
Hacks are evolving and nobody is safe! “Even if you notice the wrong address and copy yours again, it swaps it back” Kevin Beaumont, the researcher who found this new attack vector said that He discovered a crypto stealer hiding inside Adform's ad tracking script And Adform serves one JavaScript file, trackpoint-async.js, to roughly 14,000 companies About 30% of the ad market Compromise it once and you’re on every one of those sites simultaneously Here's what the code did: Watched for Bitcoin, Ethereum and TRX addresses Polled the clipboard every few seconds and swapped in attacker wallets Then it walked the entire page Text nodes Input fields Textareas Contenteditable boxes It hooked the value setter so even programmatically written addresses got rewritten in transit Intercepted copy, cut, paste and input events and even restored your cursor position so nothing looked wrong So it’s not just basic clipboard malware You could copy the correct address, paste the correct address, and still lose everything Nothing is safe in Web3












