Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.
Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities.
Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin, Ethereum, or Tron address may have pasted a different address inserted by the malicious code instead.
Adform is telling people to clear their browser cache because the altered file may remain cached after the fix, and to check any wallet address before sending funds.
Adform says…








