DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
- ID
- 13215
- Status
- summarized
- Published
- 12 Aug 2026, 12:35 AM
- Fetched
- 12 Aug 2026, 2:44 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 12 Aug 2026, 2:48 AM
- Tags
- Audience
- developers
What happened
DeadLock ransomware, active since July 2025 with 96 claimed victims across Italy, Spain, Poland, Türkiye, and the U.S., uses Polygon smart contracts and the Session messaging network to decentralize its extortion infrastructure, making takedown harder. The group employs double extortion, selective encryption using Curve25519 and XChaCha20, and communicates via Session with Bitcoin or Monero payments.
Why it matters
This is a general ransomware threat story with no direct connection to AI, agents, developer tooling, or Malaysian/Southeast Asian infrastructure. Builders in this audience are unlikely to need to change anything based on this unless they operate in the affected regions or sectors.
Discussion angle
The novel use of Polygon smart contracts for resilient extortion infrastructure is an interesting case of decentralized tech being weaponized, but it's a niche security topic unlikely to shift day-to-day decisions for most builders in this community.