Chainalysis Warns Malware Operators Are Turning Blockchains Into Dead Drops
TL;DR
- Chainalysis says cyber attackers are increasingly storing malware instructions on public blockchains.
- It calls the technique “Blockchain Dead Drops.”
- The blockchain itself is not compromised; attackers are using its public, persistent data layer.
Cybercriminals have found a new use for public blockchains, and it has nothing to do with moving money.
Chainalysis says a growing number of threat actors are storing command-and-control information for malware directly on-chain, creating what the analytics firm calls Blockchain Dead Drops, or BDDs.
The idea is clever in an unpleasant sort of way.
Traditional malware often relies on a server or domain to tell infected machines what to do next. Security teams can block the domain, seize the server or disrupt the infrastructure.
A public blockchain is considerably harder to take offline.
Attackers can place configuration data, addresses or pointers inside transactions or smart contract state and then instruct malware to read that information directly from the chain.
The Blockchain Becomes The Noticeboard
Chainalysis describes the wider technique as EtherHiding.
Instead of compromising a blockchain protocol, attackers are effectively using the network as a highly resilient public bulletin board.
Once information is written on-chain, defenders cannot simply delete it.
That makes BDDs attractive for command-and-control infrastructure because attackers can change the data their malware reads without relying on a conventional web server that could be seized.
Chainalysis says activity involving these techniques has climbed sharply, with malicious on-chain writes rising about 440% since mid-2025. The research links different forms of the technique to actors associated with North Korea and Iran, as well as financially motivated Russian-language cybercrime groups.
Those attribution claims come from Chainalysis’ own research and should be read that way.
This Is Not A Blockchain Exploit
That distinction is important.
Nothing about this technique suggests that Bitcoin, Ethereum, BNB Chain, Tron or other networks have had their underlying cryptography broken.
The attacker is using a feature that blockchains are deliberately designed to provide: public, persistent data.
It is the same property that allows anyone to verify transactions years later.
The security problem appears when malware treats that permanent data layer as infrastructure.
That creates a frustrating problem for defenders. The malicious software can still be detected and removed from infected devices, but the data it relies on may remain publicly accessible indefinitely.
For crypto infrastructure operators, wallet providers and security teams, that means monitoring blockchain activity increasingly has to account for more than stolen funds and suspicious transfers.
Sometimes the payload is information itself.
This article was written by the News Desk and edited by Samuel Rae.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
AI memory demand continues to surge: Micron (MU.US) surpasses expectations in Q4, with quarterly data center core business revenue increasing by over 10 times year-over-year
Storage chip giant Micron Technology released its financial results for the fourth quarter of fiscal year 2026 after the market closed on Wednesday. Both revenue and profit exceeded Wall Street expectations, and the company provided stronger-than-expected guidance for the next quarter.
Federal Reserve approves stress test reform by a 6-1 vote: Capital requirement volatility halved, sole dissenting vote warns of reduced resilience
The Federal Reserve has officially approved two final rules aimed at increasing transparency and reducing capital requirement volatility by approximately 50%. The new regulations will seek public comments on stress test scenarios and will calculate the capital buffer based on the average of the results from two consecutive years of testing. This averaging mechanism will take effect in 2028. The reforms are the result of years of negotiation within the banking sector and have been welcomed by industry groups. However, critics such as Governor Barr warn that the reforms will weaken the constraints of stress testing and reduce the overall resilience of the banking system.

Metals fade as long yields offset cooler inflation, lower Fed odds - Kitco PM Report
Bitwise brings NEAR to Wall Street – But the chart isn’t impressed
