New Ransomware Exploits Polygon Smart Contracts to Evade Detection Cybersecurity researchers have uncovered a novel ransomware operation, dubbed “DeadLock,” thatNew Ransomware Exploits Polygon Smart Contracts to Evade Detection Cybersecurity researchers have uncovered a novel ransomware operation, dubbed “DeadLock,” that

DeadLock Malware Attacks Polygon Smart Contracts to Stay Hidden

For feedback or concerns regarding this content, please contact us at [email protected]
Deadlock Malware Attacks Polygon Smart Contracts To Stay Hidden

New Ransomware Exploits Polygon Smart Contracts to Evade Detection

Cybersecurity researchers have uncovered a novel ransomware operation, dubbed “DeadLock,” that clandestinely exploits Polygon smart contracts to manage its command-and-control infrastructure. Despite its limited apparent impact thus far, the technique’s sophistication poses significant risks for organizations unprepared for blockchain-based threats.

Key Takeaways

  • DeadLock leverages Polygon smart contracts to store and rotate proxy addresses, making its infrastructure resilient and hard to disrupt.
  • The malware interacts with specific smart contracts to dynamically update communication channels, complicating detection and mitigation efforts.
  • Its low profile has kept it under the radar, but the innovative approach signals a dangerous evolution in blockchain-enabled cyberattacks.
  • Similar tactics, such as North Korean hacking groups employing “EtherHiding,” demonstrate the growing trend of covert malware deployment on public blockchains.

Tickers mentioned: None

Sentiment: Alert

Price impact: Neutral, as the threat pertains primarily to cybersecurity concerns rather than immediate market movements.

Trading idea (Not Financial Advice): Hold, as the broader market remains unaffected by this specific threat but should remain vigilant about blockchain-based vulnerabilities.

Market context: Rising cyber threats exploiting blockchain technology emphasize the need for enhanced security protocols within the crypto ecosystem.

Unveiling DeadLock’s Covert Operations

Cybersecurity firm Group-IB has reported the discovery of DeadLock, a ransomware strain first identified in July that uses a highly stealthy approach involving Polygon smart contracts. The malware exploits on-chain code to store and rotate proxy server addresses, facilitating communication with infected victims. As outlined by Group-IB, the malware interacts with a targeted smart contract, employing functions that permit the dynamic updating of command-and-control infrastructure—eschewing traditional centralized servers.

After infection and encryption, victims are typically met with ransom demands and threats to sell stolen data. The on-chain storage of proxy addresses ensures the infrastructure remains resilient against takedown attempts, as blockchain data is replicated across distributed nodes globally forever, making disruption exceedingly difficult.

HTML file with an embedded private messenger used to contact the threat actor. Source: Group-IB

Group-IB highlighted that this method allows for virtually unlimited variations, owing to the programmable nature of smart contracts. This adaptability means malicious actors can continually refine their techniques, potentially facilitating a wide range of blockchain-enabled cyberattacks.

Broader Threat Landscape: “EtherHiding” and State-Sponsored Actors

The use of smart contracts for malicious purposes is not new. Google previously reported a tactic called “EtherHiding,” employed by North Korean threat actors such as UNC5342, which embeds malicious payloads within blockchain transactions to serve as decentralized command-and-control servers. These methods leverage the resilience and permanence of blockchain technology to hide malware and evade traditional detection mechanisms.

As the use of blockchain for malicious purposes evolves, cybersecurity professionals emphasize the importance of vigilant monitoring and robust security measures to counteract these emerging threats, which continue to blur the line between legitimate blockchain activity and covert cyberattacks.

This article was originally published as DeadLock Malware Attacks Polygon Smart Contracts to Stay Hidden on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

Market Opportunity
Smart Blockchain Logo
Smart Blockchain Price(SMART)
$0.004171
$0.004171$0.004171
-2.02%
USD
Smart Blockchain (SMART) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

WAR Token Surges 56% as On-Chain Activity Signals Growing Adoption in Gaming Sector

WAR Token Surges 56% as On-Chain Activity Signals Growing Adoption in Gaming Sector

WAR token has recorded a remarkable 56% price increase over the past 24 hours, accompanied by $17.85 million in trading volume. Our analysis reveals interesting
Share
Blockchainmagazine2026/03/06 07:06
South Korea Consumer Price Index Growth (YoY) below forecasts (2.1%) in February: Actual (2%)

South Korea Consumer Price Index Growth (YoY) below forecasts (2.1%) in February: Actual (2%)

The post South Korea Consumer Price Index Growth (YoY) below forecasts (2.1%) in February: Actual (2%) appeared on BitcoinEthereumNews.com. GBP/USD edged lower
Share
BitcoinEthereumNews2026/03/06 07:37
CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10