Highlights
- Cases of malware instructions written into onchain transactions and smart contracts are up roughly 440% in under a year
- Daily cases rose from about 2 per day to roughly 11 per day, per Chainalysis
- State-linked hacking groups tied to North Korea and Iran now drive about two-thirds of the activity
- The surge tracks the mid-2026 release of unrestricted open-source AI models capable of generating malicious code
A blockchain's biggest selling point — nobody can erase what's written to it — has become one of cybercrime's more durable tools. Chainalysis calls the technique a "blockchain dead drop": a pre-arranged, takedown-resistant spot on a public chain where an attacker deposits malicious payloads, command-and-control configurations, or pointers that malware on an infected machine later retrieves. Because the location can't be seized or taken offline the way a web server can, attackers can rotate their infrastructure with a single new transaction instead of needing to reinfect victims from scratch.
What's changed isn't the technique — Chainalysis and others have tracked blockchain dead drops for years — it's the volume. The firm's data shows daily cases climbing from roughly two per day to about eleven, a jump of approximately 440% in less than twelve months. The inflection point lines up almost exactly with the mid-2026 release of powerful open-source AI models out of China with no built-in restrictions on generating malicious code. Unlike commercial AI tools that refuse overtly harmful requests, open-source models can be run entirely offline and modified by whoever downloads them, stripping out whatever safety guardrails the original developers built in.
That capability shift changed who's using the technique as much as how often. Through early 2026, blockchain dead drops were overwhelmingly a financially motivated cybercriminal tool. Chainalysis's newer data shows state-linked groups — primarily those tied to North Korea and Iran — now account for roughly two-thirds of new dead-drop activity each quarter, a rough reversal of the earlier pattern. For groups already known for large-scale crypto theft to fund state programs, a persistent, unseizable channel for coordinating malware campaigns is a natural fit alongside their existing playbook.
Related: DCENT Flags Abnormal Transfers, Urges App Wallet Users to Move Funds
The mechanics work against victims in a way traditional malware infrastructure doesn't. A conventional command-and-control server can be identified, sanctioned, or knocked offline by researchers and law enforcement working with hosting providers — that's a large part of how security teams disrupt ongoing campaigns. A dead drop written into a smart contract or transaction has none of that friction; once it's on a public, permissionless ledger, it stays there permanently, and taking it down would require rewriting the blockchain's history, which isn't realistically possible on any major chain. Attackers can update their instructions by simply broadcasting a new transaction rather than standing up new infrastructure that defenders might catch.
The finding lands alongside a string of more conventional crypto-security warnings this week. BlueWallet's CTO recently screened 904 iOS crypto wallet apps and found 45 with serious security failures, and researchers separately flagged a fake GTA 6 "leak" site that was actually a multi-chain wallet drainer — a reminder that the AI-driven sophistication showing up in state-sponsored dead-drop campaigns exists on the same threat spectrum as much cruder scams still working on ordinary users. Chainalysis's report doesn't suggest dead drops are close to being contained; if open-source AI models keep getting more capable and more accessible, the 440% jump this year is more likely a floor than a ceiling for what shows up in next year's numbers.
FAQ
What exactly is a “blockchain dead drop”?
It's a spot on a public blockchain — inside a transaction or smart contract — where an attacker stores malware instructions or command-and-control data for later retrieval, taking advantage of the fact that blockchain records can't be deleted or taken offline.
Does this put ordinary crypto users at risk, or just enterprises?
The technique itself targets infected machines and networks rather than crypto wallets directly, so it's primarily a cybersecurity concern for organizations. It's a separate risk category from wallet-drainer scams and phishing sites, though both reflect the same broader trend of attackers becoming more resourced.
Why are North Korea and Iran specifically named?
Chainalysis attributes roughly two-thirds of current dead-drop activity to state-linked groups tied to those two countries, consistent with their documented use of crypto theft and cyber operations to fund state programs under sanctions.
