Blockchain Dead Drops Soar by 440% as State-Linked Actors Expand Use
Blockchain dead drops have surged by 440% in less than a year, according to Chainalysis. This phenomenon involves attackers storing command-and-control data and infrastructure information in transactions and smart contracts on public blockchains.
The use of blockchain dead drops is becoming increasingly sophisticated and widespread, with state-linked groups such as North Korea- and Iran-linked operators playing a significant role. Chainalysis identified over 15 campaigns and threat-actor clusters using this tactic.
Chainalysis highlighted the growing importance of open-source AI coding models in enabling the development of blockchain-based command-and-control infrastructure. While the firm did not establish a direct causal link, it noted that the emergence of these tools coincides with the significant increase in malicious blockchain writes from 2.06 to 11.1 per day.
The use of public blockchains creates challenges for defenders, as the same networks support both legitimate and malicious activities. However, the publicly available transaction history can aid investigators in identifying connections between infrastructure that might otherwise appear unrelated.