The use of public blockchains to host malware instructions has risen sharply following the emergence of unrestricted open-source artificial intelligence models, according to a recent report from blockchain analytics firm Chainalysis.
Chainalysis found that malicious instructions written to blockchains increased by about 440% in less than a year, with the number of daily harmful on-chain writes rising from 2.06 to 11.1. The activity reflects a growing use of blockchains as infrastructure for communicating with compromised devices rather than solely as systems for transferring digital assets.
The firm refers to the technique as blockchain dead drops, or BDDs. Under this approach, attackers place malware payloads, instructions or command information inside blockchain transactions or smart contracts. Infected devices can then retrieve the information when required.
The primary advantage for attackers is the persistence of public blockchains, which can allow malicious command infrastructure to remain accessible even after domains, servers, and online repositories are taken down.
North Korea and Iran linked to much of the activity
Chainalysis said state-linked operators associated with North Korea and Iran account for much of the recent blockchain-based malware activity. The development marks an expansion of blockchain technology into a role that can support cyber operations by providing a resilient location for command-and-control information.
Traditional malware campaigns often depend on centralized servers to distribute instructions to infected computers. Those servers can be identified, seized, blocked or taken offline by security teams and authorities. Public blockchains create a different challenge because information recorded on-chain can remain available for extended periods and is distributed across networks rather than being dependent on a single hosting provider.
The technique itself is not new. Chainalysis traced the concept back to 2013, when a variant of the Necurs botnet used Namecoin, a Bitcoin-derived blockchain, to store domain information. The method later expanded to Ethereum Virtual Machine-compatible networks.
In 2023, the technique became more visible through a method known as EtherHiding, which uses blockchain infrastructure to conceal malicious content. Security researchers subsequently linked the approach to North Korean activity, including campaigns involving fake job interviews.
AI lowers the technical barrier
Chainalysis identified mid-2025 as a major turning point in the growth of blockchain dead drops. The firm attributed the acceleration in part to the availability of powerful Chinese open-weight AI models that could generate malicious code without the restrictions found in more tightly controlled systems.
Before the wider availability of such models, deploying blockchain-based malware infrastructure required greater technical expertise. The report indicates that AI-assisted code generation reduced that barrier, allowing more operators to develop or modify malicious software and integrate it with blockchain-based communication mechanisms.
The key change is therefore not greater malware capability alone, but the easier creation and deployment of infrastructure that can survive conventional takedown efforts.
The development also illustrates how techniques initially associated with cryptocurrency networks can affect the wider cybersecurity ecosystem. Public ledgers, smart contracts and decentralized infrastructure can provide legitimate applications with persistence and availability, but the same characteristics can also be exploited by threat actors.
Activity extends beyond blockchain networks
The impact is no longer limited to blockchain users or cryptocurrency-related systems. Netskope researchers reported that the ChainDrop supply-chain attack affected more than 440 npm packages in August 2026, highlighting how blockchain-enabled malware techniques can intersect with mainstream software-development infrastructure.
For enterprises, the shift complicates conventional approaches to identifying and disrupting command-and-control systems. Blocking a malicious domain or removing a compromised server may not be sufficient when instructions are stored on a public ledger.
For cybersecurity teams, the trend increases the importance of monitoring blockchain transactions, smart contracts, and other decentralized infrastructure alongside conventional domains, servers, and software repositories.
The findings underscore a broader challenge created by the combination of generative AI and decentralized technology. AI can reduce the expertise needed to build malicious tools, while blockchains can provide persistent infrastructure for distributing instructions, creating a combination that could make some cyber campaigns more difficult to disrupt.







