Blockchain dead drop attacks, which use public blockchains to conceal malware instructions, rose 420% over the past 12 months, Chainalysis said. The company described that figure as a year-over-year increase. By the second quarter of 2026, state-linked groups accounted for roughly two-thirds of new activity in this category.
In a separate measure, Chainalysis said malicious blockchain writes increased from 2.06 per day before the arrival of high-capacity, open-weight Chinese AI models in mid-2025 to 11.1 per day in less than a year, a 440% jump.
How the technique works
Chainalysis calls the method a blockchain dead drop, or BDD. Attackers place malware payloads or pointers to their current command-and-control infrastructure in transaction data or smart contracts. Infected devices read the onchain entry and then connect to the attackers’ offchain systems, where credential theft, remote access, or data exfiltration takes place.
Redundant chains make disruption harder
In one campaign linked to North Korea, Chainalysis said operators placed encoded pointers on Tron and Aptos, with both leading infected devices to the same transaction on BNB Smart Chain. The malware checks Tron first and uses Aptos as a fallback. The BNB Smart Chain transaction holds encrypted configuration data and command-and-control server addresses.
That setup allows operators to rotate offchain servers by publishing a new transaction while leaving infected devices programmed to fetch the latest instructions. Chainalysis said disrupting the campaign would require coordinated action across all three chains.
Google Threat Intelligence Group separately documented North Korea-linked group UNC5342 using a related technique since February 2025. Google said the group embedded malicious code in public-chain smart contracts during fake job interview campaigns aimed at cryptocurrency developers.
Cases tied to Iran and Russian-language groups
Chainalysis also attributed a transaction-based method to operators it suspects are linked to Iran’s Ministry of Intelligence. Those actors sent small Bitcoin payments while encoding command-and-control routing data in the transactions for malware to retrieve. The firm said its Iran assessment was based not on blockchain activity alone, but on the malware family, decoding logic, timing, and infrastructure.
According to the report, Russian-language criminal groups used Polygon smart contracts to store and update infrastructure locations for malware-as-a-service customers. Chainalysis said those actors were not necessarily state-sponsored. It classified them as Russian-language groups based on linguistic analysis and external reporting.
Persistence rather than greater destructive power
Chainalysis said blockchain records do not make malware more destructive. What they do is remove the central server that defenders would normally seize or take offline. As long as the underlying chain remains operational, the stored code or pointer stays available.
Access routes can still come under pressure. Google said centralized API providers used by UNC5342 acted quickly after its researchers reached out, though several other platforms did not respond.
The mix of actors has shifted
Chainalysis said cybercriminals accounted for nearly all blockchain dead-drop activity through early 2024. By the second quarter of 2026, state-linked groups generated roughly two-thirds of new activity each quarter and represented half of all activity tracked by the firm.

