State-sponsored hacking groups are increasingly exploiting public blockchains as takedown-resistant dead drops to direct and maintain malware infrastructure, according to Chainalysis.

• Chainalysis reported a 420% to 440% jump in blockchain dead drop activity over the past year, with daily malicious on-chain writes rising from 2.06 to 11.1.
• State-aligned operators, primarily from North Korea and Iran, now account for roughly two-thirds of newly observed blockchain dead drop activity.
• North Korean group UNC5342 established redundant command paths using Tron and Aptos to route malware to Binance Smart Chain, while suspected Iranian actors embedded routing checkpoints in Bitcoin transactions.
• Researchers noted the escalation coincided with the release of open-weight Chinese AI models, which lowered the technical expertise needed to craft on-chain malware instructions.
Why it matters
The growing weaponization of public blockchains by nation-states threatens to heighten regulatory pressure on crypto network monitoring and transaction-level data filtering.