Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

alimac

Well-known member
VIP
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.

Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin, Ethereum, or Tron address may have pasted a different address inserted by the malicious code instead.

So on all websites that ran the script, your crypto could be stolen. But it's not clear which websites were infected, and I assume an adblocker may prevent his stuff. Opera also has a clipboard protection feature, weird that not all Chromium browsers have implemented this.

https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html

https://blogs.opera.com/security/2026/07/how-opera-paste-protect-guards-against-clipboard-attacks/
 
Back
Top