
Chainalysis finds that nation-state hackers are increasingly hiding malware instructions directly on public blockchains, with state-linked activity growing 5.2 times over the past year.
Blockchain analytics firm Chainalysis has published new research showing that North Korean and Iranian state-linked threat actors are driving a sharp rise in a cyberattack technique known as blockchain dead drops (BDDs).
According to the report, BDD activity has surged 420% over the past 12 months, and nation-state operators now account for roughly half of all recorded activity.
What Is a Blockchain Dead Drop?
Rather than storing malicious code on centralised servers, attackers hide malware instructions directly on public blockchains which are resistant to censorship and shutdown.
This technique is known as a blockchain dead drop, where payloads are stored in on-chain transactions or smart contracts that infected devices can query on demand to retrieve updated attacker instructions.
The technique isn’t new; the earliest example dates back to 2013 when a variant of the Necurs botnet stored command-and-control (C2) domains on Namecoin. The rising popularity of the attack technique is in part due to the lowered entry barrier resulting from open-source AI models.
The 2025 launch of high-capacity, open-weight Chinese AI models, which place no restrictions on generating malicious code, coincided with the jump in malicious blockchain writes from 2.06 per day to 11.1 per day.
Key Technical Deployment Methods
Chainalysis identified two principal storage models: transaction-based storage, and contract-based storage.
The former sees attackers publishing C2 configurations within blockchain transactions for later retrieval, while the latter uses smart contracts as more resilient storage locations. Newer variants also utilise a technique that hides C2 server IP addresses inside the bytes of “phantom wallets”, or addresses with no private keys, that are activated via zero-value transactions.
Why Blocking Traffic Fails
Defenders cannot feasibly counter BDDs by blocking blockchain traffic. Blocking traffic on Ethereum, for example, would require blocking every public RPC endpoint operated by providers like Cloudflare, Infura, and Alchemy. This would also disrupt key wallet and decentralised finance (DeFi) services, while attackers would simply fall back to running their own node.
North Korea Case Study
The report details a DPRK-linked group using smart contracts to deliver malware to job-seeking cryptocurrency developers through fake recruiter schemes.
Iran Case Study
Chainalysis attributes activity to threat actors it suspects are linked to Iran’s Ministry of Intelligence, who embed encoded C2 routing data into Bitcoin transactions sent to a well-known address historically associated with Satoshi Nakamoto.
BDD Countermeasures
The same immutability making blockchains attractive to attackers also makes their activity uniquely observable. By tracing the evidence trail left in each transaction, defenders using blockchain intelligence and infrastructure identification tools can profile adversaries and tailor their response.
Read more via the report here.
Stay updated on crypto and AI by following our socials.


