By the sounds of it they removed the ad as soon as they knew about it.
No ad network is 100% malware free this is a sad reality.
The malware group that is using goolge's short url's has been at it for well over 2 years using this same setup. With their trigger being once per IP and targeting select browsers add to this them turning it on and off at different times of the day and sometimes off days at a time it makes it rather hard for any ad network to find before it's in the wild.
They have affected not only adult sites/ad networks but are also in the wild on the top main stream networks.
Chrome/google has flagged a number of times its own goo.gl short url service as an issue.
Google Safe Browsing diagnostic page for goo.gl