Chainalysis Says State-Linked Hackers Now Account for Half of Malware Instructions Hidden on Blockchains

Chainalysis Says State-Linked Hackers Now Account for Half of Malware Instructions Hidden on Blockchains

N
News Editor
2026-09-17 23:58:57
Malware instructions written directly to public blockchains have surged more than fivefold over the past year, and state-linked operators now account for roughly half of the attributed activity, according to a Thursday report from Chainalysis. The firm said daily writes carrying malware instructions rose from 2.06 to 11.1 after open-weight Chinese AI models were released in mid-2025, spanning more than a dozen malware strains across five blockchains. Chainalysis described the method as a "blockchain dead drop," where attackers place the address of a command server inside a smart contract or transaction instead of embedding it in malware. Infected machines then query the chain to learn where to connect, making domain blocking far less effective. The report said instructions written to public chains are extremely difficult to seize or remove through traditional means. The company outlined three operating models: a North Korean group tracked by Google as UNC5342 using TRON, Aptos, and BNB Chain; operators suspected of links to Iran’s Ministry of Intelligence writing instructions into Bitcoin transactions; and a Russian-language criminal service model renting resolver contracts on Polygon. Chainalysis said state-linked groups began appearing in meaningful numbers in mid-2024 and were responsible for 51% of attributed writes by the second quarter of 2026.

Malware instructions written to public blockchains have increased more than fivefold in a year, and state-backed operators are now responsible for roughly half of that activity, according to a Thursday report from Chainalysis.

The blockchain analytics firm said writes carrying malware instructions climbed from 2.06 a day to 11.1 a day after open-weight Chinese AI models were released in mid-2025. The activity spans more than a dozen malware strains across five blockchains, and Chainalysis said it has identified more than 15 campaigns and threat-actor clusters.

How the "blockchain dead drop" works

Chainalysis calls the technique a "blockchain dead drop." Instead of hardcoding the address of a command server into malware, attackers place that address in a smart contract or a transaction. Infected machines then query the blockchain to find out where they should connect.

That setup weakens the impact of domain blocking. A single transaction can redirect every compromised machine at once, the report said. Chainalysis added that instructions written to a public chain are nearly impossible to seize or remove through traditional takedown methods.

Three operating models identified

One case involves the North Korean group Google tracks as UNC5342. According to the report, the group now spreads its infrastructure across three chains. Pointers on TRON and Aptos both resolve to one transaction on BNB Chain, meaning any disruption effort would need coordinated action across all three networks.

The group reaches victims through fake job interviews aimed at crypto developers. Google has said the malware targets MetaMask and Phantom wallets, along with saved browser credentials.

Chainalysis also described operators it suspects are linked to Iran’s Ministry of Intelligence. Those actors write their instructions into Bitcoin transactions and send small payments to an address historically associated with Satoshi Nakamoto. The address has no connection to them, the report said, and that is precisely the point: using a permanent public lookup location reduces their footprint. Chainalysis said the link is based on the malware itself, not on-chain activity alone.

A third model appears to be run as a business by Russian-language criminals. Chainalysis said fleets of resolver contracts on Polygon are rented out to other crews. One deployer wallet appears linked to fraudulent tokens impersonating stablecoins and to more than 50 near-identical contracts on BNB Chain.

Shift from cybercriminals to state-linked groups

Through early 2024, cybercriminals accounted for essentially all of this activity, Chainalysis found. State-linked groups began appearing in meaningful numbers in mid-2024. By the second quarter of 2026, they were responsible for 51% of attributed writes.

Chainalysis tied the acceleration to open-weight Chinese models that carry no restrictions on generating malicious code. The firm said those models lowered the barrier to entry for less experienced attackers. Its timeline places the shift at the release of Kimi K2 and Qwen3-Coder.

An old idea at a new scale

Chainalysis dates the underlying idea back to 2013. Guardio Labs documented the first smart-contract version in October 2023, after a criminal group began using a BNB Chain contract in September 2023 to serve fake browser-update lures.

What changed, the report said, is the volume and the mix of actors behind it. Chainalysis also noted that defenders cannot simply block the traffic without cutting off the public endpoints that wallets and applications rely on.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
2400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.