Malware instructions written to public blockchains have increased more than fivefold in a year, and state-backed operators are now responsible for roughly half of that activity, according to a Thursday report from Chainalysis.
The blockchain analytics firm said writes carrying malware instructions climbed from 2.06 a day to 11.1 a day after open-weight Chinese AI models were released in mid-2025. The activity spans more than a dozen malware strains across five blockchains, and Chainalysis said it has identified more than 15 campaigns and threat-actor clusters.
How the "blockchain dead drop" works
Chainalysis calls the technique a "blockchain dead drop." Instead of hardcoding the address of a command server into malware, attackers place that address in a smart contract or a transaction. Infected machines then query the blockchain to find out where they should connect.
That setup weakens the impact of domain blocking. A single transaction can redirect every compromised machine at once, the report said. Chainalysis added that instructions written to a public chain are nearly impossible to seize or remove through traditional takedown methods.
Three operating models identified
One case involves the North Korean group Google tracks as UNC5342. According to the report, the group now spreads its infrastructure across three chains. Pointers on TRON and Aptos both resolve to one transaction on BNB Chain, meaning any disruption effort would need coordinated action across all three networks.
The group reaches victims through fake job interviews aimed at crypto developers. Google has said the malware targets MetaMask and Phantom wallets, along with saved browser credentials.
Chainalysis also described operators it suspects are linked to Iran’s Ministry of Intelligence. Those actors write their instructions into Bitcoin transactions and send small payments to an address historically associated with Satoshi Nakamoto. The address has no connection to them, the report said, and that is precisely the point: using a permanent public lookup location reduces their footprint. Chainalysis said the link is based on the malware itself, not on-chain activity alone.
A third model appears to be run as a business by Russian-language criminals. Chainalysis said fleets of resolver contracts on Polygon are rented out to other crews. One deployer wallet appears linked to fraudulent tokens impersonating stablecoins and to more than 50 near-identical contracts on BNB Chain.
Shift from cybercriminals to state-linked groups
Through early 2024, cybercriminals accounted for essentially all of this activity, Chainalysis found. State-linked groups began appearing in meaningful numbers in mid-2024. By the second quarter of 2026, they were responsible for 51% of attributed writes.
Chainalysis tied the acceleration to open-weight Chinese models that carry no restrictions on generating malicious code. The firm said those models lowered the barrier to entry for less experienced attackers. Its timeline places the shift at the release of Kimi K2 and Qwen3-Coder.
An old idea at a new scale
Chainalysis dates the underlying idea back to 2013. Guardio Labs documented the first smart-contract version in October 2023, after a criminal group began using a BNB Chain contract in September 2023 to serve fake browser-update lures.
What changed, the report said, is the volume and the mix of actors behind it. Chainalysis also noted that defenders cannot simply block the traffic without cutting off the public endpoints that wallets and applications rely on.

