Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers compromised Adform’s trackpoint-async.js and turned it into a browser-side tool that rewrites Bitcoin, Ethereum, and Tron wallet addresses on affected pages. Adform removed the malicious code on July 27, 2026, notified customers, and advised users to clear browser cache and verify wallet addresses before sending funds. #Adform #trackpoint-async.js #Bitcoin #Ethereum #Tron

Keypoints

  • Adform’s trackpoint-async.js was modified to replace cryptocurrency wallet addresses.
  • The malicious script affected Bitcoin, Ethereum, and Tron addresses.
  • Adform said the code operated only while the page was open and did not install persistence.
  • The script could rewrite copied addresses and values typed into form fields.
  • The compromise of a shared Adform resource created a supply-chain risk for downstream sites.

Read More: https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html