Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Blockchain News

Blockchain Dead Drops Surge 440% as State-Linked Actors Expand Use 

Chainalysis says attackers are using Bitcoin, BNB Chain, TRON, Aptos and Polygon to store malware infrastructure data, with state-linked groups driving recent growth.

Written By Isha Chavda
Edited by Sujha Sundararajan
Published 2026-09-17·Updated 14 hours ago
Make The Crypto Times preferred on GoogleGoogle
Hooded hacker using a Chainanalysis-branded laptop with flags of North Korea and Iran in the background.

Key Highlights

  • Chainalysis identified more than 15 campaigns and threat-actor clusters using blockchain dead drops.
  • Malicious on-chain writes increased from 2.06 to 11.1 per day, a 440% rise in less than a year.
  • North Korea- and Iran-linked operators are among the groups using blockchains as part of malware infrastructure.

Public blockchains are increasingly being used as part of malware infrastructure, with attackers storing command-and-control data and infrastructure information in transactions and smart contracts.

According to a Chainalysis report published September 17, the firm identified more than 15 campaigns and threat-actor clusters using what it calls blockchain dead drops (BDDs).

Our latest research shows how North Korean and Iranian hackers are increasingly launching hard-to-stop cyberattacks. And they’re using blockchains to do it.

We call the attack tactic “Blockchain Dead Drops,” or BDDs. BDDs are getting more sophisticated, more prevalent, and… pic.twitter.com/mBx8EyMmQ8

— Chainalysis (@chainalysis) September 17, 2026

The technique allows malware on compromised devices to retrieve information from public blockchains rather than relying entirely on conventional servers. Chainalysis said malicious blockchain writes increased from an average of 2.06 per day to 11.1 per day, a 440% increase in less than a year.

The firm said state-linked groups, including operators associated with North Korea and Iran, now account for much of the new activity.

How blockchain dead drops work

A blockchain dead drop is a location on a public blockchain where attackers store malware payloads, command-and-control configurations, or pointers to infrastructure.

The information can be embedded in transactions or smart contracts. Malware on an infected device retrieves and decodes the data before connecting to the attacker’s off-chain infrastructure.

The approach does not necessarily replace conventional command-and-control systems. Instead, blockchain data can provide a durable layer for delivering updated infrastructure information even when domains, servers, or repositories used by attackers are disrupted.

Chainalysis said the main advantage is campaign durability rather than greater destructive capability.

“The danger of blockchain dead drops is not greater destructive power. The danger is greater campaign durability.”

Activity rises alongside AI coding tools

Chainalysis linked the increase in BDD activity to the emergence of powerful open-source AI coding models during 2025.

The firm said developing blockchain-based command-and-control infrastructure historically required substantial cybersecurity and blockchain expertise. The availability of open-weight AI models capable of generating code may have lowered some of those technical barriers.

The timing coincides with the increase in malicious blockchain writes from 2.06 to 11.1 per day.

Chainalysis did not establish that AI caused the increase. Instead, it identified the emergence of these models and the subsequent growth in BDD activity as a notable correlation.

State-linked groups drive new activity

The composition of BDD activity has changed over time.

Cybercriminal groups accounted for almost all identified activity through early 2024, according to Chainalysis. State-linked groups became more prominent from the middle of that year.

By Q2 2026, state-linked actors accounted for roughly two-thirds of new BDD activity in each quarter and around half of total activity.

Chainalysis identified activity associated with North Korean, Iranian and Russian-language threat actors.

The firm cautioned that attribution varies by campaign. Its assessment of Iranian activity, for example, relies on malware characteristics, decoding methods, operational timing and related infrastructure rather than blockchain activity alone.

North Korean campaign uses three networks

One campaign involves UNC5342, a North Korea-linked group previously associated with attacks targeting cryptocurrency developers through fake job opportunities.

Chainalysis identified a BDD technique using TRON and Aptos to direct infected devices toward information stored on BNB Smart Chain.

The attackers embed encoded pointers in TRON and Aptos transactions. Malware checks one route and can use the other if the first fails, providing redundancy before retrieving encrypted instructions from BNB Smart Chain.

The BNB Smart Chain transaction contains encrypted malware instructions, including C2 addresses and configuration data, and references to additional on-chain stages.

When attackers change their infrastructure, they can publish updated transaction data rather than modifying malware already installed on victims’ devices.

Chainalysis linked the activity to a BNB Smart Chain deployer previously attributed to UNC5342.

Iran-linked operators use Bitcoin transactions

Chainalysis also identified activity it believes is connected to Iranian state operators using Bitcoin transactions to store command-and-control information.

In the campaign, attackers send small Bitcoin payments to a well-known address with historical links to Satoshi Nakamoto. The payments themselves are not the main purpose of the transactions.

Instead, malware searches the transaction data for encoded information that can be decoded to identify the attackers’ current infrastructure.

Chainalysis said the assessment linking the activity to Iran is based on evidence from the malware and broader operation rather than the Bitcoin transactions alone.

The blockchain therefore functions as a publicly accessible lookup point while the actual malware activity continues through off-chain infrastructure.

Russian-language groups use Polygon

Chainalysis also identified Russian-language cybercriminal groups using Polygon smart contracts to store infrastructure information.

In one campaign, a smart contract acts as a resolver containing the current location of attacker-controlled infrastructure. Operators can update the information when domains or servers are disrupted.

The firm observed one operator wallet controlling multiple resolver contracts, a structure it said is consistent with a malware-as-a-service model in which different contracts may serve separate customers or campaigns.

Chainalysis also linked the broader infrastructure to activity involving fraudulent tokens and campaigns targeting cryptocurrency users.

Public chains create a detection challenge

Using public blockchains creates a challenge for defenders because the same networks support legitimate wallets, exchanges, and decentralized applications.

Chainalysis said simply blocking blockchain traffic would be impractical because it could disrupt legitimate wallets, applications and DeFi services while still leaving attackers able to use alternative infrastructure.

At the same time, public blockchain activity creates a record of transactions, contract deployments and updates.

Investigators can examine transaction histories, resolver contracts, wallet relationships, and related activity to identify connections between infrastructure that might otherwise appear unrelated.

Recent crypto campaigns add context

The findings come as state-linked groups continue targeting cryptocurrency users through different methods.

In July 2026, North Korea-linked BlueNoroff used fake Zoom meeting invitations to distribute malware. The campaign reportedly used trusted Telegram contacts and targeted people involved in crypto, including checking whether potential victims held cryptocurrency before attempting to infect their devices.

That campaign relied on social engineering and malware delivery rather than blockchain dead drops, but it illustrates another method used by state-linked actors targeting cryptocurrency participants.

BDDs add another layer to cyber investigations

The Chainalysis findings show that public blockchains can serve a role in malware infrastructure even when the underlying attack does not involve stealing cryptocurrency.

The report identified BDD activity across five major blockchains and more than a dozen malware strains.

For defenders, this adds another consideration when investigating malware campaigns: blockchain transactions and smart contracts may contain infrastructure information that connects otherwise separate parts of an operation.

The growth in malicious on-chain writes suggests that public blockchains are becoming an additional infrastructure layer for some cybercriminal and state-linked campaigns, while their public records give investigators another source of evidence.

Also Read: MarsCat’s MCAT Surges 186% as Trading Activity Jumps

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Blockchain
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Galaxy Says Crypto Can Move On as CLARITY Act Stalls in Senate
Galaxy Says Crypto Can Move On as CLARITY Act Stalls in Senate
Strategy Stock MSTR Jumps 13% to $151 as Bitcoin Gains Focus
Strategy Stock MSTR Jumps 13% to $151 as Bitcoin Gains Focus
Collection of physical cryptocurrency coins, featuring Bitcoin in the center, against a green rising stock candlestick chart.
Why Is the Crypto Market Up Today? Altcoins Lead the Rally
Haruko Cyberattack Exposes API Data Across 15 Crypto Clients 
Haruko Cyberattack Exposes API Data Across 15 Crypto Clients 
Litecoin Posts Over 4% Gain in 24Hrs Amid Rising Open Interest
Litecoin Posts Over 4% Gain in 24Hrs Amid Rising Open Interest

Find Us on Socials

You may also like

Gold Zcash cryptocurrency coin with Z symbol against a digital blockchain network background

Zcash NU7 Mainnet Upgrade Targets November 5 With 25-Second Blocks

Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.

Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch

A hand holding a smartphone with the Arc logo in front of a blurred Circle company logo.

Circle’s USDC-Native Layer 1 Blockchain ‘Arc’ Goes Live on Mainnet 

KuCoin Opens Direct USDC Transfers as Circle’s Arc Blockchain Goes Live

KuCoin Opens Direct USDC Transfers as Circle’s Arc Blockchain Goes Live

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information