Chainalysis: Blockchain Dead Drops for Malware Surge 420% in a Year
Cybercriminals and state-sponsored hackers are increasingly storing malware instructions directly on public blockchains, a tactic Chainalysis calls “blockchain dead drops,” according to a rep
A
AnonymousCryptoCompass newsroom
September 18, 2026
2 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for bitcoin coverage.
Cybercriminals and state-sponsored hackers are increasingly storing malware instructions directly on public blockchains, a tactic Chainalysis calls “blockchain dead drops,” according to a report the analytics firm published on September 17. The practice has surged 420% over the past year and 440% since open-source Chinese AI models began generating malicious code, with North Korean and Iranian state-linked groups now responsible for roughly two-thirds of new activity.
How Blockchain Dead Drops Work
Blockchain dead drops, or BDDs, store malware payloads and command-and-control configuration data in on-chain transactions and smart contracts, where infected machines can retrieve them on demand. Because public blockchains cannot be taken offline, the technique gives campaigns a durability that survives domain seizures, hosting takedowns and repository removals. The danger is not greater destructive power, Chainalysis notes, but greater campaign longevity. Once the malware retrieves what it needs, the operation moves off-chain for the actual compromise. This builds on earlier reporting in which Microsoft exposed BNB Smart Chain contracts used to deliver malware instructions.
Nation-State Actors Take the Lead
The tactic has existed for more than a decade, from a Necurs botnet variant storing command-and-control domains on Namecoin in 2013 to the Glupteba botnet writing data into Bitcoin’s OP_RETURN field in 2019. It reached EVM chains in mid-2023 with “EtherHiding,” when ClearFake operators embedded malware in Binance Smart Chain smart contracts after Cloudflare disrupted their servers. Iranian threat actors embedded command-and-control data in Bitcoin transactions in late 2024, and North Korean agents folded EtherHiding into their fake job interview ruse in early 2025. By the second quarter of 2026, state-linked groups accounted for roughly half of total dead-drop activity, with malicious writes to the blockchain climbing from 2.06 per day to 11.1 per day.
AI Lowers the Barrier, and Threat Intel Misses It
The surge accelerated after open-weight Chinese large language models launched without restrictions on generating malicious code, removing the expertise barrier that once limited the tactic to sophisticated operators. Chainalysis now tracks dead drops across five major blockchains and more than a dozen named malware strains, with campaigns often targeting crypto wallets and credentials through infostealing malware or installing remote access trojans for persistent control. The firm warns that traditional threat-intelligence platforms can miss on-chain activity, echoing its earlier finding that AI use in crypto crime jumped 40% in a year.
Ripple CTO Emeritus David Schwartz has entered the discussion regarding the cautious stance of major cryptocurrency exchanges, including Coinbase, toward listing Bitcoin BLAKE2b, a new asset
Ethereum-related non-profit Ethereum Institutional has publicly backed Ethlabs’ push to make the network faster by reducing block times. In a Friday post on X, the group argued that shorter b
A three-person team at security startup Hacktron AI chained two flaws to hijack an OpenAI employee’s ChatGPT account and reach the company’s private code. The whole break-in took less than 72