Photo: Julio Lopez / Pexels
Chainalysis reports onchain malware activity surges 420% as AI lowers barriers for attackers
Cybercriminals and state-linked groups are increasingly adopting "Blockchain Dead Drops" technique to hide malware instructions on public blockchains.
Blockchain-based malware activity has surged 420% over the past year as cyber attackers increasingly use public blockchains to conceal malware instructions and maintain command-and-control infrastructure, according to a new report from Chainalysis.
The crypto analytics firm said nation-state actors, including groups linked to North Korea and Iran, represent the majority of Blockchain Dead Drops (BDDs) activity. The growth has accelerated alongside open-source AI coding tools, which have lowered the technical barrier to deploying blockchain-based malware infrastructure.
BDDs allow attackers to store malware payloads, C2 configurations and infrastructure pointers in public blockchain transactions and smart contracts. Because blockchains are difficult to take offline, infected devices can continue retrieving updated instructions even after conventional domains, servers and repositories are disrupted.
Chainalysis said BDDs have risen 440% since the emergence of high-capacity open-source Chinese AI models that can generate malicious code without restrictions.
The technique dates back more than a decade, when attackers used Bitcoin and Namecoin to store C2 information. BDDs became more sophisticated on EVM networks in 2023, when ClearFake operators used EtherHiding to place malicious code in BSC smart contracts. Iranian threat actors later began embedding C2 data in Bitcoin transactions, while North Korean operators adopted EtherHiding in campaigns targeting cryptocurrency developers.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Chainalysis, which tracks BDDs across five major blockchains and more than a dozen malware strains, said it observed malicious blockchain writes rising from over 2 per day to about 11 per day following the emergence of high-capacity open-source Chinese AI models.
State-linked actors have become an increasingly important part of that activity. Through early 2024, cybercriminals accounted for essentially all malware instructions posted to blockchains. State-linked groups began appearing meaningfully in mid-2024, and by Q2 2026 they accounted for roughly two-thirds of new BDD activity each quarter and half of total activity.
Most BDD campaigns use either transaction-based or contract-based storage. Malware retrieves the information from the blockchain and then moves off-chain to carry out activities such as credential theft, remote access or data exfiltration. Attackers have also used phantom wallet addresses to encode C2 server IP addresses.