Netskope Threat Labs
BSides Barcelona

BSides Barcelona 2026: Hunting Blockchain Dead-Drop Resolvers in Enterprise Traffic

Districte Administratiu de la Generalitat de Catalunya
BSides Barcelona 2026: Hunting Blockchain Dead-Drop Resolvers in Enterprise Traffic
Presented by
About this talk

Malware C2 is moving to public smart contracts: a dead drop nobody can seize, hidden in the same JSON-RPC traffic as every wallet app, rotated for cents. You can hunt it with tools you already have. This talk reproduces the technique live across EVM, Solana, and TON with one-liners that pull and decode contract artifacts exactly the way the malware does, shows what separates malware resolution from benign crypto traffic in your logs, and releases a script that turns every contract you find into blocklist IOCs. No chain expertise required.