Blockchain malware writes rose from 2.06 a day to 11.1 after high-capacity open-weight Chinese AI models emerged, a 440% increase in less than a year, Chainalysis said. By the second quarter of 2026, groups linked to North Korea and Iran accounted for roughly two-thirds of newly observed blockchain-dead-drop activity each quarter. State-linked operators represented about half of all activity tracked by the firm, up from a negligible share in early 2024.
Why it matters
A blockchain dead drop stores malware instructions, command-and-control addresses or infrastructure pointers inside transactions and smart contracts. Infected devices can query those public records for updates, allowing attackers to rotate servers without reinfecting victims. Chainalysis said AI coding tools lowered the expertise needed to build this infrastructure, while noting that its data does not identify a single model or prove that AI alone caused the increase.
North Korean-linked group UNC5342 used TRON and Aptos as redundant routes into BNB Smart Chain, with infected devices switching routes if one failed. Iran-linked operators instead embedded routing information inside Bitcoin transactions sent to a well-known address associated with Satoshi Nakamoto. The address has no connection to the attackers and serves as a permanent public reference point.
Market impact
The technique raises operational risk for crypto companies, developers and enterprises, but blocking entire networks would also disrupt legitimate wallets, DeFi platforms and other applications. Russian-language criminal groups have used Polygon smart contracts as command resolvers, including infrastructure offered through a malware-as-a-service model.
The same permanence that helps attackers also creates a monitoring trail. Defenders can map wallets, resolver contracts and update histories, while organizations can inspect outbound JSON-RPC requests for suspicious queries. RPC gateways, API providers, exchanges and cybersecurity firms are likely to face growing pressure to block malicious activity without impairing ordinary blockchain access.
Frequently asked questions
-
What is a blockchain dead drop used for in malware campaigns?
It stores malware instructions, command-and-control addresses or infrastructure pointers in transactions and smart contracts. Infected devices query those public records for updates.
-
How much did malicious blockchain writing increase?
Chainalysis said malicious writes rose from 2.06 a day to 11.1, a 440% increase in less than a year.
-
Which networks did UNC5342 use for redundant malware routing?
North Korean-linked UNC5342 used TRON and Aptos as redundant routes into BNB Smart Chain. Infected devices could switch routes when one failed.
-
Why can defenders not simply block the affected blockchains?
Entire-network blocking would also disrupt legitimate wallets, DeFi platforms and other applications that rely on the same infrastructure.
-
What can defenders monitor to detect blockchain-based malware activity?
Defenders can track wallets, resolver contracts, funding relationships and update histories. Organizations can also inspect outbound JSON-RPC requests for suspicious queries.
CryptoSlate