Chainalysis says blockchain “dead drop” abuse jumped about 420% over the past 12 months

Chainalysis says blockchain “dead drop” abuse jumped about 420% over the past 12 months

N
News Editor
2026-09-18 00:26:57
A new Chainalysis report says the use of so-called blockchain “dead drops” — a technique that stores malicious payloads or command-and-control, or C2, configurations in on-chain transactions and smart contracts — rose about 420% over the past 12 months. The report says average daily malicious writes increased from 2.06 to 11.1, with more than 15 operations identified across five major public blockchains. Chainalysis also said that, as of the second quarter of 2026, state-backed actors accounted for roughly two-thirds of newly observed activity. The report names North Korea’s UNC5342, which it said had targeted crypto developers with fake job offers since February 2025 and repeatedly used TRON, Aptos and BSC. It also said parties linked to Iran’s Ministry of Intelligence had encoded data through Bitcoin OP_RETURN since late 2024, while Russian-speaking criminal groups were operating on Polygon under a malware-as-a-service model.

According to a Chainalysis report cited by ChainCatcher, the use of “blockchain dead drops” — storing malicious payloads or command-and-control, or C2, configurations in on-chain transactions and smart contracts — increased by about 420% over the past 12 months.

Average daily malicious writes rose from 2.06 to 11.1, and more than 15 operations have been identified across five major public blockchains, the report said.

As of the second quarter of 2026, state-backed actors accounted for about two-thirds of newly observed activity. Chainalysis said North Korea’s UNC5342 had been targeting crypto developers with fake job offers since February 2025, with repeated use of TRON, Aptos and BNB Smart Chain, or BSC. Parties linked to Iran’s Ministry of Intelligence had used Bitcoin OP_RETURN to encode data since late 2024, while Russian-speaking criminal groups were operating on Polygon under a malware-as-a-service model.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1900

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.