<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/adform-s-ad-tracking-script-was-compromised-to-swap-cryptocurrency-wallet-addresses-0hio8awyf" -->

---
title: Adform&#x27;s ad tracking script was compromised to swap...
description: Adform&#x27;s widely-deployed JavaScript tracking script `trackpoint-async.js` was trojanized in a supply chain attack discovered on July 27, 2026. The malicious...
canonical: https://daily.dev/posts/adform-s-ad-tracking-script-was-compromised-to-swap-cryptocurrency-wallet-addresses-0hio8awyf
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Adform&#x27;s ad tracking script was compromised to swap cryptocurrency wallet addresses | daily.dev
og:description: Adform&#x27;s widely-deployed JavaScript tracking script `trackpoint-async.js` was trojanized in a supply chain attack discovered on July 27, 2026. The malicious...
og:url: https://daily.dev/posts/adform-s-ad-tracking-script-was-compromised-to-swap-cryptocurrency-wallet-addresses-0hio8awyf
og:image: https://api.daily.dev/og/posts/0Hio8Awyf.png
og:image:alt: Adform&#x27;s ad tracking script was compromised to swap cryptocurrency wallet addresses
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Adform's ad tracking script was compromised to swap cryptocurrency wallet addresses

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Adform's widely-deployed JavaScript tracking script `trackpoint-async.js` was trojanized in a supply chain attack discovered on July 27, 2026. The malicious code polled the clipboard every three seconds, replacing Bitcoin, Ethereum, and TRON wallet addresses with attacker-controlled ones, and also rewrote wallet addresses displayed on web pages. The attack beaconed victim IP addresses and referrer URLs to a remote C2 server. With the script embedded across roughly 14,000 businesses, the potential reach was significant. Security researcher Kevin Beaumont uncovered the compromise, which had gone undetected for at least a week with no antivirus detections on VirusTotal. Adform removed the malicious code after being notified. The C2 server at `84.32.102.230:7744` is the primary indicator of compromise for defenders to block.

## Content

Adform, a digital advertising platform that serves roughly 1.5 billion ads daily and counts around 14,000 businesses as customers, was hit by a supply chain attack on July 27, 2026. Its JavaScript tracking script, `trackpoint-async.js`, was trojanized to steal cryptocurrency.

## What the malicious code did

The injected code polled victims' clipboards every three seconds, replacing any Bitcoin, Ethereum, or TRON wallet addresses it found with attacker-controlled ones. It also rewrote wallet addresses displayed directly on web pages. If a user noticed something was off and recopied the correct address, the script replaced it again.

Beyond the clipboard manipulation, the code beaconed victim IP addresses and referrer URLs back to an attacker-controlled server at `84.32.102.230:7744`.

Any website embedding Adform's ad infrastructure was potentially affected — users didn't need to interact with an ad for the script to run.

## Detection and response

Security researcher Kevin Beaumont discovered the attack. At the time of discovery, every security vendor on VirusTotal flagged the malicious files and domains as clean. The compromise appears to have gone undetected for at least a week.

Adform removed the malicious code shortly after it was flagged. The company has disclosed the incident but hasn't said how the initial compromise happened or how many users were affected. Adform states the code did not install persistent software on victims' machines.

Users who visited affected sites on July 27 are advised to clear their browser cookies.

## Ad blockers prevented this entirely

This is worth noting plainly: uBlock Origin and Wipr blocked Adform's domain outright, which meant the malicious script never loaded for users running either tool. The attack didn't require visiting a shady site or downloading anything — just loading a page that used Adform's infrastructure was enough. Ad blockers stopped it cold.

## Indicators of compromise

Defenders should look for outbound connections to `84.32.102.230:7744` and flag any unexpected modifications to clipboard content involving cryptocurrency wallet address patterns. The malicious version of `trackpoint-async.js` passed VirusTotal clean at the time of the attack, so signature-based detection alone wasn't sufficient.

## Community take

How the wider developer community reacted, aggregated from 1 discussion and 76 comments across hackernews (as of 2026-08-04).

**TL;DR:** Commenters broadly agree that ad blockers are a necessary security tool, not just a convenience, and treat this incident as further evidence that third-party ad scripts are an inherent attack surface. A vocal minority pushes back on the article's framing, arguing the real fix is better browser security or disabling clipboard API access entirely.

**Sentiment:** 15% positive · 25% mixed · 60% skeptical

**The case for**

- Ad blockers like uBlock Origin provide a meaningful security layer by preventing malicious third-party scripts from executing at all.
- DNS-level blocking adds another defensive layer, especially for non-technical users on mobile devices.
- Disabling clipboard events in Firefox (dom.event.clipboardevents.enabled=false) would have independently prevented this specific exploit.
- The attack's blockchain footprint (~$165k across Bitcoin and ETH wallets) confirms the technique is financially effective, validating the threat.

**The pushback**

- The article's framing is called fallacious — a supply chain compromise argues for better browser security, not specifically ad blockers.
- Ad blockers alone don't solve surveillance; even a 'secure' browser loading ads enables tracking.
- Clipboard API access by browsers is the deeper architectural problem that ad blockers only work around, not fix.
- Ad blockers themselves could theoretically be compromised, shifting rather than eliminating the trust problem.

**By community**

- hackernews (mixed): Strongly sympathetic to ad blocking as a security necessity, but divided on whether the incident proves the case for blockers specifically versus exposing deeper browser API and supply-chain security failures.

**Hottest debate:** Whether this incident proves ad blockers are the right solution or whether it exposes a more fundamental problem with browsers granting JavaScript access to the system clipboard.

**Open questions**

- How was Adform initially compromised, and what does that mean for the security of other ad networks?
- How many users were actually affected and what is the total financial damage?
- Should browsers restrict or gate clipboard API access by default, and what would break if they did?
- Will ad networks face any meaningful legal or regulatory consequences for enabling malware delivery at scale?

**Highlights**

> You can disable it on Firefox by setting dom.event.clipboardevents.enabled to false. I haven't had any issues with it. Someone shared the code in the comments, it uses 'copy' and 'cut' event listeners, so disabling this setting would have prevented the exploit regardless of an adblock.
> — [afarah1 on hackernews · 1 comments](https://news.ycombinator.com/item?id=49172813)

> The code in question is here: https://pastebin.com/raw/mc7psaNF It appears to be normal Adform code plus two appended chunks at the end.    Bitcoin: bc1qmplgt0hcg62jc2guz86wn2sms7tqrsulkkrrls    Ethereum: 0xE7983E69df17079ADb0aD7b3458488Cac0dBc573    TRON: TW4AgGnDc2Pk6YAynCtjCKzoKYWPg7nJe (?) Edit: Activity for those addresses: ~$110k bitcoin https://www.blockchain.com/explorer/addresses/btc/bc1qmplgt0... ~$55k in ETH https://www.blockchain.com/explorer/addresses/eth/0xE7983E69...
> — [strictnein on hackernews · 2 comments](https://news.ycombinator.com/item?id=49170769)

> I read an article a while ago about some scientist who decided that he wanted to go around investigating a certain species of leech that lives inside a hippo's butt, like attached directly to the colon. He suggested that, as big as the hippo is, it probably wasn't really all that aware that the leeches are even in its butt, but that's where the leech likes to be because there's a good source of blood there for the leech to feed on. Now, the scientist is probably right, the hippo probably goes its whole life not really knowing that it has all these leeches in its butt. It might feel a little pain in the butt, but the hippo probably isn't concerned with why that pain is there, much less how or even if it can get rid of it, it's just something that the hippo has always lived with. The hippo accepts that one of the facts of daily life is that you just need to live with some pain in your butt. Now, imagine (and believe me, this is a hypothetical), if the hippo let someone root around inside its butt and remove every one of the leeches, and even stop any others from attaching. It might take a day or two to get used to and get back to normal, but the hippo would wake up one day and realize that it no longer has a pain in its butt. It can still do everything it used to do, it can frolic in the water, it can roam around and find the tender little pieces of grass, it can do that thing where it poops and swishes its tail around to spread it all over its neighbors, and it realizes that it can do all of those things it likes without having that pain in its butt. Now, maybe the leeches could talk. Maybe the leeches talk to the hippos and they say things like, listen, hippo, my life cycle depends on you letting me get into your butt when you're in the water. I need to drink your blood and drop out some eggs, so that other leeches can be born and start the cycle all over again. It's not really a big price you pay, I mean sure, there's a little pain in your butt, but I need you to do this. If you want to get in the water, it's just something you have to deal with. It's the price of admission. If you get in the water without letting me in your butt, it's like you're stealing the water. I bet that the hippo would hear that, and would still want to continue going about its day without any pain in its butt. I don't think the hippo would feel very sorry for the butt leech. Sure, maybe the butt leech contributes to the aquatic ecosystem, maybe its eggs or the dead leeches get eaten by other things and fertilize the grass that the hippo likes to eat. But, if the leeches weren't there, the grass would just find other nutrients. Even though the leech is trying to argue that it's a necessary part of this ecosystem, it's actually just a pain in the butt. In reality, despite what it tells everyone else, the major beneficiary of anything that the butt leech does is the actual butt leech. Anyway, I just had a thought that advertisers kind of sound like hippo butt leeches.
> — [datakan on hackernews · 2 comments](https://news.ycombinator.com/item?id=49172395)

> "You will be annoyed" and "you will be served malware" are two different classes of need. The first is enough to get me running Firefox/uBlock Origin on my own devices. The second is what got me to run it at work.
> — [ksenzee on hackernews](https://news.ycombinator.com/item?id=49170491)

> > Granted, even in the 1990s there were ads; the ads in the 90s were served by the same server of the site you were browsing. those ads were images. today's ads are from 3rd party servers running arbitrary JS code that the server of the site you are browsing knows nothing about how it works. ads from the 90s while possibly obnoxious and annoying were not able to be malicious as ads from today.
> — [dylan604 on hackernews](https://news.ycombinator.com/item?id=49173252)

**Source threads**

- [hackernews](https://news.ycombinator.com/item?id=49170001) · 194 points · 76 comments

## Similar posts on daily.dev

- [Crypto Heist Fueled by Elaborate Fake Reputation Campaign](https://daily.dev/posts/crypto-heist-fueled-by-elaborate-fake-reputation-campaign-jl8cj7yzf) · Dark Reading · 1 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#javascript](https://daily.dev/tags/javascript), [#crypto](https://daily.dev/tags/crypto)

[View this post on daily.dev](https://daily.dev/posts/adform-s-ad-tracking-script-was-compromised-to-swap-cryptocurrency-wallet-addresses-0hio8awyf)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Adform's ad tracking script was compromised to swap cryptocurrency wallet addresses","url":"https://daily.dev/posts/adform-s-ad-tracking-script-was-compromised-to-swap-cryptocurrency-wallet-addresses-0hio8awyf","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/adform-s-ad-tracking-script-was-compromised-to-swap-cryptocurrency-wallet-addresses-0hio8awyf"},"datePublished":"2026-07-31T21:29:50.805Z","dateModified":"2026-08-04T21:38:33.301Z","description":"Adform's widely-deployed JavaScript tracking script `trackpoint-async.js` was trojanized in a supply chain attack discovered on July 27, 2026. The malicious...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ed7e1b25912fda6d13efb9329d8aa5ea?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ed7e1b25912fda6d13efb9329d8aa5ea?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/adform-s-ad-tracking-script-was-compromised-to-swap-cryptocurrency-wallet-addresses-0hio8awyf","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,javascript,crypto","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Adform's ad tracking script was compromised to swap cryptocurrency wallet addresses"}]}
```

