Blockchain Dead Drops Skyrocket as State Hackers Expand Malicious Activity
Chainalysis has reported a significant increase in blockchain dead drop attacks, which use public chains to hide malware instructions. The number of such attacks rose by 420% over the past 12 months, with state-linked groups accounting for roughly two-thirds of new activity in the second quarter of 2026.
The technique, known as a blockchain dead drop or BDD, involves placing malware payloads or pointers to command-and-control infrastructure in transaction data or smart contracts. Infected devices read the entry and then connect to the attackers' off-chain systems, where credential theft, remote access, or data exfiltration occurs.
Chainalysis identified a North Korea-linked campaign that used Tron, Aptos, and BNB Smart Chain as redundant command paths. The malware checks Tron first and uses Aptos as a fallback; the BNB Smart Chain transaction contains encrypted configuration data and command-and-control server addresses.
The setup allows operators to rotate their off-chain servers by publishing a new transaction while leaving infected devices programmed to retrieve the latest instructions. Disrupting this campaign would require coordinated action across all three chains, making it more challenging for defenders to take down the operation.