Advertisement

Blockchain Dead Drop Attacks Jump 420% as State Hackers Expand

Chainalysis says North Korean operators use Tron, Aptos and BNB Smart Chain as redundant command paths, while suspected Iranian actors encode routing data in Bitcoin transactions.
By: The Defiant Team · Edited by Camila Russo
Blockchain Dead Drop Attacks Jump 420% as State Hackers Expand

Blockchain dead drop attacks — campaigns that use public chains to hide malware instructions — increased 420% over the past 12 months, Chainalysis said, as state-linked groups came to account for roughly two-thirds of new activity in the second quarter of 2026.

Chainalysis described the 420% figure as a year-over-year increase in attacks. Separately, it measured malicious blockchain writes rising from 2.06 per day before the arrival of high-capacity, open-weight Chinese AI models in mid-2025 to 11.1 per day, a 440% increase in less than a year.

The firm calls the technique a blockchain dead drop, or BDD. Attackers place malware payloads or pointers to their current command-and-control infrastructure in transaction data or smart contracts. Infected devices read the entry and then connect to the attackers’ offchain systems, where credential theft, remote access or data exfiltration occurs.

Redundant Chains Raise Takedown Costs

In one North Korea-linked campaign, Chainalysis said operators placed encoded pointers on Tron and Aptos that both led infected devices to the same transaction on BNB Smart Chain. The malware checks Tron first and uses Aptos as a fallback; the BNB Smart Chain transaction contains encrypted configuration data and command-and-control server addresses.

The setup lets operators rotate their offchain servers by publishing a new transaction while leaving infected devices programmed to retrieve the latest instructions. Chainalysis said disrupting that campaign would require coordinated action across all three chains.

Google Threat Intelligence Group independently documented North Korea-linked group UNC5342 using a related technique since February 2025. Google said the group embedded malicious code in public-chain smart contracts during fake-job-interview campaigns targeting cryptocurrency developers.

Chainalysis also attributed a transaction-based technique to operators it suspects are linked to Iran’s Ministry of Intelligence. Those actors sent small Bitcoin payments while encoding command-and-control routing data in the transactions for malware to retrieve. The firm said the Iran assessment rests on the malware family, decoding logic, timing and infrastructure rather than the blockchain activity alone.

Russian-language criminal groups used Polygon smart contracts to store and update infrastructure locations for malware-as-a-service customers, according to the report. Chainalysis said the actors were not necessarily state-sponsored and classified them as Russian-language based on linguistic analysis and external reporting.

Persistence, Not More Destructive Malware

The blockchain records do not make malware more destructive, but they remove the central server that defenders would normally seize or take offline. As long as the underlying chain remains operational, the stored code or pointer remains available.

Access routes can still be pressured. Google said centralized API providers used by UNC5342 were quick to act when its researchers contacted them, although several other platforms remained unresponsive.

Chainalysis said cybercriminals accounted for nearly all blockchain dead-drop activity through early 2024. By the second quarter of 2026, state-linked groups generated roughly two-thirds of new activity each quarter and represented half of all activity tracked by the firm.

Advertisement

Get an edge in Crypto with our free daily newsletter

Know what matters in Crypto and Web3 with The Defiant Daily newsletter, Mon to Fri

90k+ Defiers informed every day. Unsubscribe anytime.