Adform JavaScript poisoned to rewrite crypto wallet addresses on customer sites
Source headline: Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Intelligence Summary
Attackers modified a JavaScript file distributed through Adform’s advertising stack. The altered script ran in visitors’ browsers and rewrote cryptocurrency wallet addresses before transactions were initiated. Adform says it detected the tampering on July 27, 2026, removed the malicious code, and notified affected clients. Sites that carried the compromised script during that window were potentially exposed for anyone who copied or used a Bitcoin wallet address. Users and site owners should confirm Adform script integrity and review wallet address handling for sessions from the incident timeframe.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.