CRYPTOCURRENCY NEWS

Chainalysis: State Hackers Write Half of Blockchain Malware

State-sponsored hackers have moved from the fringes to the center of a fast-growing threat that uses public blockchains as covert infrastructure.

Share:

What Chainalysis Found: A Tactic Going Mainstream Among State Actors

Chainalysis defines a Blockchain Dead Drop (BDD) as the practice of writing malicious data, such as encrypted malware instructions or pointers to command-and-control servers, into public blockchain transactions or smart contracts. Because on-chain data cannot be deleted, defenders cannot simply take down the infrastructure the way they can pull a rogue domain or server. For related coverage, see Crypto Stocks Fell After Clarity Act Failure: Is Bitcoin Next?.

The volume of this activity has surged. Chainalysis reports that malicious BDD writes rose from 2.06 per day to 11.1 per day in less than a year, a 440% increase that the firm ties to the proliferation of high-capacity open-weight AI coding models.

Blockchain Dead Drops
440%
Increase in malicious blockchain writes, from 2.06 to 11.1 per day, according to Chainalysis.

By Q2 2026, state-actor-linked groups represented roughly two-thirds of new BDD activity each quarter and half of total BDD activity overall, according to Chainalysis. That shift marks a significant evolution: when the technique first surfaced at scale in 2023, it was primarily a criminal tool. For related coverage, see Crypto.com Can List US Single-Stock Futures Without SEC Approval.

Q2 2026
50%
Share of total Blockchain Dead Drop activity linked to state actors, according to Chainalysis.

From Criminal Tool to Nation-State Weapon: The EtherHiding Lineage

The technique has a traceable origin. Guardio Labs documented EtherHiding in October 2023, reporting that the ClearFake campaign pivoted to BNB Smart Chain contracts after Cloudflare blocked the servers used in an earlier variant. The appeal was straightforward: blockchain writes are cheap, permanent, and distributed across thousands of nodes, making them far harder to neutralize than conventional hosting.

Nation-state actors took notice. Chainalysis describes a DPRK-linked campaign that uses encoded pointers on TRON and Aptos leading to a BNB Smart Chain transaction carrying encrypted malware instructions. Google Threat Intelligence Group independently observed the group tracked as UNC5342 deploying EtherHiding from February 2025 in a social-engineering campaign targeting cryptocurrency developers, which GTIG characterized as the first nation-state adoption of the technique it had observed. The Chainalysis research further notes that active campaigns have spanned BNB Smart Chain, Bitcoin, TRON, Aptos, and Polygon.

One detail that underscores the economics of blockchain-based command-and-control: the UNC5342 BNB Smart Chain contract was updated more than 20 times in its first four months at an average cost of roughly $1.37 per update. Defenders who detect the pointer address cannot prevent the operator from cheaply re-pointing it to new infrastructure.

What This Means for Crypto Security Teams and Users

The durability of on-chain infrastructure is the core challenge. Traditional takedown requests, domain seizures, and hosting provider notices have no equivalent on a public blockchain. Google Threat Intelligence Group noted that some API service providers acted promptly after being notified about UNC5342 activity, while several others remained unresponsive, highlighting that disruption depends on voluntary cooperation from the surrounding off-chain infrastructure rather than the chain itself.

For exchanges, wallet providers, and developers, the Chainalysis findings reinforce the case for monitoring unusual smart-contract interaction patterns, not just wallet balances and transfer volumes. The same blockchain analytics capabilities Chainalysis has applied to financial crime are increasingly being directed at mapping the command-and-control layer of nation-state malware campaigns.

For individual users and developers, the immediate implication is about software supply chains. BDD campaigns documented so far have targeted developers through social engineering, making source verification and cautious handling of unexpected downloads or repository invitations the most direct mitigation. The regulatory environment around crypto infrastructure is still forming, and the Chainalysis research adds a national-security dimension to a debate that has so far focused primarily on financial oversight.

Why Attribution and Continuous Monitoring Matter

The 440% surge in BDD activity correlates with the availability of AI coding tools, which Chainalysis connects to lowering the technical barrier for writing malware that can interact with smart contracts. As state actors account for a growing share of this activity, the distinction between cybercrime and state-sponsored espionage in the crypto space is narrowing. The expansion of blockchain infrastructure into mainstream financial systems makes the underlying resilience of that infrastructure to misuse an increasingly urgent question.

Bitcoin trades at $76,547 with the broader Fear & Greed Index at 56 (Greed). The market backdrop is stable, but the Chainalysis report is a reminder that the most consequential developments in crypto security are happening at the infrastructure layer, not the price chart.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Stay ahead of the market

Get daily crypto insights delivered to your inbox.

Related Articles

View all →