A JavaScript modification on an Adform advertising technology site turned into a browser-side tool that rewrites cryptocurrency wallet addresses This article explores pasted altered address. . Anyone who visited sites carrying the modified script on July 27 could have pasted an altered address instead of their intended one.
Beaumont, an independent security researcher, revealed the compromise, stating, "Even if you notice the address is incorrect and re-enter the wallet, it keeps replacing it." Beaumont reported that the file and its associated URLs, domains, and IP addresses did not receive any detections on VirusTotal at the time. The second module iterates through the document's text nodes, updates the values within input, textarea, and contenteditable elements, and resets the cursor location afterward.
It stated in its incident report that "Technical analysis suggests such transmission could have been possible." The first payload's request sends a page hostname and path to an external server; this has yet to be confirmed as reaching the operator based on the sample data. The scope is still lacking: how many websites hosted the file, how many visitors were affected, how attackers gained access to Adform's deployment path, and whether any funds were diverted.
Their 2025 annual report indicates they had approximately 1,800 customers, processed over 1.5 billion ads daily, and served or transacted ads in more than 180 countries during that year.












