Chainalysis Flags 440% Surge in On-Chain Malware Dead Drops
Chainalysis says attackers are using public blockchains as bulletproof command-and-control servers, with malicious on-chain writes up 440% since mid-2025. The networks aren't broken. The problem is that permanence cuts both ways.
A new Chainalysis report says cybercriminals have found a new use for public blockchains, and it has nothing to do with moving money. The analytics firm calls the technique Blockchain Dead Drops. Attackers are storing malware instructions, configuration data, and pointers inside transactions and smart contract state. Then the malware reads that data directly from the chain.
The numbers are striking. Chainalysis says malicious on-chain writes have climbed about 440% since mid-2025. The research links different forms of the technique to actors associated with North Korea and Iran, as well as financially motivated Russian-language cybercrime groups. Those attribution claims come from Chainalysis itself, so treat them with the usual caution.
Here's the key detail: this isn't a blockchain exploit. Bitcoin, Ethereum, BNB Chain, and Tron haven't had their cryptography broken. Attackers are using a feature that blockchains are designed to provide, which is public, persistent data. The problem is that permanence cuts both ways. Once information is written on-chain, defenders can't simply delete it.
Traditional malware relies on a server or domain for command-and-control. Security teams can block the domain or seize the server. A public blockchain is much harder to take offline. So attackers can change the data their malware reads without relying on a conventional web server. Chainalysis describes the wider technique as EtherHiding.
From a compliance standpoint, this changes the monitoring calculus for wallet providers, exchanges, and crypto infrastructure operators. On-chain surveillance can no longer focus only on stolen funds and suspicious transfers. Sometimes the payload is information itself. That means blockchain analytics firms are now competing in threat intelligence, not just financial crime.
My take? This is a feature, not a bug, and the industry needs to admit that. The same immutability that makes crypto trustworthy makes it a perfect dead drop. The attackers didn't break the chain. They just read the fine print. Watch for regulators to start asking whether node operators and analytics firms should be doing more to flag malicious on-chain writes. That's a hard question with no easy answer.
Explore More
Key Terms Explained
The first cryptocurrency, created in 2009 by the pseudonymous Satoshi Nakamoto.
A bundle of transactions that gets permanently added to the blockchain.
A distributed database where transactions are grouped into blocks and linked together cryptographically.
Following the laws and regulations that apply to financial activities, including crypto.