Skip to content

Invest1 publisher3 min readPublished

Chainalysis puts state hackers behind two of every three blockchain dead drops

Chainalysis says writes of malware instructions to public blockchains have climbed from about 2.06 a day to 11.1 since July 2025, with groups tied to North Korea and Iran behind most of the increase. Its research lead could not confirm AI models helped.

The Investor · Invest desk

Illustration accompanying Chainalysis puts state hackers behind two of every three blockchain dead drops

What happened

  • Chainalysis reported Thursday that instances of attackers writing malware instructions or infrastructure data to public blockchains rose 420% over the past year, and named North Korea- and Iran-linked groups for most of it.
  • Nation-state operators now publish roughly two of every three of these dead drops; in early 2024 ordinary cybercriminals accounted for most of them.
  • In a separate operation, the firm found links to Iran's Ministry of Intelligence in code that encoded command-and-control routing data directly on the Bitcoin blockchain.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Nobody can withdraw a confirmed transaction at a security team's request, so the last remaining control point is the infected endpoint.
  • exposure Tron, Aptos, BNB Smart Chain and Bitcoin are carrying live attacker command-and-control, and the exchanges, wallet providers and security teams built on top of them inherit the response.
  • decision State-funded operators do not quit when a campaign stops paying, so anyone budgeting for this has to assume a longer infection life and a smaller return on any single takedown request.
  • cost The losses these instructions direct sit with the hacked companies: about $25.7m per incident on CertiK's count of 263 since 2016.

Eleven writes a day is a small number. At 11.1 a day the run rate is about 4,050 a year, against roughly 750 at the old rate of 2.06 [11][2]. No chain notices that. The cost lands on defenders who used to end these campaigns by seizing a domain, cutting hosting or getting a repository pulled [3]. A payload or a command-and-control pointer written into a transaction or a smart contract stays fetchable after all three, and Chainalysis calls the technique a blockchain dead drop [3][4].

Migration under takedown pressure was demonstrated three years ago. ClearFake's operators moved their infostealer code to BNB Smart Chain after Cloudflare took their servers down [7]. Chainalysis dates the technique's spread to Ethereum-style chains, under the EtherHiding label, to that mid-2023 episode [7]. Earlier cases were narrower. A Necurs botnet variant parked its C2 domains on Namecoin in 2013, and Glupteba's operators hid data in Bitcoin's OP_RETURN field in 2019 [5][6].

The composition matters more to me than the growth rate. Two-thirds of 11.1 works out to about 7.4 state-linked writes a day, and that is more than three times the entire daily rate at the start of the period [8][11][3].

The report carries two growth figures on two windows. The headline is 420% over the past year; the daily series, 2.06 to 11.1, is an increase of about 439% and matches the 440% the firm dates from July 2025 [1][11][1]. Chainalysis also notes that the same stretch saw the most advanced Chinese open-source models become capable of A-level code [12]. Eric Jardine, the firm's cybercrimes research lead, said Chainalysis could not confirm that the actors publishing the malicious transactions had used the models to boost their output [13].

On the money, CertiK estimated in May that DPRK-linked actors have taken about $6.75bn since 2016 across 263 incidents, and CertiK attributes the haul more to social engineering than to software exploits [14]. Work presented at Black Hat this year put North Korean operators inside 1,640 companies across 57 countries [15]. US intelligence has said the proceeds help pay for the regime's nuclear and missile programs [16]. Pyongyang has denied it [16].

The count is of instances Chainalysis found, and that is the weak joint. A firm that got better at spotting on-chain dead drops over the same twelve months would draw a curve of this shape, and attribution work aimed at state groups would lift the state share as a side effect [1][8]. Google Threat Intelligence already tracks UNC5342, the North Korea-tied group Chainalysis matched to transactions on Tron, Aptos and BNB Smart Chain, so a second party publishing writes per day would test both numbers [9]. Until one does, I would treat the named groups and chains as the firmer part of the report and the 420% as detection-sensitive.

What to watch

  • An independent writes-per-day count, from Google Threat Intelligence or another vendor, would test both the 420% and the two-thirds state share.
  • Whether Chainalysis publishes how its detection method changed over the measured year, which separates more activity from more finding.
  • Whether any exchange or wallet provider named in the alarm discloses new monitoring of OP_RETURN fields and contract calls.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories