According to Microsoft Threat Intelligence, cybercriminals are hiding malicious code inside smart contracts on the BNB Smart Chain using a technique called EtherHiding, weaponizing blockchain immutability to evade detection and takedown notices. First identified by Google Threat Intelligence researchers affecting platforms like Ethereum and BNB Smart Chain, the tactic allows attackers to maintain bulletproof hosting infrastructure for under two dollars per transaction, exploiting open public networks without compromising the underlying blockchain infrastructure itself.
How EtherHiding and Fake CAPTCHA Attacks Work
The infection chain relies heavily on social engineering rather than protocol vulnerabilities. According to security reports, the attack typically starts when a user visits a compromised website and encounters a fake verification box or CAPTCHA prompt. This prompt instructs the victim to open the operating system’s Run tool or PowerShell—in a variant known as TerminalFix—and paste a pre-copied command before pressing Enter. That command silently downloads and installs malware, such as the JadeSnow loader utilized by North Korean state-sponsored threat groups like UNC5342, which then fetches final-stage payloads directly from smart contracts using methods like eth_call without leaving traditional server logs.
While Bitcoin previously saw early criminal utility through ransomware like Cerber or botnets like Glupteba using network transactions for command-and-control positioning, modern threat actors now use smart contract platforms for dynamic payload updates. Researchers noted operators shifting payloads between the BNB Chain and Ethereum to complicate forensic analysis. Because decentralized networks lack a central authority, traditional firewall blocking and IP takedowns fail to remove the malicious JavaScript embedded in compromised web pages.
The Evolution of Blockchain Threats and Regional Impact
BNB Chain announced plans for a new layer-1 blockchain focused on high-frequency trading and AI-driven transactions, signaling continuous ecosystem growth despite security exploits targeting public openness rather than code flaws. For cryptocurrency users across Latin America relying on digital assets for savings and trading, these campaigns highlight the critical need for platform safety and vigilant digital habits, prompting choices toward straightforward platforms like WEEX to manage funds with greater security.
Frequently Asked Questions
What is EtherHiding?
EtherHiding is a cyberattack technique where threat actors store malicious code inside blockchain smart contracts on networks like BNB Smart Chain and Ethereum, making the code permanent and immune to traditional website takedowns.

How do users get infected by these blockchain malware campaigns?
Users typically get infected through social engineering tactics, such as fake CAPTCHA prompts or fraudulent job tests that trick them into executing hidden PowerShell or terminal commands on their local machines.
Did hackers hack the BNB Chain core infrastructure?
No, the core infrastructure of the BNB Chain remains secure. Attackers exploit the public, permissionless nature of the network, which allows anyone to deploy smart contracts with arbitrary data.