Microsoft said hackers are using BNB Chain as part of a malware campaign that starts on compromised websites and ends with visitors being pushed to run malicious commands on Windows devices. According to the company, the sites retrieve instructions from the blockchain before presenting users with fake CAPTCHA prompts.
The development matters because it shows attackers using crypto infrastructure as a distribution layer, not just as a target. For readers, the risk is practical: a familiar web security step, such as a CAPTCHA, can be imitated to make a malicious action look routine.
Microsoft’s finding points to a tactic in which compromised websites act as the first point of contact, while blockchain-based data helps deliver the next step in the attack. The source material does not indicate that BNB Chain itself was compromised.
The campaign also underscores a broader security issue for the crypto ecosystem: public blockchains can be used by anyone, including threat actors, to store or reference information. That openness is a core feature of blockchain networks, but it can also make abuse harder to remove once malicious instructions are posted.
Users should treat unexpected CAPTCHA pages that ask them to copy, paste, or run commands with caution, especially on Windows devices. The key warning from Microsoft’s report is that the attack depends on convincing the visitor to execute the instructions themselves.