Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A large-scale cybercriminal campaign has compromised more than 5,400 small-business websites to distribute ClickFix malware, with the malicious payloads stored inside smart contracts on the BNB Smart Chain blockchain.
Why this matters: Storing malware on a blockchain is a real problem for defenders. Blockchain content is decentralized and practically impossible to take down the way a normal server can be. That means the usual response — find the host, pull the file — does not work here. Small-business websites are the delivery mechanism, which makes this hard to trace and easy to scale. If you visit a compromised site, you may get hit before anyone knows it is infected. The people running these sites probably have no idea they are part of it.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.