Adform ad platform hijacked to swap crypto wallet addresses on visitor clipboards
A tampered script served through the Danish ad-tech firm's network quietly replaced Bitcoin and Ethereum addresses with attacker-controlled ones, redirecting payments from anyone who copied a wallet on an affected site.

Key points
- Adform, a Copenhagen-based online advertising company, had one of its ad-serving scripts tampered with in a supply-chain attack.
- The malicious code hunted for cryptocurrency wallet addresses copied to a visitor's clipboard and swapped them for the attacker's.
- Any website running Adform's ad tags could have served the poisoned script to visitors during the window of compromise.
- Adform has removed the malicious code and says its core ad-serving systems were not breached.
- Anyone who sent crypto after copy-pasting a wallet address on an affected site in that window should check the destination on the blockchain.
Adform, a Danish online advertising firm that places ads across thousands of publisher websites, was hit by a supply-chain attack that turned its own script into a cryptocurrency thief.
A supply-chain attack is when criminals tamper with a trusted supplier's software so that everyone downstream ends up serving the poisoned version. In this case the supplier was an ad-tech company, and the downstream victims were the ordinary websites running its ads and the readers visiting those sites.
The attack was first reported by BleepingComputer.
What did the malicious script actually do?
It watched the clipboard. When a visitor to an affected website copied a cryptocurrency wallet address, meaning the long string of characters used to receive Bitcoin or Ethereum, the script silently replaced it with an address controlled by the attacker.
The trick relies on a habit almost every crypto user has. You copy a wallet address from an email or exchange, paste it into your wallet app to send funds, and glance at the first and last few characters to check it looks right. The swapped address is designed to look plausible at a glance. The money then goes to the criminal instead of the intended recipient.
This technique has a name in the trade: clipper malware. It usually lives on an infected computer. Delivering it through a mainstream ad platform is what makes this incident notable, because a single tampered script can reach visitors across many unrelated websites at once.
How did the attackers get into Adform's supply chain?
Adform has not published a full breakdown of the intrusion. The company says its core ad-serving infrastructure was not breached and that the malicious code has been removed. The exact route the attackers used, whether a stolen developer credential, a hijacked third-party dependency, or something else, has not been disclosed at the time of writing.
Supply-chain attacks on ad networks are not new. Criminals target them precisely because one foothold buys reach across the wider internet.
| Detail | What we know |
|---|---|
| Company | Adform (Copenhagen, Denmark) |
| Attack type | Supply-chain, clipboard-hijacking script |
| Payload | Crypto wallet address swap (clipper) |
| Status | Malicious code removed; investigation ongoing |
Should ordinary internet users be worried?
If you don't send cryptocurrency, this attack does not touch you. The script only did one thing: swap wallet addresses at the moment of copy-paste.
If you do send crypto, take two simple precautions from now on, not just because of this incident. Paste the address into your wallet, then read the full string against the source, not only the first and last characters. And where the receiving service supports it, send a small test transaction first.
Anyone who made a crypto payment in recent weeks after copying an address while browsing an ads-heavy site should check the destination on a blockchain explorer against the address the recipient actually gave them. If they don't match, the funds are almost certainly gone. Cryptocurrency transactions are not reversible, and there is no ransom demand or negotiation here: the attackers simply keep what they redirected.
Adform has not disclosed how much cryptocurrency was stolen through the tampered script, and the attacker's wallets have not been publicly identified.



