A new Chainalysis report finds blockchain-assisted cyberattacks have increased more than fivefold year over year. The technique, called Blockchain Dead Drops (BDD), stores malware payloads or command-and-control configuration data directly on public blockchains, where it is immutable and replicated worldwide. That makes the infrastructure highly resistant to domain seizures, repository removals, or hosting takedowns.
Attackers use transaction-based storage, embedding data in fields like memos or calldata, or contract-based storage, where smart contracts hold current C2 pointers. A newer trick involves "phantom wallets"—addresses with no private key—where the C2 server's IP is encoded into the address bytes and sent in zero-value transactions. Once the victim's machine decodes the data, the actual attack moves off-chain.
Chainalysis attributes the surge largely to nation-state actors. Iranian groups linked to the country's Ministry of Intelligence began embedding C2 data in Bitcoin transactions in 2024, and North Korean actors adopted EtherHiding in fake job interview campaigns by 2025. The report states that by Q2 2026, state-actor-linked groups were responsible for roughly two-thirds of new BDD activity each quarter. It also links the rise to open-weight Chinese LLMs, which have lowered the technical barrier for less-experienced attackers and helped push daily malicious blockchain writes from 2.06 to 11.1—a 440% increase.