Blockchain analytics firm Chainalysis has recorded a 440 percent jump in malware instructions written into on-chain transactions and smart contracts over the past year, according to a report published Wednesday.

The firm calls the technique a "blockchain dead drop". Daily malicious on-chain writes rose from an average of 2.06 to 11.1 in less than twelve months.

Chainalysis ties the jump directly to mid-2025, when high-capacity, open-weight Chinese AI models launched with no restrictions on generating malicious code. Building an effective dead drop used to demand real cybersecurity and crypto expertise. The report says that barrier has now largely disappeared, a shift that mirrors how dark LLMs like WormGPT and FraudGPT already lowered the skill floor for phishing and fraud.

em360tech image

State-linked hacking groups, including operators tied to North Korea and Iran, are driving the surge. By the second quarter of 2026, Chainalysis found, state-linked actors accounted for roughly two-thirds of new dead-drop activity each quarter and about half of all activity to date.

What A Blockchain Dead Drop Actually Does

Once malware infects a device through conventional means, such as a malicious download or a supply-chain compromise, it needs to reach its command-and-control server. Attackers used to host that connection on servers or domains that investigators could seize or take offline (not unlike the way DNS tunneling abuses a trusted protocol to hide a covert channel in plain sight).

A dead drop moves that step onto a blockchain instead. Instructions, such as the current location of the attacker's server, get written into a transaction or smart contract. Because blockchain records are effectively permanent, that pointer survives takedowns of the surrounding infrastructure.

Chainalysis's own framing of the risk is blunt: "The danger is greater campaign durability."

The tactic isn't new. Chainalysis traces early versions back to 2013, when a variant of the Necurs botnet stored command-and-control domains on Namecoin. The modern wave began in mid-2023 with "EtherHiding," after ClearFake operators, blocked from their usual hosting, moved their malicious code onto Binance Smart Chain smart contracts instead.

The report details three separate operations. A North Korea-linked group tracked by Google as UNC5342, previously known for luring crypto developers with fake job offers, now relays instructions across three blockchains at once. Pointers embedded in TRON and Aptos transactions both resolve to a payload stored on BNB Smart Chain, giving the operation redundancy if one route is disrupted.

Hard To Block But Easier To Trace

Chainalysis says blocking the technique outright isn't realistic. Cutting off blockchain traffic at the network level would also break legitimate wallets and DeFi applications, and attackers could fall back on running their own nodes regardless.

The firm argues the same permanence that makes dead drops attractive to hackers also makes them traceable. Every update an attacker posts is timestamped and visible, letting investigators connect campaigns that might otherwise look unrelated.

Chainalysis said it can't determine from blockchain data alone how many of the traced attacks succeeded or how much was stolen. The broader picture is still worsening: crypto hacks overall rose roughly 150 percent to 207 incidents in the first half of the year, according to separate data from TRM Labs.