Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

What we know about the cryptocurrency theft through Adform ads | Kaspersky official blog

0
Medium
Published: 08/11/2026 (08/11/2026, 14:18:13 UTC)
Source: Kaspersky Security Blog

Description

Adform, a major advertising platform, remained compromised for roughly 24 hours from late on July 26 through the evening of July 27 after being breached by unknown attackers. Few people outside the industry recognize the name, but Adform serves around 1.5 billion ad impressions every day across tens of thousands of websites. That means anyone visiting any site that runs Adform ads could have been targeted. The attackers weren’t trying to install malware. Instead, they ran a script in the victim’s browser that checked the clipboard every three seconds, and if it found a cryptocurrency wallet address had been copied, swapped it for the attackers’ own wallet address. So if someone had a site with the malicious ad open in one browser tab, and was making a crypto transaction in another tab or in a dedicated app, the funds could have ended up in the attackers’ pockets instead. Adform’s owners caught the attack and fixed the problem, but there’s no guarantee a similar incident won’t happen again — which is why every user should defend themselves against malvertising . Check out our tips at the end of this post. What we know about the attack on Adform There isn’t a lot of information out there, since the company’s official statement covers only what happened and when, without getting into the root cause of the incident. Independent research has dug up technical details about how ordinary users were targeted, but none of that explains how Adform itself was breached in the first place. What’s clear is that the attackers slipped their own code into the JavaScript that loaded on every site running Adform ads. Whenever an ad was about to display, the script would load from Adform’s server, pick the right ad, and show it — but the attackers had tacked on a set of malicious functions: monitoring the clipboard, sending data about the site where the encounter happened, and the victim’s IP address back to their own server, and swapping out Bitcoin, Ethereum, and Tron wallet addresses. All it took to make it work was having any site with Adform-served ads open in one browser tab. It didn’t matter what kind of site it was, what the ad looked like, or which advertiser it belonged to. The one thing that mattered was whether the site ran over HTTP or HTTPS. According to Adform, the attack couldn’t succeed on a site loaded over HTTPS since the connection to the attackers’ server was blocked in this case. The company hasn’t shared any information on how many users were affected, or how many sites still serve their content and ads over HTTP. Malicious ads are an everyday occurrence Unfortunately, dangerous online ads have become a systemic problem. And we’re not just talking about sketchy supplement ads or gambling promos — we mean ads that spread malware or lead to sites designed to steal payment details and other valuable data. Attackers have built out industrial-scale infrastructure to pull this off, and they use several different approaches. Hacking and compromising ad servers. Adform isn’t an isolated case: attackers have previously breached Revive ad servers , for one, and spread malware through ads on PornHub . Hijacking the ad accounts of legitimate, reputable brands . All it takes is stealing a password from someone in marketing. From there, the cybercriminals run ads posing as the company they hacked, pushing fake app updates, bogus promotions, and similar scams. In the worst cases — like the account breaches at adtech.de and adxpansion.com — attackers managed to run ads that redirected victims straight into automatic malware installs ( drive-by downloads ). Buying ads directly. That’s right — attackers simply set up their own advertiser accounts and run ads for their phishing sites and malware, just like any other business online. Since ads show up practically everywhere — on websites, in apps, and on social media — these threats can turn up in pretty much any context. And you’ll find variations of this threat on both computers and mobile de…

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 14:21:22 UTC

Technical Analysis

In late July 2026, attackers breached Adform's advertising platform and injected malicious JavaScript into ads served on approximately 1.5 billion daily impressions across many websites. The malicious script ran in users' browsers, checking the clipboard every three seconds for cryptocurrency wallet addresses and replacing them with attacker-controlled addresses for Bitcoin, Ethereum, and Tron. This attack vector did not rely on malware installation but on clipboard hijacking via injected ad scripts. The attack was effective only on sites served over HTTP, as HTTPS connections prevented the malicious script from communicating with the attackers' server. Adform detected and remediated the breach within 24 hours but has not disclosed the breach's root cause or the number of affected users. This incident exemplifies the growing threat of malvertising, where attackers compromise ad servers or accounts to distribute malicious code at scale.

Potential Impact

The attack enabled attackers to intercept and redirect cryptocurrency transactions by replacing wallet addresses copied to victims' clipboards with attacker-controlled addresses. This could result in financial theft from users performing crypto transactions while having a site with compromised Adform ads open. The attack did not involve malware installation, reducing detection likelihood. The scope was potentially large given Adform's extensive ad network, but the attack was limited to sites served over HTTP. The breach undermines trust in online advertising platforms and exposes users to covert financial theft risks.

Defensive Guidance

Adform detected and fixed the breach within approximately 24 hours. Users should prefer accessing sites over HTTPS, as the attack was ineffective on HTTPS sites due to blocked malicious server connections. Blocking or limiting exposure to online ads via secure DNS with content filtering, ad and tracker blockers, and browser protection extensions can reduce risk. Security solutions that analyze browser activity and block malicious scripts provide additional protection. Users should remain vigilant against malvertising threats and apply recommended security measures to mitigate similar future incidents.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.64,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.kaspersky.com/blog/adform-compromise-malicious-ads-cryptocurrency-theft/56257/","fetched":true,"fetchedAt":"2026-08-11T14:21:09.410Z","wordCount":1487}

Threat ID: 6a7b2fd5bf8831d539db4f9d

Added to database: 08/11/2026, 14:21:09 UTC

Last enriched: 08/11/2026, 14:21:22 UTC

Last updated: 08/12/2026, 01:42:22 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses