Chainalysis Warns Malware Operators Are Turning Blockchains Into Dead Drops

TL;DR
- Chainalysis says cyber attackers are increasingly storing malware instructions on public blockchains.
- It calls the technique “Blockchain Dead Drops.”
- The blockchain itself is not compromised; attackers are using its public, persistent data layer.
Cybercriminals have found a new use for public blockchains, and it has nothing to do with moving money.
Chainalysis says a growing number of threat actors are storing command-and-control information for malware directly , creating what the analytics firm calls Blockchain Dead Drops, or BDDs.
The idea is clever in an unpleasant sort of way.
Traditional malware often relies on a server or domain to tell infected machines what to do next. Security teams can block the domain, seize the server or disrupt the infrastructure.
A public blockchain is considerably harder to take offline.
Attackers can place configuration data, addresses or pointers inside transactions or state and then instruct malware to read that information directly from the chain.
The Blockchain Becomes The Noticeboard
Chainalysis describes the wider technique as EtherHiding.
Instead of compromising a blockchain protocol, attackers are effectively using the network as a highly resilient public bulletin board.
Once information is written on-chain, defenders cannot simply delete it.
That makes BDDs attractive for command-and-control infrastructure because attackers can change the data their malware reads without relying on a conventional web server that could be seized.
Chainalysis says activity involving these techniques has climbed sharply, with malicious on-chain writes rising about 440% since mid-2025. The research links different forms of the technique to actors associated with North Korea and Iran, as well as financially motivated Russian-language cybercrime groups.
Those attribution claims come from Chainalysis’ own research and should be read that way.
This Is Not A Blockchain Exploit
That distinction is important.
Nothing about this technique suggests that , , BNB Chain, Tron or other networks have had their underlying cryptography broken.
The attacker is using a feature that blockchains are deliberately designed to provide: public, persistent data.
It is the same property that allows anyone to verify transactions years later.
The security problem appears when malware treats that permanent data layer as infrastructure.
That creates a frustrating problem for defenders. The malicious software can still be detected and removed from infected devices, but the data it relies on may remain publicly accessible indefinitely.
For crypto infrastructure operators, providers and security teams, that means monitoring blockchain activity increasingly has to account for more than stolen funds and suspicious transfers.
Sometimes the payload is information itself.
Source: Chainalysis research —
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released by Chainalysis. at










