The solution
Akamai researchers tracking a botnet for about two years watched it adopt a new survival trick: when its command-and-control server gets sinkholed — the standard defender move of taking over the C2 infrastructure — infected machines find the backup server's IP address encoded in the bitcoin blockchain.
The encoding is spare and exact: the two most recent transactions on a wallet chosen by the operators carry the address as Satoshi values, one hundred millionth of a bitcoin. The malware converts each value to hexadecimal, splits it into bytes, and reassembles four octets — 36,305 satoshis becomes 209.141, 6,957 becomes 45.27, for a live fallback at 209.141.45.27. The ledger is decentralized, so unlike traditional backup channels there is no central authority to take down, censor or block.
Akamai said it had never before seen an in-the-wild botnet use a decentralized blockchain this way, though a proof-of-concept Ethereum-based command server existed in research. Criminals had used covert channels before — VPNFilter, deployed by Russian government-backed hackers against 500,000 routers in 2018, stashed its server pointers in GPS data inside Photobucket images — but those platforms could be persuaded or forced to cooperate; the blockchain cannot.
Why it worked
Sinkholing works by severing or seizing a server; a note stored in the ledger survives any seizure.
Bitcoin transactions are ordinary economic activity, indistinguishable from wallet noise to outsiders.
Only the operators need write access; every infected machine just reads the public chain.
Decentralization removes the last resort of pressuring a hosting provider or platform to delete.
What can be applied
Any public, immutable datastore becomes infrastructure for whoever needs permanence — defenders' takedown playbook assumes a delete button the blockchain doesn't have.
Aftermath
Akamai published the analysis in February 2021, making the technique — and its limits, such as the watchable wallet — public. Researchers noted the Ethereum proof-of-concept showed the approach generalises to other chains; the cat-and-mouse of botnet infrastructure had simply moved to a ledger with no delete key.
FOLLOW THE EVIDENCE