What happened?
Analytics firm Chainalysis reported a sharp rise in malware activity that abuses public blockchains as part of its infrastructure. According to the firm, the volume of this activity grew by 440%. According to CryptoSlate, which relays the data, public blockchains are increasingly being used to keep malware connected to control infrastructure that classic takedowns cannot easily shut off.
The key figure: groups linked to North Korea and Iran accounted for roughly two thirds of newly observed cases of this technique each quarter through the second quarter of 2026. State-backed operators today represent, according to Chainalysis, about half of all activity the firm tracks, up from a negligible share at the start of 2024.
What is a "blockchain dead drop"?
A blockchain dead drop is a technique in which attackers store malware instructions, command-and-control (C2, meaning control servers) addresses, or pointers to further infrastructure directly in blockchain transactions. As described by CryptoSlate, this hides data in a place that is public and permanent, yet at the same time hard to censor or remove.
Why this is advantageous for attackers:
- The blockchain is decentralized, so there is no single server that authorities could seize or shut down.
- Records are permanent, so instructions remain available even after a classic strike against the infrastructure.
- The traffic looks like ordinary blockchain transactions, which complicates detection.
What role does AI play?
According to the framing relayed by CryptoSlate, artificial intelligence is lowering the bar for carrying out these operations, meaning it makes it easier for less advanced actors to deploy more sophisticated methods. The available source does not go into detail on the exact technical mechanics of how AI specifically lowers that bar (for example through code generation, automation, or modifying malware). We therefore present this part as probable, not fully documented in detail.
How much do we know for certain?
From the available source, the documented figures are the growth (440%), the share of groups linked to North Korea and Iran (roughly two thirds of newly observed activity in Q2 2026), and the rise in the share of state actors from practically zero at the start of 2024 to roughly half. All of this data comes from Chainalysis.
What, on the other hand, does not clearly follow from the single available source: absolute volumes (how many cases this is in numbers), specific names of campaigns or victims, the impact on ordinary crypto users, and the exact methodology by which Chainalysis measures the activity and attributes it to states.
How does this fit into the broader trend in on-chain security?
The abuse of the blockchain as attack infrastructure comes at a time when commercial interest in on-chain security in general is growing. According to Incrypted, S&P Global has agreed to acquire OpenZeppelin, one of the leaders in the field of on-chain finance security. According to the same source, the firm's smart contracts secure transfers worth USD 37 trillion and the firm has uncovered more than 10,000 vulnerabilities. This shows that security is becoming a subject of interest for large financial institutions, even though it is a different segment (auditing smart contracts) than the malware described here.
What to watch out for with this type of news?
Cybersecurity figures typically come from a single analytics firm and reflect what that firm is able to track and attribute. Attribution to specific states is always a matter of probability, not judicial proof. The next time you come across a report about "growth of hundreds of percent," it is worth looking for: what base it is calculated from, over what period, who is measuring it, and whether there is independent confirmation. On the topic of blockchain dead drops, we so far have one main data source.

