440% surge in blockchain malware commands linked to Chinese AI models: Chainalysis

Chainalysis reports a 440% increase in blockchain malware commands due to Chinese AI models.

17/09/2026 12:2612 min read

Chainalysis has reported that since the introduction of unrestricted Chinese open-source AI models, attackers have been posting malware instructions to blockchains 440% more frequently. Within less than a year, daily malicious on-chain writes increased from 2.06 to 11.1.

The technique is referred to as blockchain dead drops (BDDs) by Chainalysis. The firm discovered that most of the activity is now generated by state-linked operators from North Korea and Iran.

Censorship resistance now leveraged as a hacking asset

According to its latest report, Chainalysis pointed out that hackers previously stored malicious code on centralized servers, which could be seized, blocked, or taken offline. Attackers now, however, store such code on public blockchains.

“We call this technique ‘blockchain dead drops’ (BDD). BDDs store payloads in on-chain transactions and smart contracts where infected devices can retrieve them on demand. The permanence of blockchains gives threat actors’ cyber campaigns longevity; they can communicate with compromised machines without fear of losing their command-and-control (C2) relayer,” the report read.

The firm emphasizes that the threat is in durability rather than firepower. Campaigns outlast domain seizures, hosting takedowns, and repository removals. The technique goes back to 2013, when a variant of the Necurs botnet stored domains on a Bitcoin (BTC) fork named Namecoin.

By 2023, it had arrived on Ethereum Virtual Machine (EVM) chains under the name EtherHiding. Later, Google caught North Korea's UNC5342 using the technique in fake job interviews.

The recent explosion is attributed by Chainalysis to mid-2025. At that time, powerful open-weight Chinese models were launched without guardrails against writing malicious code. According to the firm, this removed the skill barrier that previously kept dead drops rare.

The spread now extends well beyond cryptocurrency. Researchers at Netskope report that the ChainDrop supply chain attack affected over 440 npm packages in August 2026.

North Korea, Iran, and Russian forums each craft their own playbooks

Through early 2024, cybercriminals were responsible for almost all dead drop activity. By Q2 2026, state-linked groups were generating about two-thirds of new activity each quarter and half of the overall total.

North Korea's UNC5342 now operates a three-chain relay. Pointers on TRON (TRX) and Aptos (APT) direct infected devices to encrypted devices on BNB Smart Chain.

“The attacker rotates infrastructure by publishing new transactions, and every previously infected device picks up the change automatically. Disrupting the operation would require action across all three chains simultaneously,” the team noted.

Suspected Iranian intelligence operators make small Bitcoin payments to a well-known address associated with Satoshi Nakamoto. Chainalysis says the malware searches for data within each transaction, then decodes it to obtain the current attacker infrastructure.

Meanwhile, Russian-language criminals offer the capability as a service. An operator wallet on Polygon (POL) manages a fleet of resolver contracts, each apparently serving a distinct paying customer.

The report notes that defenders cannot simply block blockchain traffic without disrupting all legitimate wallets and apps. However, the same permanence that protects attackers also leaves every update on a public ledger.

Whether investigators can convert that trail into arrests faster than AI tools create new operators remains the open question.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles