Blockchain Relays Make Botnet Takedowns Harder

Dysphoria has moved the part defenders can see and block away from the real controller. A seizure or IP block now hits a relay or a naming record, not the endpoint the botnet actually depends on, so the usual takedown playbook loses leverage. Researchers say the lineage added blockchain-based name services and infected-device relays after the March JackSkid disruption. XLab traced ENS and Solana name records, relay-only builds, and a design where bots ask a distribution node for a server list that points them to compromised machines relaying traffic onward; reported bot counts are large, but the counts are not independently verified. That makes disruption harder, but not impossible. The chain still depends on blockchain records, reachable relays, and compromised devices, so defenders have to look past the obvious controller address and watch the full naming-and-relay layer.

Part of the PlainSec briefing for 2026-07-28

Sources