NewsCryptoHackers Use Public Blockchains to Keep Malware Infrastructure Online

Hackers Use Public Blockchains to Keep Malware Infrastructure Online

Author: CoinLineup·

Key Takeaways

  • Attackers are embedding command-and-control data, such as web addresses or encoded instructions, directly into transactions and smart contracts on public blockchains including Ethereum and Bitcoin.
  • Because blockchain records are distributed and permanent, no central authority can remove them, so defenders must instead identify and block the off-chain payload and data-exfiltration endpoints the malware points to.
  • Blockchain-based malware activity has jumped 440%, and AI tools have lowered the technical barrier enough for smaller criminal groups, not only nation-state actors, to adopt the technique.
  • For crypto holders, the main danger is prolonged malware infections delivered through phishing, fake apps, or malicious browser extensions, which give attackers more time to capture seed phrases, private keys, and login credentials.
  • Suggested defenses include keeping software updated, downloading wallet applications only from official sources, treating unexpected seed-phrase prompts as red flags, and sharing threat intelligence about suspicious on-chain activity.
Hackers Use Public Blockchains to Keep Malware Infrastructure Online

Hackers have found a new way to keep malware running even after security teams attempt to shut it down: they are hiding pieces of their attack infrastructure on public blockchain networks. Because blockchains are designed to be permanent and decentralized, malicious campaigns built on this foundation are considerably harder to disrupt than those that depend on conventional hosting services.

How Attackers Use Public Blockchains as Part of Malware Infrastructure

Most malware needs to “phone home” to receive instructions or deliver stolen data. Traditionally, attackers run these command-and-control servers on conventional hosting services, and security teams can report a malicious server so that the hosting provider takes it offline.

The newer approach works differently. Attackers write small pieces of data, such as a web address or an encoded instruction, directly onto a public blockchain. On public chains, such data can be embedded in ordinary-looking transactions or smart contracts, placing attacker-controlled data alongside legitimate network activity. Malware on an infected machine then reads that on-chain data to determine where to connect next. Because the blockchain record is distributed across thousands of computers worldwide, no single company can delete it.

The New Jersey Cybersecurity and Communications Integration Cell has documented how botnets such as Necurs — networks of infected computers controlled by hackers — use layered infrastructure to stay resilient. Blockchain-based components extend that same logic, adding one more layer that defenders cannot simply “take down.”

Blockchain data is publicly readable by design. That openness, which is meant to promote transparency in financial transactions, also means anyone — including malware running on a victim’s machine — can query it without special credentials or accounts.

Why On-Chain Malware Infrastructure Is Harder to Disrupt

When security teams discover a malicious domain or server, the standard playbook involves contacting registrars, hosting providers, or internet service providers to have it removed or blocked. That process works because a central party controls the resource.

Public blockchains have no equivalent central party. Data written to chains such as Ethereum or Bitcoin — two of the largest and longest-running blockchain networks — remains accessible for as long as the network exists. Defenders can block specific wallet addresses or flag suspicious smart contract interactions at the application layer, but the underlying data stays on-chain permanently.

This forces security teams to take a different approach. Rather than removing the infrastructure itself, they must identify and block the off-chain components that the malware points to, such as the final payload server or the data-exfiltration endpoint. That task requires more layers of investigation and faster response times.

Reporting from CryptoSlate indicates that blockchain-based malware activity has jumped 440%, with AI tools lowering the technical barrier for attackers to build and deploy these campaigns. That shift means the tactic is no longer limited to sophisticated nation-state actors; smaller criminal groups can now use it as well.

What This Means for Crypto Users and Security Teams

For everyday crypto holders, the most direct risk is not that their wallet will be targeted through the blockchain itself. The bigger concern is that malware delivered through phishing emails, fake apps, or malicious browser extensions could use blockchain infrastructure to stay active longer on an infected device. A longer-lived infection gives attackers more time to capture seed phrases, private keys, or login credentials.

Incidents in which crypto users were targeted through software vulnerabilities rather than hardware wallet exploits show that social engineering and malware remain the most common attack vectors, not direct protocol attacks. Blockchain-resilient infrastructure makes those conventional attacks more persistent once they succeed.

For platforms and security researchers, the response involves monitoring unusual on-chain data patterns, correlating them with known malware signatures, and flagging associated off-chain endpoints. Exchanges and wallet providers can contribute by sharing threat intelligence about suspicious contract addresses or wallet activity linked to malware campaigns.

Crypto users can reduce their personal risk by keeping operating systems and browser extensions updated, downloading wallet software only from official sources, and treating any unexpected prompt to enter a seed phrase as a red flag. Even if a malware campaign’s command-and-control infrastructure is blockchain-based and difficult to kill, the initial infection still relies on the same mistakes it always has: clicking the wrong link or installing an untrusted application.

The broader lesson is that blockchain’s core strengths — permanence, decentralization, and public accessibility — can be turned against users when exploited by attackers. Understanding that risk is the first step toward defending against it.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.