Hackers are increasingly hiding malware instructions in public blockchains, creating communication channels that can survive the removal of conventional servers. Chainalysis said malicious blockchain activity rose 440%, with daily entries increasing from 2.06 to 11.1 after newer AI systems emerged.
Blockchain dead drops use transaction data or smart contracts as lookup points for commands, addresses, or configuration information. Distributed records remain on the ledger even if a conventional server is removed. A North Korean-linked operation associated with UNC5342 has used TRON and Aptos before retrieving encrypted instructions through BNB Chain. Iranian actors suspected of links to the country's intelligence ministry have embedded routing information in Bitcoin transactions, while Russian-speaking criminals have used Polygon contracts for customer-operated malware campaigns. One operator controls more than 50 BNB Chain resolver contracts.
Chainalysis said high-capacity Chinese open models reduced the expertise needed to build this infrastructure by helping operators work with unfamiliar technologies. In the second quarter of 2026, state-linked groups accounted for roughly two-thirds of newly observed activity and about half of overall activity.
Defenders face a difficult balance because blocking blockchain traffic could also affect legitimate wallets, decentralized applications, exchanges, and decentralized finance services. Attackers may also run their own nodes. Chainalysis Korea General Manager Kwon Jun-hyeok said on-chain records can provide clues for tracking attackers and related infrastructure.
Comments
0No comments yet. Be the first to comment.