Chainalysis Says Blockchain Dead Drop Attacks Rose 420% as State-Linked Groups Took a Larger Share

Chainalysis Says Blockchain Dead Drop Attacks Rose 420% as State-Linked Groups Took a Larger Share

N
News Editor
2026-09-18 16:59:38
Blockchain dead drop attacks, a technique that uses public blockchains to hide malware instructions or pointers to command-and-control systems, climbed 420% over the past 12 months, according to Chainalysis. The firm said the increase was measured on a year-over-year basis, and that by the second quarter of 2026, state-linked groups were responsible for roughly two-thirds of new activity each quarter and half of all activity it tracked. Chainalysis also reported a separate rise in malicious blockchain writes, from 2.06 per day before the arrival of high-capacity, open-weight Chinese AI models in mid-2025 to 11.1 per day in less than a year, a 440% increase. The report described campaigns tied to North Korea, suspected operators linked to Iran’s Ministry of Intelligence, and Russian-language criminal groups using chains including Tron, Aptos, BNB Smart Chain, Bitcoin, and Polygon. The firm said the technique does not make malware inherently more destructive, but it removes the central server defenders would usually seize or shut down. As long as the underlying chain stays online, the stored code or pointer remains accessible.

Blockchain dead drop attacks, which use public blockchains to conceal malware instructions, rose 420% over the past 12 months, Chainalysis said. The company described that figure as a year-over-year increase. By the second quarter of 2026, state-linked groups accounted for roughly two-thirds of new activity in this category.

In a separate measure, Chainalysis said malicious blockchain writes increased from 2.06 per day before the arrival of high-capacity, open-weight Chinese AI models in mid-2025 to 11.1 per day in less than a year, a 440% jump.

How the technique works

Chainalysis calls the method a blockchain dead drop, or BDD. Attackers place malware payloads or pointers to their current command-and-control infrastructure in transaction data or smart contracts. Infected devices read the onchain entry and then connect to the attackers’ offchain systems, where credential theft, remote access, or data exfiltration takes place.

Redundant chains make disruption harder

In one campaign linked to North Korea, Chainalysis said operators placed encoded pointers on Tron and Aptos, with both leading infected devices to the same transaction on BNB Smart Chain. The malware checks Tron first and uses Aptos as a fallback. The BNB Smart Chain transaction holds encrypted configuration data and command-and-control server addresses.

That setup allows operators to rotate offchain servers by publishing a new transaction while leaving infected devices programmed to fetch the latest instructions. Chainalysis said disrupting the campaign would require coordinated action across all three chains.

Google Threat Intelligence Group separately documented North Korea-linked group UNC5342 using a related technique since February 2025. Google said the group embedded malicious code in public-chain smart contracts during fake job interview campaigns aimed at cryptocurrency developers.

Cases tied to Iran and Russian-language groups

Chainalysis also attributed a transaction-based method to operators it suspects are linked to Iran’s Ministry of Intelligence. Those actors sent small Bitcoin payments while encoding command-and-control routing data in the transactions for malware to retrieve. The firm said its Iran assessment was based not on blockchain activity alone, but on the malware family, decoding logic, timing, and infrastructure.

According to the report, Russian-language criminal groups used Polygon smart contracts to store and update infrastructure locations for malware-as-a-service customers. Chainalysis said those actors were not necessarily state-sponsored. It classified them as Russian-language groups based on linguistic analysis and external reporting.

Persistence rather than greater destructive power

Chainalysis said blockchain records do not make malware more destructive. What they do is remove the central server that defenders would normally seize or take offline. As long as the underlying chain remains operational, the stored code or pointer stays available.

Access routes can still come under pressure. Google said centralized API providers used by UNC5342 acted quickly after its researchers reached out, though several other platforms did not respond.

The mix of actors has shifted

Chainalysis said cybercriminals accounted for nearly all blockchain dead-drop activity through early 2024. By the second quarter of 2026, state-linked groups generated roughly two-thirds of new activity each quarter and represented half of all activity tracked by the firm.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.