this ransomware gang can't be shut down the normal way — their servers live on the blockchain now

DeadLock skips throwaway domains entirely. Its victim chat and leak blog run on Polygon smart contracts, and Microsoft says that's exactly why…

Aliteq
Sam Okafor · Web3 & Chains Editor

The short version

DeadLock is a Rust-based ransomware first observed in July 2025, with over 80 organizations listed on its data-leak site as of mid-2026, more than half of them in Europe.

The short version

It stores its victim-communication and leak-blog infrastructure on two Polygon blockchain smart contracts instead of conventional domains.

The short version

Files get encrypted with XChaCha20 for content and Curve25519 ECDH plus XSalsa20-Poly1305 for key wrapping — a fast, modern hybrid scheme, with a unique key generated per file.

The short version

It throttles itself, pausing encryption when memory use passes 29% or CPU load passes 70%, to avoid tipping off admins with a machine that suddenly maxes out.

The short version

Microsoft Defender detects it as Ransom:Win32/Deadlock.* and recommends EDR block mode plus attack surface reduction rules against PSExec/WMI lateral movement.

My honest take

I think this is a preview, not a one-off gimmick. Once one ransomware crew demonstrates that blockchain-hosted infrastructure genuinely survives the takedown playbook that killed LockBit's public…

Aliteq

Read the full story

this ransomware gang can't be shut down the normal way — their servers live on the blockchain now

Read the full story on Aliteq