Chainalysis Warns Malware Operators Are Turning Blockchains Into Dead Drops
TL;DR
- Chainalysis says cyber attackers are increasingly storing malware instructions on public blockchains.
- It calls the technique “Blockchain Dead Drops.”
- The blockchain itself is not compromised; attackers are using its public, persistent data layer.
Cybercriminals have found a new use for public blockchains, and it has nothing to do with moving money.
Chainalysis says a growing number of threat actors are storing command-and-control information for malware directly on-chain, creating what the analytics firm calls Blockchain Dead Drops, or BDDs.
The idea is clever in an unpleasant sort of way.
Traditional malware often relies on a server or domain to tell infected machines what to do next. Security teams can block the domain, seize the server or disrupt the infrastructure.
A public blockchain is considerably harder to take offline.
Attackers can place configuration data, addresses or pointers inside transactions or smart contract state and then instruct malware to read that information directly from the chain.
The Blockchain Becomes The Noticeboard
Chainalysis describes the wider technique as EtherHiding.
Instead of compromising a blockchain protocol, attackers are effectively using the network as a highly resilient public bulletin board.
Once information is written on-chain, defenders cannot simply delete it.
That makes BDDs attractive for command-and-control infrastructure because attackers can change the data their malware reads without relying on a conventional web server that could be seized.
Chainalysis says activity involving these techniques has climbed sharply, with malicious on-chain writes rising about 440% since mid-2025. The research links different forms of the technique to actors associated with North Korea and Iran, as well as financially motivated Russian-language cybercrime groups.
Those attribution claims come from Chainalysis’ own research and should be read that way.
This Is Not A Blockchain Exploit
That distinction is important.
Nothing about this technique suggests that Bitcoin, Ethereum, BNB Chain, Tron or other networks have had their underlying cryptography broken.
The attacker is using a feature that blockchains are deliberately designed to provide: public, persistent data.
It is the same property that allows anyone to verify transactions years later.
The security problem appears when malware treats that permanent data layer as infrastructure.
That creates a frustrating problem for defenders. The malicious software can still be detected and removed from infected devices, but the data it relies on may remain publicly accessible indefinitely.
For crypto infrastructure operators, wallet providers and security teams, that means monitoring blockchain activity increasingly has to account for more than stolen funds and suspicious transfers.
Sometimes the payload is information itself.
This article was written by the News Desk and edited by Samuel Rae.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Polygon CEO to burn 100 million POL tokens, price tests key support
Ondo gains access to DTCC Fund/SERV as ONDO eyes breakout from bull flag
Crypto Michael Explains Why He’s Still Long on XRP Since Last Month
Crypto Landscape is Dynamic, Says Route2FI as Trends Emerge
