Malware that swaps what you copy: an ad script quietly rewrote crypto addresses on thousands of sites
You copy a long string of characters, paste it into a payment box, and hit send. That's the moment a particularly sneaky kind of malware waits for - and one just played out on a large scale.
BleepingComputer and The Hacker News reported that the advertising firm Adform had one of its tracking scripts, trackpoint-async.js, tampered with around July 26-27, 2026. Adform's code sits on a lot of ordinary websites - the company's own report cites roughly 1,800 business customers - so the poisoned version reached plenty of everyday visitors. What it did was clever and quiet: it watched the clipboard every few seconds, and if it spotted a Bitcoin, Ethereum, or TRON wallet address, it silently swapped in one belonging to the attacker. It also rewrote addresses shown directly on web pages. Copy your friend's wallet to send them money, and you'd paste the crook's instead. The unsettling part: at the time, security researcher Kevin Beaumont found not a single antivirus engine on VirusTotal flagged it, because the malicious code lived on a trusted website, not on your PC.
This "clipboard hijacking" trick isn't limited to crypto or to one ad company - the same idea can quietly change a bank account number or any long code you paste. The habit that beats it costs two seconds: after you paste anything that matters, glance at the first and last few characters and confirm they match what you copied. For crypto, send a tiny test amount first. Adform says it removed the code the same day; clearing your browser's cookies flushes out any leftover.
Antivirus can't catch everything, especially a script running on a legitimate site, which is why that paste-check habit matters. Tendvane isn't an antivirus, but its Safety check does surface unexpected browser extensions and startup programs - the kind of leftovers a clipboard-swapping infection tends to drop if one ever lands on your machine.