Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Add preferred source
Chainalysis reported a 420% surge in malware instructions and infrastructure data stored on public blockchains over the past year, with state-linked hackers now responsible for roughly two-thirds of such activity. The firm identified North Korean and Iranian operators as the primary actors, connecting previously unattributed transactions across Tron, Aptos, and BNB Smart Chain to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence. Iranian-linked actors were found writing command-and-control data onto the Bitcoin blockchain, using a well-known address tied to Satoshi Nakamoto as a permanent checkpoint. The technique, known as blockchain dead drops, persists after conventional infrastructure is taken down. Malicious blockchain writes rose 440% since July 2025, coinciding with the release of capable open-source Chinese AI models, though Chainalysis could not prove a causal link.
Key Elements

The volume of malware instructions and infrastructure data planted on public blockchains has surged 420 percent over the past year, with state-linked operators now responsible for roughly two of every three such payloads, according to new research from blockchain analytics firm Chainalysis.
The findings, published Thursday, point to a significant escalation in a tactic security researchers call the “blockchain dead drop,” or BDD. The technique allows attackers to store malicious payloads and command-and-control routing information inside on-chain transactions and smart contracts, where the data remains accessible long after conventional hosting infrastructure has been dismantled.
North Korean and Iranian operators were singled out as the most active state actors adopting the method. In one investigation, Chainalysis connected a set of previously unattributed transactions spanning three separate networks to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.
That campaign routed infected devices through Tron as the primary channel, with Aptos serving as a backup path, before terminating at the same transaction on BNB Smart Chain. The BSC transaction contained encrypted server addresses and configuration data that linked compromised machines to offchain infrastructure used for remote access and data theft, Chainalysis said.
The operation mirrored a similar approach from 2025, when North Korean hackers used a technique known as EtherHiding to plant crypto-stealing code inside smart contracts on Ethereum-style chains. The persistence of on-chain data gives such campaigns a durability advantage over malware parked on traditional servers, which can be neutralized when domains are seized or hosting accounts are terminated.
Chainalysis also identified threat actors believed to be connected to Iran’s Ministry of Intelligence writing encoded command-and-control routing data directly onto the Bitcoin blockchain. The assessment drew on the malware family involved, decoding methods, timing, and server infrastructure tied to previously reported Iranian operations, rather than on-chain activity alone.
One unusual signature stood out: attacker-controlled wallets sent small payments to a well-known Bitcoin address with historical ties to Satoshi Nakamoto, the pseudonymous creator of Bitcoin. Chainalysis stressed the address had no connection to the attackers themselves. Instead, it functioned as a permanent public location that infected devices could check for updated instructions.
The arrangement gave operators a way to rotate their server infrastructure simply by publishing another Bitcoin transaction. Infected machines would then automatically retrieve the new routing information. Once the malware obtained those instructions, the operation shifted offchain for activities that could include remote access, credential theft, and the delivery of additional malware.
The first documented instance of the tactic dates to 2013, when a Necurs botnet variant parked its command-and-control domains on Namecoin. In 2019, operators of the Glupteba mining botnet used Bitcoin’s OP_RETURN field to conceal data.
The technique gained broader traction in mid-2023 under the EtherHiding label, when ClearFake operators migrated their infostealer code to BNB Smart Chain after Cloudflare took down their servers. As recently as early 2024, ordinary cybercriminals accounted for most of the activity. By the second quarter of 2026, however, nation-state operators were writing approximately two-thirds of all dead-drop payloads on public blockchains
The raw pace of malicious writes has also accelerated. Since July 2025, the analytics firm recorded a 440 percent increase in the number of malicious blockchain writes, from about 2.06 per day to 11.1 per day.
That timing coincides with the emergence of high-capacity open-competent malicious code with limited safeguards. Eric Jardine, cybercrimes research lead at Chainalysis, said the firm found a “clear point-in-time association” between the two trends, but could not confirm that the actors publishing the malicious transactions had actually used the models to boost their output
The report adds to a growing body of evidence documenting North Korean cyber operations. CertiK estimated in May that DPRK-linked actors have stolen approximately $6.75 billion since 2016 across 263 incidents, leaning heavily on social engineering rather than pure software exploits. Separate research presented at Black Hat this year put the reach wider still, with one investigator finding North Korean operators had infiltrated 1,640 companies across 57 countries.
U.S. intelligence has said funds taken by these operations help pay for the regime’s nuclear and missile programs, a charge Pyongyang has denied.
For exchanges, wallet providers, and security teams, the shift toward blockchain-based malware distribution presents a difficult challenge. Unlike traditional infrastructure, which can be seized or taken offline, data written to a public ledger persists indefinitely. The immutable nature of blockchains, long touted as a feature for legitimate applications, has become a liability in the fight against state-sponsored cybercrime.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
Source: finance.biggo.com
