Hackers Turn Public Blockchains Into Malware Dead Drops as Activity Climbs 440%, Chainalysis Says
Chainalysis reports a 440% rise in malicious blockchain activity, with attackers using on-chain dead drops to keep malware instructions alive and unrestricted AI models lowering the technical barrier.
Chainalysis claims malicious blockchain activity increased 440%, with daily entries rising from 2.06 to 11.1 after newer AI systems emerged. The technique gives attackers a way to stay in contact with compromised computers without depending entirely on servers controlled by hosting providers.
The method, described as a blockchain dead drop, uses transaction data or smart contracts as lookup points so that infected machines can retrieve commands, addresses or configuration information. Because blockchain records are distributed across networks, deleting a conventional server does not erase information already written to the ledger.
A North Korean-linked operation tracked as UNC5342 uses TRON and Aptos as alternate routes before retrieving encrypted instructions through the BNB Chain, according to the report. Its malware can check one network, switch to another when necessary and pull updated addresses without receiving a fresh malware package.
Iranian actors suspected of ties to the country's intelligence ministry have embedded encoded routing information inside Bitcoin transactions used for malware retrieval, TechRadar reported. Russian-speaking cybercriminals have commercialized the approach, using Polygon contracts to supply blockchain-backed infrastructure for campaigns run by different customers. One related operator controls more than 50 BNB Chain resolver contracts while also carrying out activity involving fraudulent tokens and clipboard-monitoring malware.
Chainalysis said the sharp increase followed the arrival of high-capacity Chinese open models that placed fewer restrictions on malware development requests. Before those systems appeared, building reliable blockchain-based malware infrastructure required expertise spanning malicious software, cryptocurrency networks and distributed communication systems. AI tools can lower that knowledge barrier by helping less experienced operators understand unfamiliar technologies and produce the components needed for blockchain communication.
In the second quarter of 2026, state-linked groups accounted for roughly two-thirds of newly observed activity and about half of all observed activity, indicating that blockchain-based malware infrastructure extends beyond conventional cybercriminal operations.
Defenders face a difficult trade-off because blocking blockchain traffic could also disrupt legitimate wallets, decentralized applications, exchanges and decentralized finance services used worldwide. Attackers can complicate disruption further by operating their own blockchain nodes, reducing their dependence on external providers that defenders might otherwise pressure or disable.
Some operators have hidden server addresses inside wallet identifiers that have no usable private keys, then used zero-value transfers to trigger malware retrieval. Those transactions leave public records that investigators can examine, potentially yielding useful clues even when attackers try to conceal their infrastructure.
"While the exploitation of blockchain by state-linked organizations such as North Korea is becoming more sophisticated, on-chain records left by attackers can actually serve as important clues to track them," said Kwon Jun-hyeok, General Manager of Chainalysis Korea. "Tracking these traces and identifying attackers and related infrastructure through blockchain intelligence will become increasingly important in responding to new cyber threats."
Editor's Summary
Chainalysis attributes a 440% rise in malicious blockchain activity to attackers using on-chain dead drops, which let infected machines retrieve commands even after conventional servers are removed. State-linked groups account for most newly observed activity, and high-capacity Chinese open models are credited with lowering the technical barrier for less experienced operators. Investigators say the public ledger records left behind can still provide leads even as blocking blockchain traffic risks disrupting legitimate cryptocurrency services.