Malware Spreads Across Blockchains as Nation States Adopt Dead Drop Technique
A new type of malware is spreading rapidly across multiple blockchains, exploiting their permanent and immutable nature. Chainalysis, a blockchain analytics firm, has documented a surge in malicious writes to public blockchains, increasing by 440% in less than a year.
The technique, called a blockchain dead drop, involves writing encoded payloads or pointers into transaction data, smart contracts, or other on-chain fields. Infected machines can then read the blockchain, decode the instructions, and execute the real attack, which can include stealing credentials, gaining remote access, extracting data, or draining cryptocurrency wallets.
The use of powerful open-weight AI models released in mid-2025 has made it easier for attackers to deploy this technique. These models generated malicious code without restrictions, dramatically lowering the technical expertise needed to build and deploy blockchain dead drops.
Nation states are also using this tactic, with North Korean attackers affiliated with UNC5342 group and Iran-linked operators tied to Iran's Ministry of Intelligence deploying blockchain dead drop techniques against developers and cryptocurrency workers.