North Korea, Iran-Linked Hackers Drive 5.2X Surge in Malware Stored on Public Blockchains, Chainalysis Finds
Key Takeaways
- •Chainalysis recorded a 420% increase over the past year in instances of malware instructions or infrastructure data being written onto public blockchains, a technique known as a blockchain dead drop.
- •Nation-state operators accounted for roughly two of every three dead drops by the second quarter of 2026, a shift from early 2024 when ordinary cybercriminals drove most of the activity.
- •Chainalysis connected previously unattributed transactions across Tron, Aptos, and BNB Smart Chain to UNC5342, a North Korea-tied group, and found links to Iran's Ministry of Intelligence in an operation that encoded command-and-control routing data on Bitcoin.
- •The tactic dates back to at least 2013, when a Necurs botnet variant stored command domains on Namecoin, and spread to Ethereum-style chains in 2023 under the label 'EtherHiding.'
- •Daily dead-drop writes climbed from about 2.06 to 11.1 since July 2025, coinciding with advanced open-source Chinese AI models gaining the capacity to write high-quality code, though Chainalysis could not establish that attackers actually used them.

Blockchain analytics firm Chainalysis on Thursday reported a 420% surge over the past year in the number of instances in which attackers wrote malware instructions or infrastructure data onto public blockchains, attributing most of the increase to hackers with North Korean and Iranian ties.
The findings, published in a Thursday report, have set off alarms at exchanges, wallet providers, and security teams. Malicious code stored on-chain can persist far longer than infrastructure parked on traditional servers or domains, which defenders can eliminate by seizing site. Public blockchains offer no equivalent off-switch: no central administrator can remove a dead drop, so the same persistence that protects legitimate transactions also shields hostile ones.
What is a blockchain dead drop?
According to Chainalysis, the technique—known as a "blockchain dead drop" (BDD)—involves attackers storing payloads and command-and-control (C2) pointers inside on-chain transactions and smart contracts—the self-executing programs that run on chains such as Ethereum—so that infected machines can retrieve them when it is time to act.
The method has gained popularity among hackers because blockchain technology inherently extends how long stored data remains viable. Conventional campaigns die a natural death when a domain is seized, hosting is cut off, or a code repository is removed. Instructions written to a public ledger, by contrast, persist and remain accessible under all of these conditions—and, because the ledger is open, they can be read by security researchers as well as by infected machines.
Chainalysis traces the first recorded use of the tactic to 2013, when a Necurs botnet variant parked its C2 domains on Namecoin, an early blockchain built for decentralized domain naming. In a separate 2019 case, operators of the Glupteba mining botnet hid data in Bitcoin's OP_RETURN field, a small slot that allows arbitrary data to be embedded directly in Bitcoin transactions. The trend spread to Ethereum-style chains in mid-2023 under the "EtherHiding" label, when ClearFake operators migrated their infostealer code to BNB Smart Chain after Cloudflare took down their servers.
As of early 2024, ordinary cybercriminals were responsible for most of the activity. By the second quarter of 2026, however, Chainalysis reported that nation-state operators were writing roughly two out of every three dead drops on public blockchains.
North Korean and Iranian operators are active
Chainalysis completed one investigation by connecting a set of previously unattributed transactions across three networks to UNC5342, a North Korea-tied group on Google Threat Intelligence's radar. That campaign routed infected devices through Tron, with Aptos as a backup, before ending at the same BNB Smart Chain transaction. It mirrored a 2025 instance in which North Korean hackers planted crypto-stealing code inside Ethereum-style smart contracts, consistent with the EtherHiding technique.
Chainalysis also found links to Iran's Ministry of Intelligence while investigating an operation that encoded C2 routing data directly on the Bitcoin blockchain. The Iranian method carried an unusual signature: tiny payments sent from attacker wallets to a Bitcoin address rumored to have ties to Satoshi Nakamoto.
Open-weight AI models have aided the operations
The 440% rise in malicious dead drops since July 2025 has coincided with the most advanced open-source Chinese AI models unlocking the capacity to write A-level code. In raw terms, daily writes climbed from about 2.06 to 11.1.
Eric Jardine, Chainalysis's cybercrimes research lead, said the firm could not confirm that the actors publishing the malicious transactions had actually used the models to boost their output—leaving the timing a correlation rather than an established cause.
The report lands on top of a long run of North Korean crypto activity. CertiK estimated in May that DPRK-linked actors have stolen about $6.75 billion since 2016 across 263 incidents, leaning on social engineering rather than pure software exploits, as Cryptopolitan reported. Separate research presented at this year's Black Hat conference put the reach wider still, with one investigator finding that North Korean operators had infiltrated 1,640 companies across 57 countries.
U.S. intelligence has said funds taken by these operations help pay for the regime's nuclear and missile programs, a charge Pyongyang has denied.
The same openness that makes dead drops durable also made them traceable—Chainalysis built its findings by reading public ledgers—and the question Jardine raised, whether the actors actually used open-weight AI models, remains unresolved.