Blockchain Dead Drops Soar 440% Amid Unrestricted AI Models
Hackers have increased their use of blockchains to store malware commands by 440% since Chinese AI open-source models were released without guardrails against malicious code in mid-2025, according to Chainalysis. These 'blockchain dead drops' (BDDs) allow attackers to communicate with compromised machines without fear of losing control over their command-and-control relayer.
The technique has become more widespread as state-linked hackers from North Korea and Iran now account for two-thirds of new blockchain dead drop activity, while Russian-language groups sell the capability as a service. Chainalysis notes that the permanence of blockchains gives threat actors' cyber campaigns longevity and allows them to survive domain seizures, hosting takedowns, and repository removals.
The explosion in BDD use is attributed to the lack of restrictions on Chinese AI models, which erased the skill barrier that once kept dead drops rare. The technique has now spread beyond crypto, with researchers saying it was used in a supply chain attack that hit over 440 npm packages in August 2026.