The post Ransomware group uses Polygon to evade takedowns appeared on BitcoinEthereumNews.com. Security researchers say a low-profile ransomware group is using The post Ransomware group uses Polygon to evade takedowns appeared on BitcoinEthereumNews.com. Security researchers say a low-profile ransomware group is using

Ransomware group uses Polygon to evade takedowns

Security researchers say a low-profile ransomware group is using Polygon smart contracts to hide and rotate its command-and-control infrastructure.

Summary

  • DeadLock ransomware, first observed in July 2025, stores rotating proxy addresses inside Polygon smart contracts to evade takedowns.
  • The technique relies only on reading on-chain data and does not exploit vulnerabilities in Polygon or other smart contracts.
  • Researchers warn the method is cheap, decentralized, and difficult to block, even though the campaign has limited confirmed victims so far.

Cybersecurity researchers are warning that a recently identified ransomware strain is using Polygon smart contracts in an unusual way that could make its infrastructure harder to disrupt.

In a report published on Jan. 15, researchers at cybersecurity firm Group-IB said the ransomware, known as DeadLock, is abusing publicly readable smart contracts on the Polygon (POL) network to store and rotate proxy server addresses used to communicate with infected victims.

DeadLock was first observed in July 2025 and has remained relatively low profile since then. Group-IB said the operation has a limited number of confirmed victims and is not linked to any known ransomware affiliate programs or public data leak sites.

Despite its low visibility, the firm warned that the techniques being used are highly inventive and could pose serious risks if copied by more established groups.

How the technique works

Instead of relying on traditional command-and-control servers, which can often be blocked or taken offline, DeadLock embeds code that queries a specific Polygon smart contract after a system has been infected and encrypted. That contract stores the current proxy address used to relay communication between the attackers and the victim.

Because the data is stored on-chain, attackers can update the proxy address at any time, allowing them to rotate infrastructure quickly without redeploying malware. Victims do not need to send transactions or pay gas fees, as the ransomware only performs read operations on the blockchain.

Once contact is established, victims receive ransom demands along with threats that stolen data will be sold if payment is not made. Group-IB noted that this approach makes the ransomware’s infrastructure far more resilient.

There is no central server to shut down, and the contract data remains available across distributed nodes worldwide, making takedowns significantly more difficult.

No Polygon vulnerability involved

The researchers stressed that DeadLock is not exploiting flaws in Polygon itself or in third-party smart contracts such as decentralized finance protocols, wallets, or bridges. The ransomware is simply abusing the public and immutable nature of blockchain data to hide configuration information, a method similar to earlier “EtherHiding” techniques.

Several smart contracts linked to the campaign were deployed or updated between August and Nov. 2025, according to Group-IB’s analysis. While the activity remains limited for now, the firm warned that the concept could be reused in countless variations by other threat actors.

While Polygon users and developers are not facing direct risk from the campaign, researchers say the case highlights how public blockchains can be misused to support off-chain criminal activity in ways that are difficult to detect and dismantle.

Source: https://crypto.news/ransomware-polygon-smart-contracts-evade-takedowns-2026/

Market Opportunity
Smart Blockchain Logo
Smart Blockchain Price(SMART)
$0.004991
$0.004991$0.004991
-1.44%
USD
Smart Blockchain (SMART) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Ethereum ETFs Lead on Jan 15 as Bitcoin Wins the Week

Ethereum ETFs Lead on Jan 15 as Bitcoin Wins the Week

The post Ethereum ETFs Lead on Jan 15 as Bitcoin Wins the Week appeared on BitcoinEthereumNews.com. Key Highlights: Ethereum ETFs led the daily inflows on January
Share
BitcoinEthereumNews2026/01/16 15:18
BlackRock Increases U.S. Stock Exposure Amid AI Surge

BlackRock Increases U.S. Stock Exposure Amid AI Surge

The post BlackRock Increases U.S. Stock Exposure Amid AI Surge appeared on BitcoinEthereumNews.com. Key Points: BlackRock significantly increased U.S. stock exposure. AI sector driven gains boost S&P 500 to historic highs. Shift may set a precedent for other major asset managers. BlackRock, the largest asset manager, significantly increased U.S. stock and AI sector exposure, adjusting its $185 billion investment portfolios, according to a recent investment outlook report.. This strategic shift signals strong confidence in U.S. market growth, driven by AI and anticipated Federal Reserve moves, influencing significant fund flows into BlackRock’s ETFs. The reallocation increases U.S. stocks by 2% while reducing holdings in international developed markets. BlackRock’s move reflects confidence in the U.S. stock market’s trajectory, driven by robust earnings and the anticipation of Federal Reserve rate cuts. As a result, billions of dollars have flowed into BlackRock’s ETFs following the portfolio adjustment. “Our increased allocation to U.S. stocks, particularly in the AI sector, is a testament to our confidence in the growth potential of these technologies.” — Larry Fink, CEO, BlackRock The financial markets have responded favorably to this adjustment. The S&P 500 Index recently reached a historic high this year, supported by AI-driven investment enthusiasm. BlackRock’s decision aligns with widespread market speculation on the Federal Reserve’s next moves, further amplifying investor interest and confidence. AI Surge Propels S&P 500 to Historic Highs At no other time in history has the S&P 500 seen such dramatic gains driven by a single sector as the recent surge spurred by AI investments in 2023. Experts suggest that the strategic increase in U.S. stock exposure by BlackRock may set a precedent for other major asset managers. Historically, shifts of this magnitude have influenced broader market behaviors as others follow suit. Market analysts point to the favorable economic environment and technological advancements that are propelling the AI sector’s momentum. The continued growth of AI technologies is…
Share
BitcoinEthereumNews2025/09/18 02:49
How RL Environments Are Revolutionizing AI Training In Silicon Valley

How RL Environments Are Revolutionizing AI Training In Silicon Valley

The post How RL Environments Are Revolutionizing AI Training In Silicon Valley appeared on BitcoinEthereumNews.com. AI Agents’ Breakthrough: How RL Environments Are Revolutionizing AI Training In Silicon Valley Skip to content Home AI News AI Agents’ Breakthrough: How RL Environments are Revolutionizing AI Training in Silicon Valley Source: https://bitcoinworld.co.in/ai-agents-rl-environments-training/
Share
BitcoinEthereumNews2025/09/22 03:42