
Adform's ad-serving code was altered to hijack crypto wallet addresses on 1.5B daily ads
Adform, which serves roughly 1.5 billion ads a day, began delivering maliciously altered ad-loading code on 27 July 2026 that rewrote crypto wallet addresses in the clipboard every three seconds. Kevin Beaumont, who surfaced it, showed that any publisher embedding Adform passed the payload straight to visitor devices — which makes a network-level ad blocker a working defense, since blocking the domain stops the code from ever loading. Adform has not disclosed how it was breached or how many people were affected, and says attackers may have accessed records of which sites victims visited.
Source: this.weekinsecurity.com ↗
This allows end user devices of downstream websites to be compromised with crypto stealing malware. Meaning if you visit example.com and they use Adform, example.com will compromise your device.
Why this matters
- → 1.5B daily ads compromised; crypto theft malware reached millions via trusted ad networks
- → Ad blockers proved essential — blocking Adform's domain prevented payload execution entirely
- → Adform withheld breach details: how breached, victim count, data exfiltration scope unknown