Polygon smart contracts under attack, but the real danger may be just starting!

ambcryptoPublicado em 2026-01-17Última atualização em 2026-01-17

Resumo

Blockchain technology's growth is increasingly exploited by threat actors, as evidenced by the DeadLock ransomware. This group uses Polygon smart contracts to dynamically rotate server addresses, making their infrastructure more resilient and evading traditional disruption methods. This highlights a concerning shift where decentralized systems, originally designed to prevent centralized abuse, are now being weaponized. Security firm Group-IB warns this is part of an emerging trend, citing similar campaigns like North Korea's UNC5342 using "EtherHiding" on Ethereum. The abuse of smart contracts for malware distribution and ransomware operations signals a deeper, growing threat to blockchain networks.

As blockchain adoption continues to grow, so does its misuse.

At a fundamental level, the technology is widely used to improve liquidity and efficiency across industries. However, threat actors are now leveraging it to make their infrastructure more resilient and harder to disrupt.

DeadLock ransomware is a clear example of this shift. According to Group-IB research, DeadLock uses Polygon [POL] smart contracts to rotate server addresses, allowing it to evade traditional detection methods.

Naturally, this puts the broader decentralization narrative under scrutiny.

In this case, Polygon smart contracts are the ones under pressure. Why does this matter? Blockchain technology was originally designed to prevent the kind of abuse historically seen in traditional, centralized systems.

However, the use of Polygon smart contracts to support ransomware operations shows that decentralized infrastructure can also be exploited by threat actors, raising the question: What does this mean for the network?

Polygon smart contracts – Part of an emerging malware trend

Looking closely, DeadLock isn’t just another ransomware.

In a centralized system, stopping an attack can be as easy as flipping a switch. However, with decentralized setups like Polygon smart contracts, teams can’t just “turn it off” as the control is baked into the core of the network.

Notably, that’s exactly what this technique is taking advantage of. And now, imagine this as part of an “emerging trend” where more attacks are likely to leverage smart contracts across other blockchain platforms.

That brings us to what Group-IB analysts are warning about.

As shown in the chart above, Google recently reported that the North Korean (DPRK) threat actor UNC5342 used a technique called “EtherHiding.” This leverages blockchains to store and retrieve payloads.

Meanwhile, another campaign used Ethereum [ETH] smart contracts which were then used to download second-stage malware. In short, the DeadLock trick with Polygon smart contracts isn’t the end of this trend.

Instead, it could be just the start of deeper smart contract abuse.


Final Thoughts

  • DeadLock ransomware exploits Polygon smart contracts to rotate server addresses, showing how decentralized infrastructure can be abused.
  • Smart contract abuse is an emerging trend, with other campaigns like UNC5342 signaling deeper threats across blockchain platforms.

Perguntas relacionadas

QWhat is the primary method used by DeadLock ransomware to evade detection, according to the article?

ADeadLock ransomware uses Polygon smart contracts to rotate server addresses, allowing it to evade traditional detection methods.

QWhy can't teams simply 'turn off' an attack when it uses decentralized setups like Polygon smart contracts?

ABecause the control is baked into the core of the network in decentralized setups, making it impossible to just 'turn it off' like in a centralized system.

QWhat emerging trend in malware attacks does the article highlight beyond the DeadLock case?

AThe article highlights an emerging trend where threat actors are leveraging smart contracts across various blockchain platforms to store and retrieve payloads or download malware, as seen with campaigns like UNC5342 using Ethereum smart contracts.

QWhich threat actor used a technique called 'EtherHiding' to leverage blockchains, as mentioned in the article?

AThe North Korean (DPRK) threat actor UNC5342 used a technique called 'EtherHiding' to leverage blockchains for storing and retrieving payloads.

QWhat does the abuse of Polygon smart contracts by ransomware operations raise questions about?

AIt raises questions about the security and implications for the network, as decentralized infrastructure can be exploited by threat actors, contrary to blockchain's original design to prevent abuse in centralized systems.

Leituras Relacionadas

13 Business Lines Surpass $100 Million in Annualized Revenue, Robinhood Moves Toward a 'Super Financial App'

Robinhood Q2 2026 Earnings: Record Revenue and a Push Towards a "Super Financial App" Robinhood (HOOD) reported strong Q2 2026 results, with net revenue reaching $1.308 billion, up 32% year-over-year, and net income hitting $561 million, a 45% increase. The company now has 13 distinct business lines each generating over $100 million in annualized revenue. Key drivers included a 44% surge in transaction-based revenue to $776 million, led by a more than 10x growth in "event contracts" (prediction markets) and strong performance in stocks and options. User metrics also grew, with funded accounts rising to 28.4 million and total assets under custody reaching $369 billion. The Robinhood Gold subscription service hit a record 4.8 million users. The report highlights a strategic shift for Robinhood. Moving beyond its core as a zero-commission trading platform for retail investors, it is actively building a broader financial ecosystem. This includes expanding into wealth management (Robinhood Strategies), payments (Robinhood Credit Card), and next-generation infrastructure like AI-powered "Agentic Trading" and its own Ethereum Layer 2 blockchain, Robinhood Chain. The company's goal is to evolve from a trading app into a comprehensive "super financial app," offering a one-stop shop for investing, cash management, and future on-chain finance.

Odaily星球日报Há 10m

13 Business Lines Surpass $100 Million in Annualized Revenue, Robinhood Moves Toward a 'Super Financial App'

Odaily星球日报Há 10m

13 Business Lines Surpass $100 Million in Annualized Revenue, Robinhood Advances Toward a 'Super Financial App'

On July 30th, Robinhood (HOOD) reported its Q2 2026 financial results, showcasing significant growth with record revenue and profits. The company achieved a net revenue of $1.308 billion, a 32% year-over-year (YoY) increase, and a net income of $561 million, up 45% YoY. This strong performance was driven by robust trading activity and expansion into new financial services. A key highlight was the surge in transaction-based revenue, which rose 44% YoY to $776 million. Notably, income from event contracts (prediction markets) skyrocketed over 10x to $156 million, emerging as a major new growth driver alongside strong gains in stock and options trading. However, crypto trading revenue declined by 38%. Beyond trading, Robinhood is successfully diversifying its revenue streams. User assets grew 32% to $369 billion, and the subscription service Robinhood Gold reached a record 4.8 million users. The company revealed that 13 of its business lines now generate over $100 million in annualized revenue, including its new credit card, prediction markets, and Gold subscriptions. Looking forward, Robinhood is strategically investing in AI and blockchain to build a comprehensive financial ecosystem. It has launched AI-powered "Agentic Trading" and the "Robinhood Chain," a layer-2 blockchain network. The company's vision is evolving from a retail trading platform into a "super financial app" that integrates trading, wealth management, payments, and next-generation digital asset services, though regulatory hurdles remain for some new ventures.

marsbitHá 11m

13 Business Lines Surpass $100 Million in Annualized Revenue, Robinhood Advances Toward a 'Super Financial App'

marsbitHá 11m

After R&D Investment Catches Up with the U.S., Is the Sino-U.S. Chip Competition Still Just About Money?

The article examines the significance of recent data showing China's total R&D expenditure, measured by purchasing power parity (PPP), catching up to or slightly surpassing that of the United States in 2024. It argues that while this milestone reflects China's immense capacity to mobilize research resources, the competition in semiconductors now extends far beyond sheer financial input. The analysis highlights key differences: China's R&D is heavily skewed towards experimental development (over 80%), focusing on product engineering and industrialization, whereas the U.S. allocates a proportionally larger share (about 15%) to basic research. Furthermore, leading U.S. semiconductor firms reinvest a significant portion of their substantial global sales revenue into R&D, creating a sustainable commercial innovation cycle that is difficult to replicate. The article emphasizes that semiconductor progress depends on converting R&D into commercially viable products that pass rigorous customer validation and achieve repeat orders, not just on spending levels. It concludes that as China enters the top tier of R&D spenders, the critical challenges shift to improving resource allocation efficiency, fostering long-term basic research, and building effective mechanisms to bridge the gap between laboratory discoveries and reliable, market-ready industrial capabilities.

marsbitHá 1h

After R&D Investment Catches Up with the U.S., Is the Sino-U.S. Chip Competition Still Just About Money?

marsbitHá 1h

Trading

Spot
活动图片