Industry News

Hackers Exploit Blockchain Smart Contracts to Hide Malware

Blockonomi · 8 Aug 2026
Key Takeaway Keep website software and plugins updated, use web security monitoring tools, and train staff to be cautious of unexpected prompts or commands when browsing, even on familiar websites.

Microsoft's Threat Intelligence team has identified a new attack technique in which cybercriminals abuse blockchain infrastructure to hide and deliver malware. The attackers compromise legitimate, trusted websites and insert malicious JavaScript code that connects to smart contracts hosted on the BNB Smart Chain, a public blockchain network.

By storing malicious instructions on the blockchain rather than a traditional server, attackers make their infrastructure harder to detect and take down, since blockchain data is decentralised and difficult for security teams or law enforcement to remove. Visitors to the compromised websites may unknowingly interact with malicious code that is part of a broader technique known as ClickFix, which tricks users into running commands that lead to malware infection.

While this campaign currently targets larger organisations and popular websites, it highlights a growing trend of attackers using legitimate technologies like blockchain to make their attacks more resilient and harder to disrupt. Australian small businesses that rely on third-party websites, plugins, or embedded scripts should be aware that even trusted-looking sites can be compromised without obvious warning signs.

malware blockchain security Microsoft Threat Intelligence

Summarised by CISO AI from Blockonomi. We link back to every original so you can read it yourself.