DeadLock ransomware uses Polygon smart contracts to make its extortion infrastructure harder to take down

Researchers say the DeadLock ransomware group is using Polygon blockchain smart contracts to support parts of its extortion operation, making its infrastructure harder for defenders and law enforcement to disrupt. The report describes a ransomware campaign in which blockchain-hosted logic or pointers help replace more traditional web infrastructure that can be seized or blocked, showing a resilience tactic rather than a newly disclosed software vulnerability or CVE.
Why it matters: This matters because it shows ransomware groups adapting to survive domain takedowns and infrastructure seizures, which can prolong extortion pressure on victims. Defenders should track DeadLock activity, update detection for blockchain-linked infrastructure, and not assume traditional disruption steps will be enough.

Sources

DeadLock ransomware uses blockchain to resist infrastructure takedown
Bill Toulas 2026.08.11 99% relevant
This article is the same underlying event and adds Microsoft’s technical details on how DeadLock stores chat-proxy configuration and leak-site content via Polygon, uses Session for victim communications and Wasabi for stolen files, and how its Windows encryptor behaves after initial access.
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
info@thehackernews.com (The Hacker News) 2026.08.11 100% relevant
This article establishes a distinct ransomware tradecraft story centered on DeadLock's use of Polygon smart contracts, and it does not match an existing tracked event in the list.
← Back to all stories