Open Chinese AI linked to 440% rise in blockchain dead drops
Chainalysis found daily malicious on-chain writes rose from 2.06 to 11.1 since mid‑2025; North Korea- and Iran-linked groups now account for most activity.
Chainalysis reported a 440% increase in the number of times attackers stored malware instructions or infrastructure data on public blockchains since mid-2025. The firm measured daily malicious on-chain writes rising from an average of 2.06 to 11.1 within a year. State-linked groups tied to North Korea and Iran account for the bulk of the activity.
The company calls the technique “blockchain dead drops” (BDD). Threat actors embed payloads, configuration data or encoded pointers inside transactions and smart contracts so infected machines can retrieve instructions directly from a public ledger. The permanence of blockchains means those entries remain accessible after domains, servers or code repositories are taken down.
Chainalysis reported that state-linked actors increased their share of dead drops through 2026. By the second quarter of 2026, those actors produced roughly two-thirds of new quarterly activity and about half of all attributed writes in the period the firm studied.
The analysis connected a multi-chain relay to UNC5342, a group associated with North Korea. Encoded pointers on TRON and Aptos directed compromised hosts to an encrypted transaction on BNB Smart Chain that contained server addresses and configuration data. Chainalysis said the actor rotates infrastructure by publishing new transactions and that infected machines pick up the changes automatically.
In incidents tied to suspected Iranian operators, attackers wrote small Bitcoin payments to an address with historical ties to Satoshi Nakamoto. Malware scanned those transactions for embedded data, decoded routing information and used it to locate off-chain command-and-control servers. After devices retrieved updated instructions, operations moved off-chain to perform remote access, credential theft and delivery of additional malware.
Chainalysis traced earlier variants of the method to Namecoin in 2013 and to EVM chains in 2023. The firm associated the recent surge with the mid-2025 release of high-capacity, open-weight Chinese AI models that lacked safeguards against producing malicious code and lowered the technical barrier for creating on-chain payloads. Eric Jardine, Chainalysis’s cybercrimes research lead, described a “clear point-in-time association” between the models’ availability and the spike, while noting the firm could not prove operators directly used the models.
Researchers also reported on-chain techniques affecting broader software ecosystems. A supply-chain incident in August 2026 affected more than 440 npm packages. Separately, Russian-language criminal services on chains such as Polygon operate resolver contracts that appear to let paying customers publish and update dead-drop infrastructure as a service.
Chainalysis said defenders face difficult trade-offs. Blocking or filtering blockchain traffic would disrupt legitimate wallets and decentralized applications. The immutable ledger makes malicious writes durable but also leaves a public record that investigators can use to trace payments and transactions back to operators; the firm did not conclude how quickly that record will lead to effective disruption of campaigns.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.







