Skip to content
Home > News > Chainalysis Reports 440% Surge in Malware Using Blockchains for Dead Drops

Chainalysis Reports 440% Surge in Malware Using Blockchains for Dead Drops

Chainalysis Reports 440% Surge in Malware Using Blockchains for Dead Drops

Rise in On-Chain Command-and-Control Infrastructure

Chainalysis has reported a significant increase in cyber attackers using public blockchains to store malware instructions, a tactic the firm terms “Blockchain Dead Drops” or BDDs. According to data released by the blockchain analysis firm, malicious on-chain writes have risen approximately 440% since mid-2025. The broader technique is described by Chainalysis as “EtherHiding,” reflecting the use of decentralized ledgers to host persistent data that traditional web infrastructure does not easily support.

The shift represents a move away from conventional command-and-control (C2) methods. Traditional malware typically relies on centralized servers or domains to receive instructions, infrastructure that security agencies can block or seize. In contrast, public blockchains such as Bitcoin, Ethereum, BNB Chain, and Tron are distributed and persistent. Chainalysis notes that because the protocol itself is not compromised, attackers are exploiting the deliberate design feature of public, persistent data. Once information is written on-chain, defenders cannot simply delete it, allowing attackers to update malware behavior without relying on a conventional web server that might be taken offline.

How EtherHiding Operates

Chainalysis explains that attackers place configuration data, addresses, or pointers inside transactions or smart contract state. The malware on a victim’s device is then instructed to read this information directly from the chain. This method leverages the same property that allows transaction verification years later, repurposing it for malware infrastructure. While the underlying cryptography of the affected chains has not been broken, the technique exploits the immutable nature of the ledger. Malicious software can be detected and removed from individual devices, but the on-chain data remains publicly accessible indefinitely, providing a resilient backbone for the infection.

The firm’s research indicates that this trend is not limited to a single type of threat actor. Chainalysis links the technique to actors associated with North Korea, Iran, and financially motivated Russian-language cybercrime groups. The attribution claims are based on Chainalysis’ own research into the specific patterns of on-chain writes associated with these groups. The report highlights that security teams must now monitor blockchain activity for information payloads, rather than focusing solely on tracking stolen funds or illicit transfers.

Implications for Security Teams

The emergence of EtherHiding changes the landscape for digital defense. Because the data is stored in a decentralized environment, traditional takedown operations are ineffective against the C2 information itself. Security professionals are advised to treat blockchain activity as a potential vector for malware configuration. The 440% increase in malicious writes since mid-2025 underscores a rapid adoption of this method by various threat clusters. As public blockchains continue to serve as a global data layer, their use for malicious purposes presents a new challenge for organizations tasked with protecting networks from distributed threats.

Chainalysis published the findings in a blog post titled “EtherHiding: Blockchain Dead Drops.” The report serves as a warning to the cybersecurity community that the persistence and transparency of blockchain technology, while beneficial for financial transparency, also provide a robust and difficult-to-disrupt channel for cybercriminals.

Why It Matters

This development forces security teams to expand their monitoring beyond traditional web servers to include blockchain data streams. Because on-chain data is immutable and decentralized, attackers can maintain malware control even if conventional infrastructure is seized. The 440% surge in malicious writes indicates a rapid shift in cybercrime tactics that affects all users of public blockchains, requiring updated defensive strategies to detect configuration payloads hidden in transactions.

Stay Ahead of the Crypto Market

Get breaking Bitcoin, Ethereum & altcoin news the moment it happens. Free instant alerts.