Back to all lessons
Awareness Lessons
2 months ago

Poisoned Ad Script Hijacks Crypto Wallet Addresses Across Multiple Sites

Attackers compromised a trusted third-party JavaScript file served by Adform, a widely used advertising platform, turning it into a real-time crypto address hijacker across all customer websites that loaded the script. This is a classic supply chain attack: rather than targeting individual sites, adversaries exploited a single upstream vendor to achieve broad reach with minimal effort. The malicious code silently swapped legitimate cryptocurrency wallet addresses, meaning victims had no visual warning that their funds were being redirected. This incident underscores the critical risk of implicitly trusting externally hosted scripts, which inherit the attack surface of the vendor's entire infrastructure.

Tactical Insight

Immediate actions

  • Audit all third-party JavaScript dependencies and verify their integrity using Subresource Integrity (SRI) hashes.
  • Instruct end-users and internal teams to clear browser caches and verify wallet addresses through an independent source before completing any cryptocurrency transaction.

Long-term improvements

  • Implement a Content Security Policy (CSP) to restrict which external scripts are permitted to execute on your web properties.
  • Establish a formal third-party vendor risk management program that includes periodic security assessments of all script and CDN providers.
  • Self-host or pin critical third-party scripts where possible, and route updates through an internal review and approval process.

Detection measures

  • Deploy real-time script integrity monitoring tools (e.g., PerimeterX, Reflectiz, or custom hash checks) to alert on unexpected changes to loaded JavaScript files.
  • Enable detailed client-side logging and anomaly detection to identify unusual DOM manipulation or form-field modification activity across customer-facing pages.