State-Backed Hackers Turn to Blockchains to Evade Takedowns
State-backed hackers have increasingly turned to public blockchains as a way to keep malware connected to infrastructure that traditional takedowns can't easily disable. According to Chainalysis, groups tied to North Korea and Iran accounted for roughly two-thirds of newly observed blockchain-dead-drop activity each quarter by the second quarter of 2026.
The technique, known as a blockchain dead drop, stores malware instructions, command-and-control addresses or pointers inside transactions and smart contracts. This allows compromised devices to repeatedly query those public records for updated instructions, letting attackers change servers without reinfecting victims.
Chainalysis said malicious blockchain writes rose from 2.06 per day to 11.1 after the emergence of high-capacity open-weight Chinese artificial-intelligence models, a 440% increase in less than a year.