Adform Hacked to Serve Crypto-Stealing Malware — Ad Blockers Prove Their Worth

Online ad giant Adform was hacked, proving once again why ad blockers are needed

Adform Hacked to Serve Crypto-Stealing Malware — Ad Blockers Prove Their Worth

Adform, a major online advertising provider serving 1.5 billion ads daily, was compromised on July 27, 2026, when malicious code was injected into its ad-loading scripts. The code, triggered in users' browsers, replaced crypto wallet addresses in clipboard with hacker-controlled ones every three seconds, potentially redirecting cryptocurrency transactions. Security researcher Kevin Beaumont first revealed the incident, noting that any site using Adform could compromise visitors' devices. Adform has disclosed the breach but hasn't detailed the initial compromise or affected users. The incident underscores the security benefits of ad blockers, which can prevent such malicious code from loading.

This allows end user devices of downstream websites to be compromised with crypto stealing malware. Meaning if you visit example.com and they use Adform, example.com will compromise your device.
  1. strictnein

    Probably should just link to the security researcher's post, since it's far more informative:

    https://doublepulsar.com/adform-compromised-to-serve-crypto-...

  2. CM30

    It's definitely proof that dynamic ads added via an external script library are a massive security risk, that's for sure. Even if the provider doesn't actually get hacked like Adform here, you're still banking on them being able to reject/filter out malware and malicious ads, which plenty of 'credible' networks seem completely unable or unwilling to do.

    Going online without an adblocker just feels like playing with fire, especially nowadays.

  3. __MatrixMan__

    Ads are malware. It's not really surprising when they're found to be bootstrapping other malware.

  4. werds

    Are the crypto addresses known/recorded anywhere? would be interesting to see on the blockchain how much was stolen this way.

  5. tamimio

    Ad blockers at dns level too, not just browsers. A lot of people don’t even know how to block them, check your parents or kids (or non technical people in general) phone and you will see how they are riddled with ads. I had a dns blocker installed on my parents phones and in around 6hrs it blocked 10k queries from 3 apps only..

  6. functionmouse

    I have a feeling everyone with understanding of the situation or even a vague malaise opening a news article and being bombarded with popups that intercept their attention knows why ad blockers are needed, and any perceived "discourse" to the contrary is one sided, from the ad agencies and media platforms that largely and subversively direct the narrative.

    It's getting harder by the day to tell sentiment apart from narrative.

  7. shevy-java

    The sad thing is that we need adblockers in the first place.

    Granted, even in the 1990s there were ads; I remember blinking banners and what not. But often the underlying website was still fine as such.

    Fast forward some years. Now if you look at e. g. medium.com but many other websites, you are CONSTANTLY bombarded with pointless pop-ups, slide-ins, and pester-naggers. No I do use ublock origin (it works on thorium by default) so I only get very few ads, but many websites just pursue a strategy to piss off visitors. I do not understand this. If you want anyone to read your content, do not pester them at all. Nowadays when a slide-in appears that sneaks through ublock origin, I don't even let ublock origin block it, I just insta-close that tab. Cookie accept banners fall into the similar category, though some add-ons help with that.

  8. jimt1234

    Browsers should not have access to the clipboard.

More from this day

2026-08-04