Malicious code written to public blockchains has risen more than fivefold in a year, and state-backed operators are now behind roughly half of it, Chainalysis reported on Thursday.
Writes carrying malware instructions have climbed from 2.06 a day to 11.1 a day since open-weight Chinese AI models were released in mid-2025, the firm found, across more than a dozen strains and five blockchains. It has identified more than 15 campaigns and threat-actor clusters.
The technique, which Chainalysis calls a blockchain dead drop, puts the address of an attacker’s command server into a smart contract or a transaction rather than into the malware. Infected machines query the chain to learn where to connect, so blocking a domain achieves little: one transaction redirects every compromised machine at once. Instructions written to a public chain are nearly impossible to seize or take down by traditional means, the firm said.
Three Operations
The North Korean group Google tracks as UNC5342 now spreads its infrastructure across three chains, according to the report. Pointers on TRON and Aptos both resolve to one transaction on BNB Chain, so disrupting the campaign would require action on all three at once. The group reaches victims through fake job interviews aimed at crypto developers, and Google has said its malware targets MetaMask and Phantom wallets and saved browser credentials.
Operators the firm suspects are linked to Iran’s Ministry of Intelligence write their instructions into Bitcoin transactions instead, sending small payments to an address historically associated with Satoshi Nakamoto. The address has no connection to them, which is the point: a permanent public lookup spot reduces their footprint. Chainalysis bases that link on the malware, not the chain activity alone.
Evidence points to a third model run as a business by Russian-language criminals, Chainalysis said, with fleets of resolver contracts on Polygon rented to other crews. One deployer wallet appears linked to fraudulent tokens impersonating stablecoins and to more than 50 near-identical contracts on BNB Chain.
From Criminals to States
Cybercriminals accounted for essentially all of this activity through early 2024, the firm found. State-linked groups began appearing meaningfully in mid-2024, and by the second quarter of 2026 they were responsible for 51% of attributed writes.
Chainalysis attributes the acceleration to open-weight Chinese models carrying no restrictions on generating malicious code, which it wrote “removed the barrier to entry” for less experienced attackers. Its timeline marks the shift at the release of Kimi K2 and Qwen3-Coder.
The idea is old, and Chainalysis dates it to 2013. Guardio Labs documented the first smart-contract version in October 2023, after a criminal group began using a BNB Chain contract that September to serve fake browser-update lures. What has changed is the volume, and who is behind it.
Defenders cannot simply block the traffic, the firm noted, without cutting off the public endpoints every wallet and application relies on.
Related Listen: How State-Sponsored Hackers Like DPRK Drain DeFi Protocols: Uneasy Money
