MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Ransomware group uses Polygon to evade takedowns
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$65,625.00-1.73%
  • ethereumEthereum(ETH)$1,925.77-1.76%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$612.74-0.73%
  • rippleXRP(XRP)$1.35-1.81%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$82.89-1.91%
  • tronTRON(TRX)$0.280298-0.65%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-2.27%
  • dogecoinDogecoin(DOGE)$0.091845-2.36%
Smart Contracts

Ransomware group uses Polygon to evade takedowns

Last updated: January 16, 2026 12:25 pm
Published: 1 month ago
Share

Security researchers say a low-profile ransomware group is using Polygon smart contracts to hide and rotate its command-and-control infrastructure.

Cybersecurity researchers are warning that a recently identified ransomware strain is using Polygon smart contracts in an unusual way that could make its infrastructure harder to disrupt.

In a report published on Jan. 15, researchers at cybersecurity firm Group-IB said the ransomware, known as DeadLock, is abusing publicly readable smart contracts on the Polygon (POL) network to store and rotate proxy server addresses used to communicate with infected victims.

DeadLock was first observed in July 2025 and has remained relatively low profile since then. Group-IB said the operation has a limited number of confirmed victims and is not linked to any known ransomware affiliate programs or public data leak sites.

Despite its low visibility, the firm warned that the techniques being used are highly inventive and could pose serious risks if copied by more established groups.

Instead of relying on traditional command-and-control servers, which can often be blocked or taken offline, DeadLock embeds code that queries a specific Polygon smart contract after a system has been infected and encrypted. That contract stores the current proxy address used to relay communication between the attackers and the victim.

Because the data is stored on-chain, attackers can update the proxy address at any time, allowing them to rotate infrastructure quickly without redeploying malware. Victims do not need to send transactions or pay gas fees, as the ransomware only performs read operations on the blockchain.

Once contact is established, victims receive ransom demands along with threats that stolen data will be sold if payment is not made. Group-IB noted that this approach makes the ransomware’s infrastructure far more resilient.

There is no central server to shut down, and the contract data remains available across distributed nodes worldwide, making takedowns significantly more difficult.

The researchers stressed that DeadLock is not exploiting flaws in Polygon itself or in third-party smart contracts such as decentralized finance protocols, wallets, or bridges. The ransomware is simply abusing the public and immutable nature of blockchain data to hide configuration information, a method similar to earlier “EtherHiding” techniques.

Several smart contracts linked to the campaign were deployed or updated between August and Nov. 2025, according to Group-IB’s analysis. While the activity remains limited for now, the firm warned that the concept could be reused in countless variations by other threat actors.

While Polygon users and developers are not facing direct risk from the campaign, researchers say the case highlights how public blockchains can be misused to support off-chain criminal activity in ways that are difficult to detect and dismantle.

Read more on crypto.news

This news is powered by crypto.news crypto.news

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

New cryptocurrency Mutuum Finance (MUTM) raises $15.8M as phase 6 reaches 40%
Best Crypto to Buy Now Q4: MoonBull Presale Breaks Silence While Bitcoin Cash Soars and Stellar Rattles Markets – Crypto Economy
Tron Utility Rises, Aster Expands, Yet BullZilla’s Presale ROI Hits $461K on $7.5K Entry – Top 100x Crypto Presale in 2025
Ika Launches Mainnet to Enable Native Cross-Chain Asset Control on Sui Blockchain – Crypto Economy
Best Cryptos to Invest in 2025: BullZilla Leads the Pack – South Africa Today

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article South Korea approves tokenized securities framework in key legislative hearing
Next Article Is crypto an opportunity or a threat?
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d