Adform ad platform hijacked to swap crypto wallet addresses on visitor clipboards
A tampered script served through the Danish ad-tech firm's network quietly replaced Bitcoin and Ethereum addresses with attacker-controlled ones, redirecting payments from anyone who copied a wallet on an affected site.

Key points
- Adform, a Copenhagen-based online advertising company, had one of its ad-serving scripts tampered with in a supply-chain attack.
- The malicious code hunted for cryptocurrency wallet addresses copied to a visitor's clipboard and swapped them for the attacker's.
- Any website running Adform's ad tags could have served the poisoned script to visitors during the window of compromise.
- Adform has removed the malicious code and says its core ad-serving systems were not breached.
- Anyone who sent crypto after copy-pasting a wallet address on an affected site in that window should check the destination on the blockchain.
Adform, a Danish online advertising firm that places ads across thousands of publisher websites, was hit by a supply-chain attack that turned its own script into a cryptocurrency thief. The attack was first reported by BleepingComputer.
A supply-chain attack is when criminals tamper with a trusted supplier's software so that everyone downstream ends up serving the poisoned version. Here the supplier was an ad-tech company; the downstream victims were ordinary websites running its ads and the readers visiting those sites.
What did the malicious script actually do?
It watched the clipboard. When a visitor to an affected website copied a cryptocurrency wallet address, the long string of characters used to receive Bitcoin or Ethereum, the script silently replaced it with an address the attacker controlled.
The trick exploits a habit almost every crypto user has. You copy a wallet address from an email or exchange, paste it into your wallet app, and glance at the first and last few characters. The swapped address is built to look plausible at that glance, and the money goes to the attacker. This class of malware is called a clipper. It usually lives on an infected computer, which is what makes the ad-platform delivery notable: a single tampered script can reach visitors across many unrelated sites at once. We've tracked this distribution tactic before, including a campaign that laundered clipper payloads through sponsored posts on news sites in June 2026.
How did the attackers get into Adform's supply chain?
Adform has not published a full breakdown of the intrusion. Its core ad-serving infrastructure was not breached, the company says, and the malicious code has been removed. How the attackers got in, whether a stolen developer credential, a hijacked dependency, or something else, has not been disclosed.
Criminals target ad networks precisely because one foothold buys reach across the wider internet. Our July 2026 piece on the approval gap in ad tech explains why a single approved script can quietly pull in code from vendors a security team has never vetted.
| Detail | What we know |
|---|---|
| Company | Adform (Copenhagen, Denmark) |
| Attack type | Supply-chain, clipboard-hijacking script |
| Payload | Crypto wallet address swap (clipper) |
| Status | Malicious code removed; investigation ongoing |
Should ordinary internet users be worried?
If you don't send cryptocurrency, this attack does not touch you. The script did one thing: swap wallet addresses at the moment of copy-paste.
If you do send crypto, two precautions are worth making permanent. Paste the address into your wallet, then read the full string against the source rather than checking only the first and last characters. Where the receiving service supports it, send a small test transaction first.
Anyone who made a crypto payment in recent weeks after copying an address while browsing an ads-heavy site should check the destination on a blockchain explorer against the address the recipient actually gave them. If they don't match, the funds are almost certainly gone. Crypto transactions aren't reversible, and there's no ransom demand here: attackers simply keep what they redirected.
How much cryptocurrency moved through the tampered script is unknown, and the attacker's wallets have not been publicly identified. The more pointed question for the industry is whether ad-tech supply chains will face any structural pressure to change after this, or whether reach and speed will keep winning over scrutiny.



