State Hackers Fuel 420% Surge in Onchain Malware, Chainalysis Says
Public blockchains are becoming a durable command-and-control layer for cyberattacks. Chainalysis calls the technique “blockchain dead drops,” or BDDs: attackers place malware payloads, configuration data or infrastructure pointers in transactions and smart contracts for infected devices to retrieve. Because those records are decentralized and difficult to remove, campaigns can survive domain seizures, server takedowns and repository deletions, creating a visibility gap for conventional cyber defenses even when the final compromise occurs offchain.
On Sept. 17, 2026, Chainalysis said BDD activity had surged 420% over the previous 12 months. By the second quarter of 2026, state-linked groups generated about two-thirds of new activity each quarter and half of all tracked activity. North Korea-linked UNC5342 used Tron and Aptos as redundant routes to encrypted instructions on BNB Smart Chain, while actors suspected of ties to Iran’s Ministry of Intelligence embedded command-and-control routing data in Bitcoin transactions. The firm also recorded a 440% increase in malicious blockchain writes since July 2025.
All Coverage
2 original reportsThe Backstory
The history behind this eventThis is the first time the radar has seen this story
See the “Cryptocurrency Security” timeline →Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →