Polygon smart contracts under attack, but the real danger may be just starting!

ambcryptoОпубліковано о 2026-01-17Востаннє оновлено о 2026-01-17

Анотація

Blockchain technology's growth is increasingly exploited by threat actors, as evidenced by the DeadLock ransomware. This group uses Polygon smart contracts to dynamically rotate server addresses, making their infrastructure more resilient and evading traditional disruption methods. This highlights a concerning shift where decentralized systems, originally designed to prevent centralized abuse, are now being weaponized. Security firm Group-IB warns this is part of an emerging trend, citing similar campaigns like North Korea's UNC5342 using "EtherHiding" on Ethereum. The abuse of smart contracts for malware distribution and ransomware operations signals a deeper, growing threat to blockchain networks.

As blockchain adoption continues to grow, so does its misuse.

At a fundamental level, the technology is widely used to improve liquidity and efficiency across industries. However, threat actors are now leveraging it to make their infrastructure more resilient and harder to disrupt.

DeadLock ransomware is a clear example of this shift. According to Group-IB research, DeadLock uses Polygon [POL] smart contracts to rotate server addresses, allowing it to evade traditional detection methods.

Naturally, this puts the broader decentralization narrative under scrutiny.

In this case, Polygon smart contracts are the ones under pressure. Why does this matter? Blockchain technology was originally designed to prevent the kind of abuse historically seen in traditional, centralized systems.

However, the use of Polygon smart contracts to support ransomware operations shows that decentralized infrastructure can also be exploited by threat actors, raising the question: What does this mean for the network?

Polygon smart contracts – Part of an emerging malware trend

Looking closely, DeadLock isn’t just another ransomware.

In a centralized system, stopping an attack can be as easy as flipping a switch. However, with decentralized setups like Polygon smart contracts, teams can’t just “turn it off” as the control is baked into the core of the network.

Notably, that’s exactly what this technique is taking advantage of. And now, imagine this as part of an “emerging trend” where more attacks are likely to leverage smart contracts across other blockchain platforms.

That brings us to what Group-IB analysts are warning about.

As shown in the chart above, Google recently reported that the North Korean (DPRK) threat actor UNC5342 used a technique called “EtherHiding.” This leverages blockchains to store and retrieve payloads.

Meanwhile, another campaign used Ethereum [ETH] smart contracts which were then used to download second-stage malware. In short, the DeadLock trick with Polygon smart contracts isn’t the end of this trend.

Instead, it could be just the start of deeper smart contract abuse.


Final Thoughts

  • DeadLock ransomware exploits Polygon smart contracts to rotate server addresses, showing how decentralized infrastructure can be abused.
  • Smart contract abuse is an emerging trend, with other campaigns like UNC5342 signaling deeper threats across blockchain platforms.

Пов'язані питання

QWhat is the primary method used by DeadLock ransomware to evade detection, according to the article?

ADeadLock ransomware uses Polygon smart contracts to rotate server addresses, allowing it to evade traditional detection methods.

QWhy can't teams simply 'turn off' an attack when it uses decentralized setups like Polygon smart contracts?

ABecause the control is baked into the core of the network in decentralized setups, making it impossible to just 'turn it off' like in a centralized system.

QWhat emerging trend in malware attacks does the article highlight beyond the DeadLock case?

AThe article highlights an emerging trend where threat actors are leveraging smart contracts across various blockchain platforms to store and retrieve payloads or download malware, as seen with campaigns like UNC5342 using Ethereum smart contracts.

QWhich threat actor used a technique called 'EtherHiding' to leverage blockchains, as mentioned in the article?

AThe North Korean (DPRK) threat actor UNC5342 used a technique called 'EtherHiding' to leverage blockchains for storing and retrieving payloads.

QWhat does the abuse of Polygon smart contracts by ransomware operations raise questions about?

AIt raises questions about the security and implications for the network, as decentralized infrastructure can be exploited by threat actors, contrary to blockchain's original design to prevent abuse in centralized systems.

Пов'язані матеріали

MoonPay Launches PayBox

MoonPay, a developer of payment solutions for crypto and traditional currencies, has launched PayBox, a new type of payment wallet that enables AI assistants in Claude and ChatGPT to conduct transactions. Users can manage digital assets and pay for online services directly within chat interfaces. Upon user request, the AI can perform actions such as purchasing PYUSD, swapping tokens, cross-chain transfers, depositing funds into DeFi protocols, and booking flights. All transactions require user confirmation via an access key before execution. PayBox supports Solana and EVM-based blockchains like Ethereum, Base, Arbitrum, Polygon, Hyperliquid, Tempo, and Robinhood Chain, with plans to add more networks. It can store both crypto wallets and payment cards. Security is provided via MPC (Multi-Party Computation) technology and secure execution environments, ensuring no single entity—including MoonPay or the AI assistant—has full access to user funds. The wallet offers two permission modes: "Always Ask," requiring manual approval for each transaction, and "Standalone," where the AI can operate autonomously within user-set limits. Permissions can be modified or revoked at any time. PayBox is built on technology from Sodot, a secure crypto wallet solutions provider acquired by MoonPay earlier this year. This infrastructure reportedly secures over $50 billion in digital assets across more than 10 million wallets.

cryptonews.ru9 хв тому

MoonPay Launches PayBox

cryptonews.ru9 хв тому

Now the Greatest Regret Is to My Family: Crypto Experts Took a Stumble in the Stock Market

Summary: This article examines the significant losses recently suffered by cryptocurrency traders and influencers who ventured into the stock market, specifically by heavily investing in AI-related and semiconductor storage stocks. The narrative centers on the dramatic reversal in the Korean and US equity markets in late July, with stocks like SK Hynix and related leveraged ETFs experiencing historic plunges, erasing massive gains. The analysis highlights several key factors behind the "flip." Traders, accustomed to crypto's high volatility and frustrated by a stagnant market, chased the apparent momentum in AI-themed equities. Many made fatal mistakes: applying high-leverage strategies common in crypto (e.g., 2x ETFs, on-chain perpetual contracts) to stocks, and failing to understand the distinct rules of different stock markets (like Korean pre-market trading). This led to widespread liquidations, especially when a thin Korean pre-market trade triggered a cascading flash crash on a decentralized exchange. Post-crash reflections from prominent figures reveal deep regret and self-criticism. They acknowledge misjudging their expertise, overestimating their edge against sophisticated institutional players, and the dangers of leverage. The article concludes that while such setbacks are part of trading, surviving long-term requires recognizing one's limitations and the inherent risks of cross-market strategies.

marsbit53 хв тому

Now the Greatest Regret Is to My Family: Crypto Experts Took a Stumble in the Stock Market

marsbit53 хв тому

US Senate Makes Important Amendments to "Conflict of Interest" Section of Cryptocurrency Bill

The U.S. Senate has taken a key step regarding the CLARITY Act, which could shape the future of the U.S. crypto market. On July 29, Senators Tom Tillis and Ruben Gallego finalized amendments to the bill's "conflict of interest" rules, one of its most contentious aspects. The bipartisan bill aims to tighten restrictions on high-level federal officials' ties to digital assets. The new text, crafted as an alternative to a White House-endorsed ethics code, is expected to impose stricter rules limiting officials' ability to issue or directly participate in digital asset projects. However, with Congress entering an August recess and the revised text not yet reviewed by much of the Senate, the bill's timeline is uncertain. Senate Majority Leader John Thune indicated a procedural vote could occur between July 29 and August 1 but expressed doubt the full bill could pass before the break. The House-approved CLARITY Act, passed in July 2025, has been under Senate negotiation for over a year. Key goals of the CLARITY Act include clarifying jurisdictional boundaries between the SEC and CFTC, setting rules for digital commodity spot markets, and addressing topics like stablecoin yields, DeFi, and illicit financing. The stablecoin yield provisions could significantly impact U.S.-based DeFi protocols, exchanges, and issuers, affecting their global competitiveness. The outcome is being closely watched by both the U.S. and global digital asset markets.

cryptonews.ru1 год тому

US Senate Makes Important Amendments to "Conflict of Interest" Section of Cryptocurrency Bill

cryptonews.ru1 год тому

Pavel Durov Designated as a Terrorist in Russia. What Does This Mean for Telegram Users?

Pavel Durov, the founder of Telegram, has been added to Russia's list of terrorists and extremists by Rosfinmonitoring, as published on July 30. The entry includes his name and date of birth. The designation follows an announcement by the Russian Federal Security Service (FSB) on July 29, which charged Durov with aiding terrorist activity. The FSB alleges that a Telegram dating bot named "DaiVinchik" was used to recruit 46 individuals for attacks on police and arson, orchestrated by Ukrainian special services. The FSB also accuses Telegram's administration of failing to remove channels and bots used by Ukrainian intelligence and extremist groups. Durov is reportedly subject to an international arrest warrant. Inclusion on the Rosfinmonitoring list leads to significant restrictions: the freezing of Durov's bank accounts and assets, severe limitations on financial transactions, and a ban on election participation, media interaction, and event organization. Transfers to his accounts may be considered terrorism financing. For ordinary Russian Telegram users, purchasing Telegram Premium is not classified as financing terrorism, according to an IT expert. General use of the messenger—messaging, managing channels—does not automatically make a user a participant in extremist activity. There has been no official decision to ban Telegram itself. It is noted that French authorities are also investigating Durov over allegations of inadequate measures against criminal activity on the platform and insufficient cooperation with law enforcement. Durov denies all charges.

cryptonews.ru1 год тому

Pavel Durov Designated as a Terrorist in Russia. What Does This Mean for Telegram Users?

cryptonews.ru1 год тому

Торгівля

Спот
活动图片