Cybercriminals Compromised 5,400 Sites via Blockchain

The campaign leverages decentralized infrastructure to bypass traditional security blocks, complicating threat mitigation.

Updated on Sept. 27, 2026 in Cybersecurity

Isometric editorial illustration of interconnected geometric blocks, representing distributed ledger infrastructure in a sterile, modern digital environment.
Cybercriminals have compromised over 5,400 small-business websites by using blockchain-based smart contracts to host malicious payloads, evading traditional security protocols. AI Illustration. Upload story photo >

Live Poll

Do you trust the security of the websites you visit for everyday tasks?

As of September 2026, researchers have tracked a campaign that compromised more than 5,400 small-business websites running on WordPress and PrestaShop. The attackers used the BNB Smart Chain to host malicious payloads, a tactic that complicates efforts to take down command-and-control infrastructure.

Why it matters

By shifting malicious hosting to public blockchain testnets, attackers have successfully evaded traditional server-based blocking defenses used by security vendors. This move toward decentralized infrastructure makes disruption significantly more difficult for network administrators.

The campaign involves 300 infected sites daily contacting blockchain-hosted payloads. Attackers utilize an EtherHiding technique to embed malware, with some variants employing encrypted WebRTC channels to execute code directly in system memory.

The players

WordPress

An open-source content management system that powers a significant portion of the global web and frequently serves as a target for automated exploitation campaigns.

BNB Smart Chain

A blockchain network supporting smart contracts that threat actors have repurposed to host malicious code and evade centralized domain-based blocking.

The details

The attack begins when site visitors see fake CAPTCHA prompts that trick them into running a malicious PowerShell command in a Windows Run dialog. These scripts connect to the BNB Smart Chain, where the actual malware payloads are stored as smart contract data. By moving the stager—the initial code that downloads the main threat—to the blockchain, the attackers force security teams to contend with decentralized, immutable infrastructure rather than a single malicious server.

Timeline

  1. The campaign began its steady growth in Spring 2026.

  2. This report was published on September 7, 2026.

The Tech Race

This campaign demonstrates an escalation in the use of EtherHiding, where attackers treat public ledgers as permanent, distributed web servers. It challenges traditional security architectures that rely on blocking specific IP addresses or domain names to neutralize threats.

Users should be wary of any unexpected CAPTCHA prompts requesting the manual execution of scripts or PowerShell commands. This campaign primarily impacts administrators of small-business sites, who should ensure their plugins are updated to mitigate the risk of script injection.

The takeaway

The move toward decentralized malware hosting forces a shift away from simple domain blocking toward behavioral detection. Security professionals should monitor for suspicious outbound traffic originating from web servers to blockchain gateways.

Further reading

For more on the current state of threat vectors, see our Cybersecurity section.

Source note: This article includes information reported by Computer Crime Research Center.

Live Poll

Do you trust the security of the websites you visit for everyday tasks?