Chainalysis says malware operators are increasingly storing command-and-control data directly on public blockchains, a technique it calls "Blockchain Dead Drops." The firm reports malicious on-chain writes have climbed sharply since mid-2025, tying different variants of the method to North Korea, Iran and Russian-language cybercrime groups. The blockchains themselves are not compromised — attackers are exploiting the fact that on-chain data is public and hard to remove.
Chainalysis says malicious on-chain writes have climbed about 440% since mid-2025, as malware operators shift their command-and-control instructions onto public blockchains instead of servers.
The Chain as a Dead Drop
The analytics firm calls the technique Blockchain Dead Drops, or BDDs. Attackers place configuration data, addresses or pointers inside transactions or smart contract state, then point malware to read that information straight from the chain. Chainalysis describes the broader approach as EtherHiding.
Traditional malware typically depends on a server or domain to relay instructions to infected machines. Security teams can block that domain or seize the server. A public blockchain, however, is far harder to take offline, and once data is written to it, defenders cannot simply delete it.
Attribution Comes With a Caveat
Chainalysis links different forms of the technique to actors associated with North Korea and Iran, along with financially motivated Russian-language cybercrime groups. Those attribution claims come from Chainalysis' own research, so they should be read as the firm's assessment rather than independently confirmed fact.
Not a Break in the Blockchain Itself
This is not a case of broken cryptography. Nothing about the technique suggests Bitcoin, Ethereum, BNB Chain, Tron or other networks have had their underlying security compromised. Attackers are instead using a feature blockchains are built to provide: public, persistent on-chain data, the same property that lets anyone verify a transaction years later.
That distinction still leaves defenders with a hard problem. Malware itself can be found and removed from infected devices, but the data it depends on can stay publicly accessible indefinitely. As a result, monitoring blockchain activity increasingly has to account for more than stolen funds and suspicious transfers — sometimes the payload is information itself.
Source: Chainalysis (via NewsBTC)
Trading involves risk.