1,800 Business Websites Were Quietly Stealing From Their Visitors Last Week. The Owners Did Nothing Wrong.
Picture this. A customer is on your website. They copy a cryptocurrency wallet address to make a payment. They paste it, glance at it, and hit send. The money lands in someone else’s account. And your website did it to them.
That’s not hypothetical. That’s what happened last week, and none of the businesses involved did anything wrong.
On July 26, 2026, attackers quietly modified a JavaScript file called trackpoint-async.js, a tracking script served by Adform from their CDN at s2.adform.net.[1] Adform is one of the larger advertising technology companies in the industry, with roughly 1,800 business customers and about 1.5 billion ads served daily across more than 180 countries.[2] Every one of those customer websites loaded that same script.
The poisoned version did something simple and effective. It monitored visitors’ clipboards in real time. Any time someone copied a Bitcoin, Ethereum, or TRON wallet address, the script replaced it with an address controlled by the attackers. It also rewrote wallet addresses displayed on the page itself. Security researcher Kevin Beaumont, who uncovered the compromise, flagged what made it particularly nasty: “Even if you notice the address is wrong and recopy the wallet, it keeps replacing it.”[1]
Adform caught it the same day, July 27, and pulled the malicious code. The incident went public on July 31. The window was about 24 hours. The whole thing ran entirely inside visitors’ browsers, no malware installed on anyone’s machine, no servers compromised at any of the 1,800 affected businesses.
This Is the Category of Attack Worth Understanding
There’s a reason the phrase “supply chain attack” keeps showing up in security news. It’s because attackers have figured out that breaching one vendor is more efficient than breaching thousands of individual targets. You get the same access, at scale, through a trusted channel.
The businesses running Adform’s script didn’t fail to patch anything. They didn’t fall for a phishing email. They trusted a vendor that got compromised. Your browser doesn’t know the difference between legitimate Adform code and poisoned Adform code. Neither does your firewall. The compromise came in through a trusted route.
We’ve seen versions of this before. Earlier this year, attackers hijacked update servers for a WordPress plugin vendor and pushed backdoored code to paying customers automatically.[3] The common thread: the malicious code arrived through the normal software delivery channel. That’s what makes it hard to catch.
What Third-Party Scripts Are Actually Running on Your Website
If you run a business website, there’s a good chance you have more third-party JavaScript on it than you realize. Analytics tools. Chat widgets. Ad tracking pixels. Cookie consent banners. Booking and scheduling tools. Review and rating widgets. Payment integrations. Each one is a script your site loads from somewhere else. Each one is a company you’re implicitly trusting with access to your visitors’ browsing session.
Most small business owners have no idea how many of those are on their site, where they load from, or when they were last audited. That’s not a criticism. It’s just how these tools get added over time. Your marketing team added a pixel. Your developer dropped in a chat widget. Nobody kept a list.
The first practical step is getting that list. A web developer can audit this in an hour, maybe less. If you’re running WordPress, plugins often add third-party scripts without surfacing them anywhere obvious. You might find things you forgot were even on the site.
What Reduces the Risk
There are a few things worth considering. None of them are complex or expensive.
A Content Security Policy (CSP) is a configuration you set on your web server that tells browsers which scripts are allowed to run on your site and what those scripts are allowed to do. It won’t stop a vendor’s server from getting compromised, but it can limit what a compromised script is actually capable of. A strict policy might have blocked the clipboard access that made the Adform attack work.
Beyond that, it’s worth thinking about which third-party tools you actually need. Every script you remove is one less dependency, one less potential vector. Some of those widgets and pixels are delivering real value. Some are leftovers from a campaign that ended two years ago. Worth knowing which is which.
And if your site handles any kind of payment information, account numbers, or wallet addresses, that’s a higher-stakes environment. Third-party scripts in that context deserve more scrutiny, not less.
The bigger takeaway from the Adform incident is one that keeps coming up in this space: your security posture includes your vendors. A breach at one of them can affect your customers through your website, and those customers are going to associate the experience with you. It’s worth knowing what you’re loading and where it comes from.
Want help auditing what’s running on your website, or putting some basic protections in place? Reach out here or give us a call at (412) 307-8313.
- BleepingComputer, “Online ad firm Adform’s script compromised to steal cryptocurrency,” bleepingcomputer.com
- The Hacker News, “Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites,” thehackernews.com
- Caruso Tech Services, “Hackers Hijacked a WordPress Plugin Vendor’s Updates. The Backdoor Installed Itself.,” carusotechservices.com