Online ad giant Adform was hacked, proving once again why ad blockers are needed
A major online advertising platform, Adform, was compromised and used to silently inject clipboard-hijacking crypto malware via ads, reigniting concerns over the safety of third-party ad networks. Commenters argue that ad blockers now function as essential security tools as well as annoyance filters, while debating the broader economics and ethics of an ad-funded internet versus alternatives like paywalls, regulation, or more restrictive browser security. Many see today’s dynamic, JavaScript-heavy ad systems as a systemic risk that users cannot reasonably consent to or control.
Nature of the Adform Compromise & Crypto Theft
- Adform’s ad infrastructure was reportedly used as a supply‑chain vector to deliver a clipboard‑hijacking script.
- The malicious code appended to legit Adform JS swapped copied crypto wallet addresses with attacker-controlled ones (BTC, ETH, TRON).
- Shared blockchain explorers show at least ~$110k in BTC and ~$55k in ETH passing through associated addresses, suggesting the attack was financially worthwhile despite its apparent “niche” angle.
- Funds have been further moved through other wallets, as expected for laundering/obfuscation.
Security Implications of Ads
- Many see this as confirmation that third‑party, script-based ads are a major security risk: arbitrary JS from ad networks can be compromised without site owners knowing.
- Some argue DNS-level and network-level ad blocking plus firewalls (e.g., blocking non‑standard ports) should complement browser ad blockers.
- Others note that DNS blocking is limited when content and ads share the same domain (e.g., YouTube).
Clipboard & Browser Permissions
- The attack leveraged clipboard events to overwrite crypto addresses; commenters are surprised browsers allow JS to touch the system clipboard at all.
- Suggestions include disabling clipboard events (e.g., via browser flags) or preventing scriptable clipboard access entirely, while preserving user-initiated copy/paste.
- Broader concern: browsers expose too many OS capabilities (clipboard, USB, screen size, etc.).
Ad Blockers vs. “Better Browsers”
- One side claims hacked ad infrastructure shows the need for stronger browser security, not necessarily ad blocking.
- Others respond that even a “secure” browser still enables tracking and surveillance; blocking ads is framed as both a security and privacy prerequisite.
- Several compare browsing without an ad blocker to unprotected sex: risky, with users underestimating consequences.
Economics, Ethics, and User Experience
- Some argue modern ad‑funded internet is “parasitic,” pushing overconsumption and psychological manipulation; analogies liken advertisers to leeches on a host.
- Counterarguments stress that ads fund free services and that banning/undermining ads risks a more class‑stratified internet where only those who can pay get quality access.
- Disagreement persists on whether advertising is an economic “dead weight” that simply raises prices, or a normal business cost that can’t be cleanly removed.
Adoption Barriers & Regulation
- Many wonder why anyone still browses without an ad blocker; others note friction: mobile limitations, Chrome’s extension restrictions, unfamiliarity with alternatives.
- Some call for regulation of internet advertising rather than relying solely on individual adblocking.