State actors are now hiding malware in public blockchains—and it's accelerating fast.

Blockchain Dead Drops (BDDs) activity is up 420% YoY. Nation-state groups from North Korea and Iran now account for ~67% of new BDD campaigns in Q2 2025.

How it works:

Attackers store malware payloads, C2 configs, and infrastructure pointers directly in blockchain transactions or smart contracts. Since blockchains can't be taken offline, infected devices keep pulling updated instructions even after conventional servers get nuked.

The technique isn't new—started over a decade ago with $BTC and Namecoin—but it's evolved. EVM networks became the playground in 2023 with EtherHiding on $BSC. Iranian actors embed C2 data in $BTC txs. North Korean ops target crypto devs with the same toolkit.

Why the surge now?

Open-source Chinese AI models with zero restrictions. These tools can generate malicious code at scale. Daily malicious blockchain writes jumped from 2/day to 11/day after high-capacity AI models dropped.

Chainalysis tracks BDDs across 5 major chains and 12+ malware strains. State-linked actors were basically invisible until mid-2024. Now they're the majority.

Most campaigns use transaction-based or contract-based storage. Malware grabs the data from chain, then moves off-chain for credential theft, remote access, or exfil. Some even encode C2 server IPs into phantom wallet addresses.

The infrastructure is resilient, decentralized, and nearly impossible to disrupt. This is the new battlefield.