Invest1 publisher3 min readPublished
Chainalysis puts state hackers behind two of every three blockchain dead drops
Chainalysis says writes of malware instructions to public blockchains have climbed from about 2.06 a day to 11.1 since July 2025, with groups tied to North Korea and Iran behind most of the increase. Its research lead could not confirm AI models helped.
The Investor · Invest desk

What happened
- Chainalysis reported Thursday that instances of attackers writing malware instructions or infrastructure data to public blockchains rose 420% over the past year, and named North Korea- and Iran-linked groups for most of it.
- Nation-state operators now publish roughly two of every three of these dead drops; in early 2024 ordinary cybercriminals accounted for most of them.
- In a separate operation, the firm found links to Iran's Ministry of Intelligence in code that encoded command-and-control routing data directly on the Bitcoin blockchain.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- constraint Nobody can withdraw a confirmed transaction at a security team's request, so the last remaining control point is the infected endpoint.
- exposure Tron, Aptos, BNB Smart Chain and Bitcoin are carrying live attacker command-and-control, and the exchanges, wallet providers and security teams built on top of them inherit the response.
- decision State-funded operators do not quit when a campaign stops paying, so anyone budgeting for this has to assume a longer infection life and a smaller return on any single takedown request.
- cost The losses these instructions direct sit with the hacked companies: about $25.7m per incident on CertiK's count of 263 since 2016.
Eleven writes a day is a small number. At 11.1 a day the run rate is about 4,050 a year, against roughly 750 at the old rate of 2.06 [11][2]. No chain notices that. The cost lands on defenders who used to end these campaigns by seizing a domain, cutting hosting or getting a repository pulled [3]. A payload or a command-and-control pointer written into a transaction or a smart contract stays fetchable after all three, and Chainalysis calls the technique a blockchain dead drop [3][4].
Migration under takedown pressure was demonstrated three years ago. ClearFake's operators moved their infostealer code to BNB Smart Chain after Cloudflare took their servers down [7]. Chainalysis dates the technique's spread to Ethereum-style chains, under the EtherHiding label, to that mid-2023 episode [7]. Earlier cases were narrower. A Necurs botnet variant parked its C2 domains on Namecoin in 2013, and Glupteba's operators hid data in Bitcoin's OP_RETURN field in 2019 [5][6].
The composition matters more to me than the growth rate. Two-thirds of 11.1 works out to about 7.4 state-linked writes a day, and that is more than three times the entire daily rate at the start of the period [8][11][3].
The report carries two growth figures on two windows. The headline is 420% over the past year; the daily series, 2.06 to 11.1, is an increase of about 439% and matches the 440% the firm dates from July 2025 [1][11][1]. Chainalysis also notes that the same stretch saw the most advanced Chinese open-source models become capable of A-level code [12]. Eric Jardine, the firm's cybercrimes research lead, said Chainalysis could not confirm that the actors publishing the malicious transactions had used the models to boost their output [13].
On the money, CertiK estimated in May that DPRK-linked actors have taken about $6.75bn since 2016 across 263 incidents, and CertiK attributes the haul more to social engineering than to software exploits [14]. Work presented at Black Hat this year put North Korean operators inside 1,640 companies across 57 countries [15]. US intelligence has said the proceeds help pay for the regime's nuclear and missile programs [16]. Pyongyang has denied it [16].
The count is of instances Chainalysis found, and that is the weak joint. A firm that got better at spotting on-chain dead drops over the same twelve months would draw a curve of this shape, and attribution work aimed at state groups would lift the state share as a side effect [1][8]. Google Threat Intelligence already tracks UNC5342, the North Korea-tied group Chainalysis matched to transactions on Tron, Aptos and BNB Smart Chain, so a second party publishing writes per day would test both numbers [9]. Until one does, I would treat the named groups and chains as the firmer part of the report and the 420% as detection-sensitive.
What to watch
- An independent writes-per-day count, from Google Threat Intelligence or another vendor, would test both the 420% and the two-thirds state share.
- Whether Chainalysis publishes how its detection method changed over the measured year, which separates more activity from more finding.
- Whether any exchange or wallet provider named in the alarm discloses new monitoring of OP_RETURN fields and contract calls.