Hackers Find a New Use for the Blockchain
I keep telling people the blockchain is useful. They say it is not. Here is the proof that it is useful. (full disclosure: actually I say the reverse of this). Hackers have figured out that since the blockchain can’t be changed (of course, except when the maintainers decide it can be changed), it is a great place to hide malware. Once you upload the malware to the blockchain it is, except for a really, really, rare situation when the maintainers are willing to fork the blockchain and manually reprocess millions of records, it is a great place to store malware. It is RELATIVELY anonymous since, unlike crypto, once you put the malware up there you, the hacker, don’t need to access it ever again, making it really hard to find you.
With crypto, you actually want to get your money, which makes it very UN-anonymous.
So now you have malware on the blockchain, the transaction has a transaction ID, which you and anyone else can find.
Now you write a bit of code that CONTAINS NO MALWARE to detect. Once the user installs this code, it reaches out to the blockchain, which is not a totally suspicious thing, and downloads, installs and runs the malware.
If the cops find it, except in SUPER high profile cases, the odds of getting it taken down are basically zero.
And, since the cops are used to getting judges to authorize seizing a server – good luck, since there is no server to seize that stores the data. Do you really think a judge is going to authorize, say, taking down the Bitcoin blockchains? No. I don’t think so.
And since blockchains are decentralized, there isn’t even someone to arrest and throw in jail.
It is a pretty interesting attack vector. Diabolical.
What cops may be able to do is track hackers making changes – unless they are smart. Write once, read many. If you find a problem, you still write once (a new once) and read many. If you are dumb, you will get caught.
Hackers are using open weight AI models to execute these attacks. Run locally on a modest computer (say less than $25,000) could potentially make a nation state hacker millions. Not rich enough? Scale up. The attack is very scalable. For a $25,000 investment the hacker can earn a million. Nice return on investment. Even if the hacker can only earn $250,000 that is a 1000% return on investment. Still pretty good.
What the law needs to do is look for mistakes and hackers often make them, but you likely won’t be able to find them until AFTER the fact. Doesn’t help the victim much. ESPECIALLY if the hacker is in China or North Korea.
Credit: Tech Radar
