicates that such transmission may have been possible' but reported finding no evidence that IP address or browsing data was actually exfiltrated off-page. The file hash of a captured malicious sample is 02ff86c7f9fe609a753ff15bda90baa3c3e0d4a2e559ec4fcf8a3de0954b7c55. Security researcher Max Maass preserved a copy of the compromised script on July 27, 2026.","heading":"Technical Mechanism","severity":"critical","sources":[{"credibility":2,"name":"Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html"},{"credibility":2,"name":"Adform Compromise: Crypto-Stealing Ad Script Explained (at least a week) — IT-Connect","type":"news_article","url":"https://www.it-connect.tech/adform-breach-ad-script-steals-cryptocurrency-for-at-least-a-week/"},{"credibility":2,"name":"Adform compromised to serve crypto stealer via supply chain attack — Kevin Beaumont / DoublePulsar","type":"research","url":"https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e"}]},{"content":"The incident was identified by security researcher Kevin Beaumont, who published his findings on the DoublePulsar publication on or around July 27-30, 2026. Beaumont noted that the malicious code appeared to disappear as he was writing his disclosure, suggesting Adform or the attacker removed it upon exposure becoming imminent. The official Adform detection date is July 27, 2026; however, Beaumont and at least one other reporting outlet described activity extending back approximately one week before that date, suggesting the compromise may have been active from roughly July 20, 2026. The initial malicious samples submitted to VirusTotal returned zero detections from antivirus engines, indicating the payload evaded standard signature-based defenses at the time of discovery. The exact start date of the compromise has not been confirmed by Adform.","heading":"Discovery and Timeline Discrepancy","severity":"high","sources":[{"credibility":2,"name":"Adform compromised to serve crypto stealer via supply chain attack — Kevin Beaumont / DoublePulsar","type":"research","url":"https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e"},{"credibility":2,"name":"Adform Compromise: Crypto-Stealing Ad Script Explained — IT-Connect","type":"news_article","url":"https://www.it-connect.tech/adform-breach-ad-script-steals-cryptocurrency-for-at-least-a-week/"}]},{"content":"Adform's platform reaches approximately 14,000 businesses according to reporting based on the company's 2025 annual report, which also cited roughly 1,800 direct customers and 1.5 billion daily ad displays across more than 180 countries. One security research outlet estimated approximately 1,800 downstream customer sites carried the malicious code. The precise count of sites that actively loaded the compromised script during the window of attack, and the number of individual users exposed, has not been publicly disclosed by Adform. Because the payload was delivered through Adform's trusted CDN infrastructure, no breach of individual downstream websites was required; any site embedding the trackpoint-async.js file from s2.adform.net was automatically affected.","heading":"Scale and Downstream Impact","severity":"high","sources":[{"credibility":2,"name":"Adform Supply Chain Attack Swaps Crypto Wallets on Thousands of Sites — WebProNews","type":"news_article","url":"https://www.webpronews.com/adform-supply-chain-attack-swaps-crypto-wallets-on-thousands-of-sites/"},{"credibility":3,"name":"Adform CDN Supply Chain Attack — TechJack Solutions","type":"news_article","url":"https://techjacksolutions.com/scc-intel/adform-cdn-supply-chain-attack-poisoned-javascript-hijacks-crypto-wallet-addresses-across-1800-downstream-sites/"}]},{"content":"No confirmed financial losses have been reported by Adform or any third party as of early August 2026. Adform has not disclosed the attacker-controlled wallet addresses that were substituted by the malicious code. The company advised all customers and end users to clear browser caches — because the altered file may have remained cached after the fix was applied — and to verify any cryptocurrency wallet address before transferring funds, implicitly acknowledging that unauthorized fund diversions may have occurred. Independent on-chain analysis of potential attacker wallets has not been published in available reporting.","heading":"Financial Losses and Attacker Wallets","severity":"high","sources":[{"credibility":2,"name":"Adform ad-tech script hijacked to swap cryptocurrency wallet addresses — TEISS","type":"news_article","url":"https://www.teiss.co.uk/news/adform-ad-tech-script-hijacked-to-swap-cryptocurrency-wallet-addresses-17919"},{"credibility":2,"name":"Online ad firm Adform's script compromised to steal cryptocurrency — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/"}]},{"content":"How the attackers gained initial access to Adform's infrastructure to modify the hosted JavaScript file has not been publicly disclosed. Adform has not released indicators of compromise, attacker identities, or details of the intrusion pathway. No threat actor or nation-state has been attributed to the attack in available reporting as of August 2026. The command-and-control server IP address 84.32.102.230 on port 7744 represents the primary identified attacker infrastructure. No public attribution linking this IP to a known threat actor group has appeared in available reporting.","heading":"Initial Access Vector and Attribution","severity":"high","sources":[{"credibility":2,"name":"Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html"},{"credibility":2,"name":"Online ad firm Adform's script compromised to steal cryptocurrency — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/"}]},{"content":"Adform detected the incident on July 27, 2026, removed the malicious code from trackpoint-async.js, and notified affected clients. The company stated it found no evidence the code installed additional persistent software or that IP address and browsing data were transmitted to the attacker server, while simultaneously acknowledging that 'technical analysis indicates that such transmission may have been possible.' Adform reported the incident to authorities but did not name which agencies. The company issued guidance to customers and end users to clear browser caches and verify wallet addresses before sending any cryptocurrency transactions.","heading":"Adform's Response","severity":"medium","sources":[{"credibility":2,"name":"Adform ad-tech script hijacked to swap cryptocurrency wallet addresses — TEISS","type":"news_article","url":"https://www.teiss.co.uk/news/adform-ad-tech-script-hijacked-to-swap-cryptocurrency-wallet-addresses-17919"},{"credibility":2,"name":"Adform supply-chain attack replaced crypto wallet addresses — SC Media","type":"news_article","url":"https://www.scworld.com/brief/adform-supply-chain-attack-replaced-crypto-wallet-addresses"}]},{"content":"Security analysts commenting on the incident highlighted that Subresource Integrity (SRI) — a browser mechanism allowing websites to specify a cryptographic hash for externally loaded scripts, causing the browser to refuse execution if the file has been modified — could have prevented downstream sites from loading the compromised version of trackpoint-async.js. However, SRI is architecturally incompatible with dynamically updated CDN-hosted scripts of the type common in the ad-tech industry, where vendors regularly update files in place. This tension between convenient script delivery and supply-chain integrity is a systemic issue across the ad-tech ecosystem. The attack is broadly comparable to prior supply chain incidents targeting widely-embedded JavaScript libraries and highlights the attack surface created by the ad-tech industry's model of embedding shared, remotely-updated scripts across large numbers of third-party websites.","heading":"Broader Security Implications","severity":"medium","sources":[{"credibility":2,"name":"Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html"},{"credibility":3,"name":"Adform's Ad Tracker Was Hijacked to Steal Crypto — Gblock","type":"news_article","url":"https://www.gblock.app/articles/adform-adtech-script-supply-chain-crypto-2026"}]}],"sources_used":[{"credibility":2,"name":"Online ad firm Adform's script compromised to steal cryptocurrency — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/"},{"credibility":2,"name":"Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html"},{"credibility":2,"name":"Adform compromised to serve crypto stealer via supply chain attack — Kevin Beaumont / DoublePulsar","type":"research","url":"https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e"},{"credibility":2,"name":"Adform Supply Chain Attack Swaps Crypto Wallets on Thousands of Sites — WebProNews","type":"news_article","url":"https://www.webpronews.com/adform-supply-chain-attack-swaps-crypto-wallets-on-thousands-of-sites/"},{"credibility":2,"name":"Adform supply-chain attack replaced crypto wallet addresses — SC Media","type":"news_article","url":"https://www.scworld.com/brief/adform-supply-chain-attack-replaced-crypto-wallet-addresses"},{"credibility":2,"name":"Adform ad-tech script hijacked to swap cryptocurrency wallet addresses — TEISS","type":"news_article","url":"https://www.teiss.co.uk/news/adform-ad-tech-script-hijacked-to-swap-cryptocurrency-wallet-addresses-17919"},{"credibility":2,"name":"Adform Compromise: Crypto-Stealing Ad Script Explained — IT-Connect","type":"news_article","url":"https://www.it-connect.tech/adform-breach-ad-script-steals-cryptocurrency-for-at-least-a-week/"},{"credibility":2,"name":"Hackers Turned a Trusted Advertising Platform Into a Crypto-Stealer Delivery Network — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/adform-advertising-platform-compromised/"},{"credibility":3,"name":"Silent Supply-Chain Attack Hits Adform Script — CoinIdol","type":"news_article","url":"https://coinidol.com/silent-supply-chain-attack/"},{"credibility":3,"name":"Adform Script Compromised in Supply Chain Attack — Brinztech","type":"news_article","url":"https://www.brinztech.com/breach-alerts/brinztech-alert-adform-script-compromised-in-supply-chain-attack-to-inject-cryptocurrency-wallet-swapping-code"},{"credibility":3,"name":"Adform Script Swapped Crypto Wallet Addresses — GridinSoft Blog","type":"news_article","url":"https://blog.gridinsoft.com/adform-script-crypto-wallet-address-swap/"},{"credibility":3,"name":"Adform's Ad Tracker Was Hijacked to Steal Crypto — Gblock","type":"news_article","url":"https://www.gblock.app/articles/adform-adtech-script-supply-chain-crypto-2026"}],"summary":"On July 27, 2026, advertising technology company Adform confirmed that its JavaScript tracking script 'trackpoint-async.js', served from s2.adform.net and embedded across approximately 14,000 customer websites, had been modified by unknown attackers to intercept and replace Bitcoin, Ethereum, and Tron wallet addresses in users' clipboards and on-page form fields. The attack was discovered by security researcher Kevin Beaumont and removed the same day, though some reports indicate the malicious code may have been active for at least one week prior to public disclosure. No confirmed financial losses have been disclosed and the attackers' identity and initial access method remain unknown.","timeline":[{"date":"2026-07-20","event":"Alleged earliest possible start date of compromise, based on researcher Kevin Beaumont's observation that malicious activity extended approximately one week before the official July 27 detection date. Exact start date unconfirmed.","source":"IT-Connect / Kevin Beaumont (DoublePulsar)","source_url":"https://www.it-connect.tech/adform-breach-ad-script-steals-cryptocurrency-for-at-least-a-week/"},{"date":"2026-07-27","event":"Adform's official detection date. Security researcher Kevin Beaumont identifies and discloses the compromise. Security researcher Max Maass preserves a copy of the compromised trackpoint-async.js script. Adform removes malicious code and notifies affected clients.","source":"BleepingComputer / The Hacker News / DoublePulsar","source_url":"https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/"},{"date":"2026-07-27","event":"Adform reports the incident to authorities (agencies not identified). Company advises customers and users to clear browser cache and verify wallet addresses before any cryptocurrency transactions.","source":"TEISS / SC Media","source_url":"https://www.teiss.co.uk/news/adform-ad-tech-script-hijacked-to-swap-cryptocurrency-wallet-addresses-17919"},{"date":"2026-07-30","event":"Multiple security outlets including BleepingComputer, WebProNews, and SC Media publish detailed coverage of the incident. Kevin Beaumont's DoublePulsar write-up noted as a primary disclosure source.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/"},{"date":"2026-08-01","event":"Additional security outlets including The Hacker News and CyberSecurityNews publish further analysis. No confirmed losses or attacker attribution published.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision ce97cfd6-b90c-4f01-b3a8-42145c3e6caf
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.