Blockchain Malware Activity Jumps 440% as AI Lowers Technical Barriers
Hackers are increasingly using public blockchains to store malware instructions, with the activity rising 440% alongside the spread of powerful open-weight AI coding tools. Chainalysis said North Korea- and Iran-linked operators are among the groups expanding their use of the technique.
Hackers Turn Blockchains Into Malware Infrastructure
Chainalysis calls the technique “blockchain dead drops,” or BDDs. Attackers store malware payloads, command-and-control configurations or infrastructure pointers inside blockchain transactions and smart contracts, allowing infected machines to retrieve instructions from public networks.
The method makes malicious infrastructure harder to disrupt because blockchain records can remain accessible after conventional domains or servers are removed. Chainalysis said this can increase the durability of cyber campaigns without necessarily making the malware itself more destructive.
AI Lowers the Barrier to Blockchain Attacks
Identified blockchain dead-drop writes increased from an average of 2.06 per day to 11.1 per day in less than a year, according to Chainalysis. The firm linked the increase to the spread of high-capacity open-weight AI models that can assist with malicious coding tasks.
Building blockchain-based command infrastructure previously required substantial cybersecurity and crypto expertise. Chainalysis said AI tools are making these techniques more accessible to less experienced operators and helping attackers build more complex infrastructure.
Chainalysis co-founder and CEO Jonathan Levin has also warned about AI’s growing role in illicit activity. Levin said:
“Bad actors are already using AI to accelerate fraud, theft, money laundering, and more”.
State-Linked Groups Increase Their Use of BDDs
Cybercriminals produced almost all identified BDD activity through early 2024, but state-linked use has since expanded. By the second quarter of 2026, state-linked groups accounted for roughly two-thirds of newly observed BDD activity in each quarter and about half of all BDD activity identified by Chainalysis.
The firm identified more than 15 campaigns and threat-actor clusters across Bitcoin, BNB Smart Chain, TRON, Aptos and Polygon. Its research included activity linked to North Korea, suspected Iranian operators and Russian-language cybercriminal groups.
One campaign involved UNC5342, a North Korea-linked group previously tracked by Google Threat Intelligence Group. The attackers targeted cryptocurrency developers through fraudulent recruitment and used blockchain transactions to direct infected devices toward malware instructions.
On-Chain Activity Also Gives Investigators Evidence
The permanence that makes blockchains useful to attackers can also preserve evidence for investigators. Transactions, smart-contract deployments and infrastructure changes remain timestamped onchain, helping security teams connect wallets, campaigns and shared infrastructure.
Blocking blockchain access entirely is impractical because legitimate wallets, DeFi applications and other services use the same networks. Chainalysis said monitoring blockchain endpoints and analyzing on-chain infrastructure can instead help defenders detect and track malicious campaigns.