Chainalysis Warns Malware Operators Are Turning Blockchains Into Dead Drops
TL;DR
- Chainalysis says cyber attackers are increasingly storing malware instructions on public blockchains.
- It calls the technique “Blockchain Dead Drops.”
- The blockchain itself is not compromised; attackers are using its public, persistent data layer.
Cybercriminals have found a new use for public blockchains, and it has nothing to do with moving money.
Chainalysis says a growing number of threat actors are storing command-and-control information for malware directly on-chain, creating what the analytics firm calls Blockchain Dead Drops, or BDDs.
The idea is clever in an unpleasant sort of way.
Traditional malware often relies on a server or domain to tell infected machines what to do next. Security teams can block the domain, seize the server or disrupt the infrastructure.
A public blockchain is considerably harder to take offline.
Attackers can place configuration data, addresses or pointers inside transactions or smart contract state and then instruct malware to read that information directly from the chain.
The Blockchain Becomes The Noticeboard
Chainalysis describes the wider technique as EtherHiding.
Instead of compromising a blockchain protocol, attackers are effectively using the network as a highly resilient public bulletin board.
Once information is written on-chain, defenders cannot simply delete it.
That makes BDDs attractive for command-and-control infrastructure because attackers can change the data their malware reads without relying on a conventional web server that could be seized.
Chainalysis says activity involving these techniques has climbed sharply, with malicious on-chain writes rising about 440% since mid-2025. The research links different forms of the technique to actors associated with North Korea and Iran, as well as financially motivated Russian-language cybercrime groups.
Those attribution claims come from Chainalysis’ own research and should be read that way.
This Is Not A Blockchain Exploit
That distinction is important.
Nothing about this technique suggests that Bitcoin, Ethereum, BNB Chain, Tron or other networks have had their underlying cryptography broken.
The attacker is using a feature that blockchains are deliberately designed to provide: public, persistent data.
It is the same property that allows anyone to verify transactions years later.
The security problem appears when malware treats that permanent data layer as infrastructure.
That creates a frustrating problem for defenders. The malicious software can still be detected and removed from infected devices, but the data it relies on may remain publicly accessible indefinitely.
For crypto infrastructure operators, wallet providers and security teams, that means monitoring blockchain activity increasingly has to account for more than stolen funds and suspicious transfers.
Sometimes the payload is information itself.
This article was written by the News Desk and edited by Samuel Rae.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Strategy’s STRC plan could bring 365 dividend record dates – Details
Brazil’s New Crypto Rules Could Change the Market: 5 Altcoins Worth Holding as October Nears
With Q3 financial reports approaching, Samsung Electronics and SK Hynix face "extremely high expectations," testing "global AI trading"
The AI wave is driving a global semiconductor "super cycle," with combined third-quarter operating profits of Samsung and SK Hynix potentially approaching the historical record of 190 trillion won. The competition for HBM4 is intensifying, as agent-based AI pushes storage bandwidth demand up tenfold, making memory truly the "lifeblood" of AI data centers. Two upcoming financial reports will determine whether this boom is merely a flash in the pan or a structural transformation that will reshape the foundation of technology infrastructure.
‘Provide future qualification path’ — Strive challenges MSCI proposal to exclude Bitcoin treasuries