Cybercriminals Compromised 5,400 Sites via Blockchain
The campaign leverages decentralized infrastructure to bypass traditional security blocks, complicating threat mitigation.
Updated on Sept. 27, 2026 in Cybersecurity

Live Poll
Do you trust the security of the websites you visit for everyday tasks?
As of September 2026, researchers have tracked a campaign that compromised more than 5,400 small-business websites running on WordPress and PrestaShop. The attackers used the BNB Smart Chain to host malicious payloads, a tactic that complicates efforts to take down command-and-control infrastructure.
Why it matters
By shifting malicious hosting to public blockchain testnets, attackers have successfully evaded traditional server-based blocking defenses used by security vendors. This move toward decentralized infrastructure makes disruption significantly more difficult for network administrators.
The campaign involves 300 infected sites daily contacting blockchain-hosted payloads. Attackers utilize an EtherHiding technique to embed malware, with some variants employing encrypted WebRTC channels to execute code directly in system memory.
The players
WordPress
An open-source content management system that powers a significant portion of the global web and frequently serves as a target for automated exploitation campaigns.
BNB Smart Chain
A blockchain network supporting smart contracts that threat actors have repurposed to host malicious code and evade centralized domain-based blocking.
The details
The attack begins when site visitors see fake CAPTCHA prompts that trick them into running a malicious PowerShell command in a Windows Run dialog. These scripts connect to the BNB Smart Chain, where the actual malware payloads are stored as smart contract data. By moving the stager—the initial code that downloads the main threat—to the blockchain, the attackers force security teams to contend with decentralized, immutable infrastructure rather than a single malicious server.
Timeline
The campaign began its steady growth in Spring 2026.
This report was published on September 7, 2026.
The Tech Race
This campaign demonstrates an escalation in the use of EtherHiding, where attackers treat public ledgers as permanent, distributed web servers. It challenges traditional security architectures that rely on blocking specific IP addresses or domain names to neutralize threats.
Users should be wary of any unexpected CAPTCHA prompts requesting the manual execution of scripts or PowerShell commands. This campaign primarily impacts administrators of small-business sites, who should ensure their plugins are updated to mitigate the risk of script injection.
The takeaway
The move toward decentralized malware hosting forces a shift away from simple domain blocking toward behavioral detection. Security professionals should monitor for suspicious outbound traffic originating from web servers to blockchain gateways.
Further reading
For more on the current state of threat vectors, see our Cybersecurity section.
Source note: This article includes information reported by Computer Crime Research Center.
Live Poll
Do you trust the security of the websites you visit for everyday tasks?






