Blockchain Dead Drop Attacks Jump 420% as State-Linked Groups Expand

Blockchain Dead Drop Attacks Jump 420% as State-Linked Groups Expand

Attacks surge as state-linked groups adopt the technique

Blockchain dead drop attacks, where hackers hide instructions on public blockchains, increased 420% over the past year, according to blockchain analytics firm Chainalysis. The company said state-linked groups now account for about two-thirds of new activity in the second quarter of 2026.

Chainalysis also measured a related spike: malicious blockchain writes rose from 2.06 per day before mid-2025 to 11.1 per day, a 440% increase in less than a year.

What the Chainalysis report says

Chainalysis describes a blockchain dead drop (BDD) as a method where attackers place malware payloads or pointers to their command-and-control servers inside transaction data or smart contracts. Infected devices read this information and then connect to offchain systems for credential theft, remote access, or data exfiltration.

In one North Korea-linked campaign, operators placed encoded pointers on Tron and Aptos that both led infected devices to the same transaction on BNB Smart Chain. The malware checks Tron first and uses Aptos as a backup; the BNB Smart Chain transaction holds encrypted configuration data and server addresses. This lets attackers change their offchain servers by publishing a new transaction, while infected devices keep retrieving the latest instructions. Chainalysis says disrupting that campaign would require coordinated action across all three chains.

Independent reporting from Google

Google Threat Intelligence Group independently documented a North Korea-linked group, UNC5342, using a similar technique since February 2025. Google said the group embedded malicious code in public-chain smart contracts during fake-job-interview campaigns targeting cryptocurrency developers.

Chainalysis also attributed a transaction-based technique to operators it suspects are linked to Iran's Ministry of Intelligence. Those actors sent small Bitcoin payments while encoding command-and-control routing data in the transactions for malware to retrieve. The firm said the assessment rests on the malware family, decoding logic, timing, and infrastructure, not the blockchain activity alone.

Russian-language criminal groups used Polygon smart contracts to store and update infrastructure locations for malware-as-a-service customers, according to the report. Chainalysis said these actors were not necessarily state-sponsored and classified them as Russian-language based on linguistic analysis and external reporting.

What is confirmed

Chainalysis reports:

  • Blockchain dead drop attacks increased 420% year-over-year.
  • State-linked groups accounted for roughly two-thirds of new activity in Q2 2026 and half of all tracked activity.
  • Malicious blockchain writes increased from 2.06 to 11.1 per day, a 440% rise.
  • Cybercriminals accounted for nearly all such activity until early 2024.

Google Threat Intelligence Group confirmed UNC5342 used a related technique since February 2025 in fake-job-interview campaigns.

What is still unclear

The Iran attribution is based on malware and infrastructure indicators, not confirmed by the blockchain activity alone. Chainalysis classified Russian-language groups based on linguistic analysis and external reporting, but said they were not necessarily state-sponsored.

Why it matters

The blockchain records do not make malware more destructive, but they remove the central server that defenders would normally seize or take offline. As long as the underlying chain remains operational, the stored code or pointer remains available. Chainalysis said disrupting campaigns would require coordinated action across multiple chains.

What happens next

Google said centralized API providers used by UNC5342 were quick to act when its researchers contacted them, although several other platforms remained unresponsive. This suggests some access routes can be pressured, but full takedown remains difficult.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!