← Editorial BNB

Hackers Exploit BNB Chain to Distribute Malware via Fake CAPTCHAs

Microsoft reports that attackers are using smart contracts on BNB Chain to store malicious commands, then tricking website visitors into executing them through fraudulent security prompts.

· -6

According to Microsoft Threat Intelligence, a malware campaign leverages a technique called EtherHiding to hide malicious instructions in BNB Chain smart contracts. JavaScript code injected into compromised websites retrieves these commands from contracts previously associated with ClearFake, a known malware operation. Storing instructions on a blockchain makes them difficult to remove, since only the wallet controlling the contract can modify its contents.

The attack begins with fake CAPTCHA prompts on compromised sites. Visitors are instructed to open the Windows Run dialog, paste text from their clipboard, and press Enter—executing commands supplied by the attacker. A variation called TerminalFix directs users to Windows Terminal or PowerShell instead. Microsoft researchers describe these methods, known as ClickFix and TerminalFix, as high-volume initial access techniques, with campaigns targeting thousands of enterprise and consumer devices daily.

Successful infections can expose passwords, establish persistent access, facilitate lateral movement through networks, and lead to ransomware attacks or broader network compromise. Attackers abuse legitimate Windows tools including PowerShell, cmd, mshta, rundll32, msiexec, curl, Windows Management Instrumentation, and scheduled tasks to carry out the attacks.

Using blockchains to support malware operations is not new. Cerber ransomware began using Bitcoin transactions to locate command-and-control servers in 2016. From 2019 to 2021, the Glupteba botnet used the Bitcoin blockchain to find backup servers when primary infrastructure went offline. In September 2023, ClearFake began using EtherHiding on BNB Chain, and in April 2026, researchers discovered Omnistealer using TRON, Aptos, and BNB Chain to steal credentials and wallet data. While blockchain-based malware distribution is not unique to BNB Chain, Microsoft's decision to highlight the trend reflects its growing prevalence.

How this piece reads Sell tone -6
Site call on BNB Buy score 46.9

These two are not the same thing, and one does not produce the other. The left is how this single article reads, from its tone alone. The right is the site’s own call on the asset, from indicators and analysis. Press tone feeds no score and no signal: on the only corpus this site has measured, daily tone tracked the move that had already happened and showed no measurable link with what followed.

More on BNB All pieces →

Rewritten from the headline, the teaser and the one-line summary the qualification step produced — that is all the material there is, and nothing is added to it. The source link is kept on file so any item can be checked, and is not published here.