Blockchain Dead Drop Attacks Jump 420% as State Hackers Expand

Chainalysis reported a 420% year-over-year surge in blockchain dead drop attacks—malware campaigns that hide command-and-control pointers or payloads in public ledgers—driven largely by state-linked groups. The firm also found daily malicious blockchain writes rose from 2.06 to 11.1 after the arrival of high-capacity open-weight Chinese AI models, a 440% increase.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 28 minutes agoUpdated 28 minutes ago0 views

Why It Matters

The shift toward state-linked use of public blockchains for resilient command-and-control raises the complexity and cost of takedown efforts, since attackers can distribute instructions across multiple chains and rely on the immutable availability of on-chain data. This evolution changes how defenders and infrastructure providers must coordinate to disrupt operations.

Key Facts

  • Reported increase in blockchain dead drop attacks: 420% year-over-year
  • Malicious blockchain writes per day before mid-2025: 2.06 per day
  • Malicious blockchain writes per day after mid-2025: 11.1 per day (440% increase)
  • Share of new activity by state-linked groups in Q2 2026: Roughly two-thirds of new activity
  • Share of all tracked activity by state-linked groups: About half of all activity tracked by Chainalysis by Q2 2026},{

Chainalysis warned that blockchain dead drop attacks—where adversaries place malware payloads or pointers to command-and-control infrastructure in transaction data or smart contracts—have risen sharply over the past year. The firm quantified a 420% year-over-year increase in such campaigns and reported that daily malicious blockchain writes climbed from 2.06 to 11.1 following the advent of high-capacity, open-weight Chinese AI models in mid-2025, a 440% jump.

State-linked actors accounted for much of the recent growth. Chainalysis said North Korea-linked operators used multiple public chains as redundant command paths: nodes check Tron first, fall back to Aptos, and ultimately read encrypted configuration and server addresses from a transaction on BNB Smart Chain. That multi-chain design lets operators rotate off-chain servers by publishing new transactions while infected devices continue to retrieve the latest instructions, meaning disruption would require coordinated takedown actions across all involved chains.

The report also attributed another technique to actors it suspects are tied to Iran’s Ministry of Intelligence: those operators sent small Bitcoin payments that encoded routing information for malware to fetch. Chainalysis noted that this Iran assessment is based not on blockchain activity alone but on the malware family, decoding logic, timing and supporting infrastructure. Russian-language criminal groups, by contrast, used Polygon smart contracts to store and update infrastructure for malware-as-a-service offerings; Chainalysis characterized those actors as criminal rather than necessarily state-sponsored.

While on-chain dead drops do not make malware inherently more destructive, they remove the single centralized server defenders would typically seize to disrupt operations. As a result, the availability of instructions on an operating blockchain can keep campaigns resilient unless providers or chains themselves act. Chainalysis and independent researchers have observed some responsive actions—Google’s Threat Intelligence Group said centralized API providers reacted quickly when contacted about UNC5342, a North Korea-linked actor using similar techniques—but other platforms remained unresponsive, highlighting challenges in coordinated mitigation efforts.

Keep Reading