State hackers drive 440% surge in blockchain malware
Chainalysis reports a 420–440% surge in blockchain-based malware, driven by North Korea and Iran using advanced 'blockchain dead drop' tactics and AI-generated code.
Recent reports from Chainalysis and leading crypto news outlets reveal a dramatic 420–440% surge in malicious on-chain writes over the past year. State-linked actors, particularly from North Korea and Iran, are increasingly exploiting public blockchains such as Tron, Aptos, BNB Chain, and Bitcoin to embed malware payloads, command-and-control instructions, and operational commands. A key method, known as the 'blockchain dead drop' (BDD) technique, allows attackers to store and retrieve malicious data directly from blockchain transactions and smart contracts. This approach makes their campaigns highly resistant to traditional takedown efforts, as the persistence and immutability of blockchain technology ensure these instructions remain accessible even after conventional servers are removed. The surge in blockchain-based malware coincides with the rise of open-source AI models capable of generating harmful code, further accelerating the trend. North Korean cyber groups alone reportedly stole about $2 billion in digital assets in 2025, with total thefts exceeding $6.75 billion. This growing sophistication poses significant challenges for cybersecurity teams and the broader crypto ecosystem.