Instances of malware instructions hidden on public blockchains have surged 440% in under a year, averaging 11 cases per day, according to a report published by Chainalysis on Thursday. Before
Instances of malware instructions hidden on public blockchains have surged 440% in under a year, averaging 11 cases per day, according to a report published by Chainalysis on Thursday. Before mid-2025, the average was two per day.
Chainalysis is one of the largest blockchain analytics firms, providing investigative tools to governments, law enforcement agencies and financial institutions worldwide.
A blockchain is a shared digital ledger that permanently records every transaction made on a network, a feature that makes it useful for tracking money, but also, as the report shows, for hiding malicious code in plain sight.
Related: Satoshi-era Bitcoin stash untouched for 16 years, here's what it's worth now
What is a "blockchain dead drop"
The technique Chainalysis describes works like a digital dead drop. Attackers write malware instructions, such as commands telling infected computers where to send stolen data, directly into blockchain transactions or smart contracts.
Because blockchains are permanent and publicly accessible, the instructions can't be taken down or blocked the way a traditional server can. Any infected device that knows where to look can read the instructions without the attacker needing to maintain a separate command server.
The report calls this technique "EtherHiding" when it uses Binance Smart Chain, though similar methods have been observed across multiple networks.
Open-source AI as the accelerant
Chainalysis ties the 440% spike directly to the release of powerful open-source AI models in mid-2025 that carry no restrictions on generating malicious code.
Popular on TheStreet Roundtable:
These tools have lowered the technical barrier for less-experienced hackers, allowing them to build blockchain-based malware infrastructure that earlier required specialized knowledge.
North Korean and Iranian state-linked groups are among those using the technique, the report said, alongside financially motivated cybercriminals.
A feature turned into a vulnerability
The same property that makes blockchains valuable, immutability, meaning data once recorded cannot be altered or deleted, is what makes them attractive to attackers.
Traditional cybersecurity defenses focus on taking down malicious servers or blocking known IP addresses. When the instructions live on a blockchain, those defenses don't apply. The data is permanent, publicly readable and hosted across thousands of nodes worldwide.
Chainalysis said the trend represents an emerging front in blockchain-related cybercrime, one that requires new detection approaches beyond traditional takedown methods.
Related: CFTC makes it easier for software platforms to offer crypto trading