Blockchain malware threats surge 440% as AI helps hackers: Report

News Team
Written by News Team

Blockchain-based command-and-control activity used by cyber attackers increased 420 per cent over the past 12 months, according to Chainalysis’ report. Blockchain dead drops (BDDs), a method that saves malware instructions and control data on public blockchains, are becoming more and more popular among cyber threat actors. Attackers can continue to communicate with hacked devices while making it more difficult for authorities to take down their infrastructure by utilising decentralised networks.

Chainalysis reported that malicious blockchain writes increased from an average of 2.06 per day to 11.1 per day following the emergence of high-capacity open-source AI models, a 440 per cent increase. The research said the activity remains small compared with legitimate blockchain transactions but indicates growing use of public blockchains as persistent infrastructure for cyberattacks.

Understanding blockchain dead drops (BDDs)

Malware instructions, command-and-control (C2) information, or links to malicious infrastructure can be stored on public blockchains using a technique called blockchain dead drops (BDDs). Infected devices retrieve data directly from blockchain networks rather than depending just on attacker-controlled servers, strengthening the communication channel’s resistance to conventional takedown attempts.

Blockchain data typically remain available, enabling attackers to retain a steady reference point even when their infrastructure changes, even when domains, servers, and hosting accounts might be seized or shut down. This makes malicious processes more difficult to stop, but it does not increase the power of malware.

Researchers have also observed a sharp rise in BDD activity. Chainalysis’ research found that BDD attacks increased 420 per cent over the previous 12 months and 440 per cent since the emergence of the high-capacity open-source AI models referenced in its analysis. The company said it is tracking activity across five major blockchains and more than a dozen malware strains. Chainalysis stated that the arrival of capable open-weight AI models in 2025 reduced some of the technical barriers involved in creating BDD infrastructure.

Origins of blockchain-based malware

The use of blockchain technology for malicious communications predates the recent EtherHiding activity. Chainalysis traced early examples back to 2013, when a version of the Necurs botnet reportedly stored command-and-control domains on Namecoin, a Bitcoin-derived network.

In 2019, researchers documented banking malware that used transaction amounts to encode C2 IP addresses. The Glupteba botnet also used Bitcoin’s OP_RETURN field to store malicious data.

In 2023, the EtherHiding technique showed how attackers could store information in smart contracts on networks such as BNB Smart Chain. The ClearFake operation reportedly adopted this method after facing pressure on conventional hosting infrastructure. Under this model, malware retrieved information from blockchain infrastructure while the malicious activity itself continued elsewhere.

State-sponsored blockchain threats

Chainalysis reported that cybercriminals accounted for nearly all identified BDD activity through early 2024. State-linked activity began to rise in mid-2024. By the second quarter of 2026, state-linked groups were responsible for roughly two-thirds of new BDD activity each quarter and about half of all BDD activity, according to the company.

One instance of malware activity aided by blockchain technology is North Korean operators. According to Google Threat Intelligence, the DPRK-affiliated group UNC5342 employed EtherHiding in a campaign that exploited phony employment offers to target bitcoin engineers. According to reports, the campaign started employing the strategy in February 2025.

According to Chainalysis, the 2026 research analysed a DPRK-related tactic that was based on TRON, Aptos, and BNB Smart Chain. The method established redundancy across numerous blockchain systems. Data on two different chains could send a compromised machine to a different chain.

Iranian threats, Russian cybercrime

Additionally, Chainalysis found behaviour connected to the Iranian government that made use of Bitcoin transaction data. The research found that attacker-controlled wallets encoded C2 routing information into transaction data while sending little payments. Rather than relying solely on blockchain activity, the attribution to Iran was based on the broader malware operation, decoding techniques, infrastructure, and time.

Chainalysis also identified Russian-language cybercriminal activity involving smart contracts on Polygon and a Malware-as-a-Service (MaaS) model. Under this model, one operator maintains the infrastructure while other criminals use it for their own campaigns. Instead of building a blockchain-based C2 system from scratch, customers can rely on a specialist provider.

The technical barrier to entrance is reduced by this model. If a provider provides the resolver contracts, administration tools, and accompanying infrastructure, users do not necessarily need to be proficient in blockchain programming. The setup reflects a well-known trend in technology services: specialists create and manage intricate systems that are usable by numerous clients. According to Chainalysis, trends consistent with operator wallets managing groups of resolver contracts and connecting activity across campaigns were discovered throughout its analysis.