Crypto news report · source clearly identified
Blockchain Dead Drop Attacks Surge 420% as State-Linked Groups Expand Use of Multiple Chains
Chainalysis reports a 420% year‑over‑year rise in blockchain dead‑drop attacks, with state‑linked actors now responsible for about two‑thirds of new activity in Q2 2026.

Blockchain dead‑drop attacks—campaigns that embed malware instructions in public blockchain data—have risen sharply, according to Chainalysis. Over the past 12 months the number of attacks grew 420%, and state‑linked groups now account for roughly two‑thirds of new activity in the second quarter of 2026.
How the attacks work
Attackers place either full malware payloads or pointers to off‑chain command‑and‑control (C2) servers in transaction data or smart contracts. Compromised devices read these entries, then connect to the attackers’ infrastructure for credential theft, remote access, or data exfiltration.
Redundant chain usage raises takedown costs
A North Korea‑linked campaign used encoded pointers on Tron and Aptos that both directed infected devices to a single transaction on BNB Smart Chain. The BNB Smart Chain transaction held encrypted configuration data and C2 server addresses. This redundancy lets operators rotate off‑chain servers by publishing a new transaction while infected devices continue to fetch the latest instructions, complicating disruption efforts.
Other state‑linked techniques
- Suspected Iranian actors sent small Bitcoin payments that encoded routing data for malware to retrieve, based on malware family characteristics and timing.
- Russian‑language criminal groups stored infrastructure locations in Polygon smart contracts for malware‑as‑a‑service customers, though they were not classified as state‑sponsored.
Impact and response
The use of public chains does not make the malware itself more destructive, but it removes a central server that defenders could seize. As long as the underlying blockchain remains operational, the malicious code or pointers stay accessible. Some centralized API providers responded quickly when contacted by researchers, while other platforms remained unresponsive.
Trends over time
Malicious blockchain writes increased from 2.06 per day before mid‑2025 to 11.1 per day—a 440% rise in less than a year. Early 2024 saw cybercriminals dominate dead‑drop activity; by Q2 2026, state‑linked groups generated roughly two‑thirds of new activity each quarter and represented half of all activity tracked by Chainalysis.
Source & attribution
News Source
- Publisher
- The Defiant
- Original date
- September 18, 2026, 4:59 PM
- Original headline
- Blockchain Dead Drop Attacks Jump 420% as State Hackers Expand