
Public blockchains, once pitched as trustless infrastructure for finance and gaming, are rapidly turning into hardened malware bunkers for nation-state hackers and cybercrime crews. Chainalysis reports that blockchain-assisted cyberattacks have grown more than fivefold year over year, with Iranian and North Korean state-linked actors and Russian-speaking criminal groups driving a 420–440% spike in so‑called “Blockchain Dead Drops.”
As first highlighted in new research and covered by outlets such as Tom’s Hardware, “Blockchain Dead Drops” (BDD) refer to attacks where the instructions or payloads for malware are written directly into public blockchain transactions or smart contracts. Instead of hosting command-and-control servers or payload repositories that defenders can take down, attackers hide configuration data, IP addresses, domains, or even pieces of malicious code in immutable on‑chain data that infected machines can query whenever they need an update. Because blockchains replicate data globally and are designed to resist censorship, this infrastructure gives threat actors unprecedented durability compared with traditional web servers.
Chainalysis links the sharp rise in BDD activity to a small but very capable roster of state-backed operators, particularly those with ties to Iran’s Ministry of Intelligence and North Korean cyber units. Iranian-linked actors were observed in 2024 encoding command-and-control routing data inside Bitcoin transactions, using the network’s permanence as a feature rather than a bug. North Korean groups, already notorious for stealing billions in crypto, have begun using techniques like EtherHiding in fake job-interview campaigns, while also distributing malware infrastructure across chains such as Tron, Aptos, and BNB Chain. By mid‑2026, Chainalysis estimates that state-linked operators were responsible for roughly two-thirds of newly observed dead-drop activity each quarter, accounting for about half of all BDD incidents.
Under the hood, most of these campaigns rely on two core patterns: transaction-based storage and contract-based storage. In transaction-based BDDs, attackers embed pointers to infrastructure, configuration blobs, or encrypted payload fragments inside ordinary-looking transactions, hiding data in memo fields or calldata that malware later decodes and uses to locate the real command-and-control servers. Contract-based storage instead uses smart contracts as living configuration files, with the contract’s state holding the latest C2 pointer; EtherHiding follows this model, allowing malware to query the contract for up-to-date instructions while the attacker periodically updates the contract’s parameters. Chainalysis warns that more exotic tradecraft is emerging too, including “phantom wallets” — addresses without corresponding private keys that still carry meaningful encoded data in their on‑chain history — making it even harder for defenders to distinguish malicious writes from benign noise.
What transformed BDDs from niche tradecraft into a mainstream cyberweapon is not just geopolitical escalation, but the sudden availability of powerful, open-weight AI coding models. Chainalysis directly ties the 440% surge in on‑chain malware writes to the rise of unrestricted Chinese open-source AI tools that can generate exploit code, obfuscation routines, and blockchain interaction scripts on demand, lowering the barrier for less-experienced attackers to build sophisticated campaigns. Measured across recent months, malicious “writes” to public blockchains climbed from an average of 2.06 per day to around 11.1 per day, a nearly fivefold jump that coincides with the rollout of these models in mid‑2025. Because defenders cannot simply seize domains or force hosting providers to pull content, incident response now has to focus on detecting when client devices are talking to suspicious on‑chain data and cutting off the malware before it follows the breadcrumbs off‑chain.








