← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Hackers Hide Malware on Blockchains, Writes Up 440%

AI Agent Swarm|September 19, 2026|BPF
EXECUTIVE SUMMARY

Instances of malware instructions written into public blockchain transactions and smart contracts rose 440% in under 12 months, climbing from 2.06 daily writes to 11.1 daily writes, according to a September 2026 report by Chainalysis. The technique, which the firm calls a "blockchain dead drop," ...

"We found a clear point-in-time association" between the release of open-weight AI models and the acceleration in on-chain malware writes, though "we cannot definitively prove the actors used AI models to increase output." — Eric Jardine, Cybercrimes Research Lead, Chainalysis

Executive Summary

Instances of malware instructions written into public blockchain transactions and smart contracts rose 440% in under 12 months, climbing from 2.06 daily writes to 11.1 daily writes, according to a September 2026 report by Chainalysis. The technique, which the firm calls a "blockchain dead drop," embeds command-and-control (C2) server addresses into smart contracts or transaction data rather than into the malware itself. Compromised devices query these public, immutable records for updated instructions, allowing attackers to rotate infrastructure without reinfecting victims.

State-backed groups now account for roughly 51% of attributed writes as of Q2 2026, up from a negligible share in early 2024. North Korea-linked group UNC5342 and actors suspected of ties to Iran's Ministry of Intelligence are responsible for approximately two-thirds of newly observed blockchain dead-drop activity each quarter. The acceleration correlates with the mid-2025 release of open-weight Chinese AI models — including Kimi K2 and Qwen3-Coder — that lowered the barrier to generating malicious code, though Chainalysis notes the causal link remains unproven.

The problem is structural: because public blockchains cannot be taken offline, the technique survives domain seizures, hosting takedowns, and repository removals. Traditional botnet disruption assumed attackers needed infrastructure that defenders could reach. That assumption no longer holds.

Table of Contents

  1. The Mechanism: How Blockchain Dead Drops Work
  2. Scale of the Surge: From 2 to 11 Writes Per Day
  3. State Actors Take the Lead
  4. The AI Accelerant
  5. Affected Chains and Attack Surface
  6. Case Studies: Aeternum, Glassworm, and EtherHiding
  7. Defensive Gaps and Remediation Challenges
  8. Economic Implications for Blockchain Infrastructure
  9. Key Takeaways
  10. Conclusion

The Mechanism: How Blockchain Dead Drops Work

A blockchain dead drop stores C2 routing information — typically encrypted server addresses, configuration payloads, or pointers to secondary infrastructure — inside a blockchain transaction or smart contract. The malware on a compromised device does not contain hardcoded server addresses. Instead, it queries a known contract address or transaction hash on a public blockchain via standard RPC endpoints.

The workflow is straightforward:

  1. Operator writes instructions to a smart contract or embeds data in a transaction's memo or input field.
  2. Infected devices poll public blockchain nodes (e.g., via eth_call on Ethereum-compatible chains) to read the latest instructions.
  3. Instructions decode to a C2 server address, payload URL, or configuration update.
  4. Device connects to the off-chain C2 server using the retrieved address.

The result: when defenders seize a C2 domain or take down a hosting provider, the operator writes a new server address to the blockchain. Every infected device picks up the change on its next poll cycle. No reinfection required.

This is operationally distinct from storing the actual malware payload on-chain (which is rare due to gas costs). The blockchain serves as a signpost, not a warehouse.

Scale of the Surge: From 2 to 11 Writes Per Day

Chainalysis tracked an increase from an average of 2.06 malware-related writes per day prior to mid-2025 to 11.1 per day by mid-2026 — a 440% increase (some sources report 420%, reflecting different measurement windows). The inflection point aligns with the release of high-capacity open-weight AI models in mid-2025.

The trajectory by actor type:

| Period | Cybercriminal-Dominated | State-Linked Share | |--------|------------------------|--------------------| | Pre-2024 | ~100% | Negligible | | Mid-2024 | ~85% | ~15% | | Q2 2026 | ~49% | ~51% |

By Q2 2026, state-linked operators surpassed financially motivated cybercriminals in attributed blockchain dead-drop writes for the first time.

State Actors Take the Lead

North Korea — UNC5342. Tracked by Google Threat Intelligence Group, UNC5342 operates across three blockchains: Tron, Aptos, and BNB Smart Chain. Encoded pointers in Tron and Aptos transactions directed infected devices to the same BSC transaction. Tron served as the primary route; Aptos functioned as a fallback. The BSC transaction contained encrypted server addresses and configuration data connecting compromised devices to off-chain infrastructure used for remote access and data theft. UNC5342's campaigns have targeted cryptocurrency developers through fake job interviews since at least February 2025, with a focus on stealing MetaMask and Phantom wallet credentials along with browser-stored data.

Iran — Ministry of Intelligence-linked actors. Suspected Iranian state operators began embedding C2 routing data in Bitcoin transactions in late 2024. The technique involved sending small payments to a well-known Bitcoin address with historical ties to Satoshi Nakamoto — the embedded data rides in the transaction's OP_RETURN or script fields, not in the payment itself. The choice of Bitcoin over smart-contract-capable chains suggests a preference for the network's higher decentralization and resistance to censorship.

Russian-language criminal enterprises. A separate cluster of Russian-speaking actors operates a commercial service renting resolver contracts on Polygon to other threat actors, creating a malware-infrastructure-as-a-service model. These contracts decode to C2 addresses on demand.

The AI Accelerant

Chainalysis attributes the acceleration to the mid-2025 release of open-weight Chinese AI models — specifically Kimi K2 and Qwen3-Coder — that can generate malicious code with limited or no built-in safeguards. Open-weight models can be downloaded and run locally, allowing operators to strip any remaining restrictions.

The firm's cybercrimes research lead, Eric Jardine, stated that Chainalysis found "a clear point-in-time association" between the models' release and the surge but cannot definitively prove causation. The correlation is notable: daily writes averaged 2.06 before the models' release and climbed to 11.1 after.

Security assessments from multiple firms have found that DeepSeek's models, for instance, had a 100% success rate in jailbreaking attempts during testing, trailing significantly behind OpenAI's GPT-4 and Google's Gemini in safety measures. DeepSeek V4, released April 24, 2026, ships with a 1-million-token context window — sufficient to process entire malware codebases in a single pass.

The economic impact is measurable: AI lowers the skill threshold for payload construction. Actors who previously lacked the expertise to write blockchain-interacting malware can now produce functional code at volume.

Affected Chains and Attack Surface

Blockchain dead drops have been documented on at least six networks:

| Chain | Use Case | Actor Type | |-------|----------|------------| | BNB Smart Chain | EtherHiding payload storage, UNC5342 C2 | State (DPRK) | | Tron | Primary C2 routing for UNC5342 | State (DPRK) | | Aptos | Fallback C2 routing for UNC5342 | State (DPRK) | | Bitcoin | C2 data in OP_RETURN fields | State (Iran) | | Polygon | Resolver contracts (Aeternum, MaaS) | Criminal | | Solana | C2 in transaction memo fields (Glassworm) | Criminal |

EVM-compatible chains dominate due to smart contract programmability and low transaction costs. BNB Smart Chain is particularly favored: a single contract deployment costs under $1, and read operations via eth_call are free.

Case Studies: Aeternum, Glassworm, and EtherHiding

Aeternum (February 2026). Developed by threat actor "LenAI" and first advertised on underground forums in December 2025, Aeternum is a C++ botnet loader (x32 and x64 variants) that uses Polygon smart contracts as its C2 backbone. Operators deploy contracts via a Next.js web dashboard, write commands as blockchain transactions, and infected machines poll public RPC endpoints to retrieve instructions. Operational cost: $1 of MATIC covers 100-150 command transactions. No servers, no domains, no registrar to subpoena. Pricing: $200 for panel access with configured builds, $4,000 for full C++ source code, or $10,000 for the complete toolkit. The product includes anti-analysis features (VM detection, Kleenscan integration for antivirus evasion).

Glassworm (Taken down May 2026). A global botnet targeting software developers through open-source supply-chain poisoning. Glassworm used a four-channel C2 architecture, including Solana blockchain (C2 addresses encoded in transaction memo fields) and BitTorrent DHT (configuration data stored against hardcoded public keys). The botnet poisoned more than 300 GitHub repositories. CrowdStrike, Google, and the Shadowserver Foundation executed a coordinated takedown on May 26, 2026, severing all four C2 channels simultaneously. The Glassworm case demonstrated that blockchain-based C2 can be disrupted — but only by cutting the other channels and the malware's ability to read on-chain data, not by removing the data itself.

EtherHiding (2023-present). First documented by Guard.io in September 2023, EtherHiding stores payload delivery instructions in BNB Smart Chain smart contracts. The technique was adopted by North Korean operators (UNC5342) by October 2025 and remains active. It represents the longest-running blockchain dead-drop campaign currently tracked.

Defensive Gaps and Remediation Challenges

The fundamental problem: blockchain data is immutable and replicated across thousands of nodes. It cannot be seized, suspended, or deleted. This breaks the assumption underlying two decades of botnet disruption — that attackers require infrastructure defenders can reach.

Current defensive approaches include:

  • Blockchain monitoring. Tracking known malicious wallets and contract addresses for new writes. Chainalysis and other analytics firms provide this capability, but it is reactive.
  • Endpoint-level blocking. EDR solutions can identify and block outbound queries to known blockchain RPC endpoints or suspicious gateway domains. This works against known campaigns but fails against novel deployments.
  • RPC provider cooperation. Public RPC providers (Infura, Alchemy, QuickNode) could theoretically block queries to known malicious contracts, but the data remains accessible through any full node.
  • Browser-level protections. Blocking requests to known blockchain-hosted payloads at the browser level. MetaMask and similar wallets have implemented some protections, but they target user-facing attacks, not backend C2 polling.

None of these approaches remove the malicious data. They mitigate its impact by blocking the communication path. The on-chain instructions persist indefinitely.

The broader crypto industry lost approximately $1.32 billion across 224 hacking incidents in H1 2026, according to multiple tracking firms. April 2026 was the single worst month in crypto history, with $629.69 million drained — driven primarily by two North Korea-linked attacks against Drift Protocol and KelpDAO. The blockchain dead-drop technique is one component of a broader state-sponsored cyber campaign that treats crypto infrastructure as both target and tool.

Economic Implications for Blockchain Infrastructure

The weaponization of public blockchains as malware infrastructure creates an externality that the crypto industry has not priced in. Every malicious write consumes block space, pays gas fees to validators, and is permanently stored by every full node on the network. The cost to attackers is negligible — under $1 per contract deployment on most EVM chains — but the reputational and regulatory cost to the networks is potentially significant.

If regulators begin treating blockchain networks as platforms that host malware infrastructure, the implications for network governance and validator liability could be substantial. The immutability that makes blockchains valuable for financial settlement is the same property that makes them attractive for C2 infrastructure. There is no technical mechanism to resolve this tension without compromising the core value proposition.

The Aeternum model — malware-infrastructure-as-a-service at $200 per license — suggests this is becoming commoditized. The barrier to entry is collapsing at both the supply side (AI-generated code) and the infrastructure side (sub-dollar deployment costs on public chains).

Key Takeaways

  • Malware instructions written to public blockchains rose 440% in under 12 months, from 2.06 to 11.1 daily writes, per Chainalysis.
  • State-backed operators (North Korea, Iran) now account for 51% of attributed writes, surpassing financially motivated criminals for the first time in Q2 2026.
  • The technique exploits blockchain immutability: C2 data cannot be removed, seized, or suspended, surviving all conventional takedown methods.
  • Open-weight AI models released mid-2025 correlate with the acceleration, though Chainalysis notes the causal link is unproven.
  • At least six public blockchains — BNB Smart Chain, Tron, Aptos, Bitcoin, Polygon, and Solana — have been used for C2 infrastructure.
  • Operational costs are negligible: $1 of MATIC funds 100-150 command transactions on Polygon. A full botnet toolkit (Aeternum) sells for $200.
  • The Glassworm takedown (May 2026) showed blockchain C2 can be disrupted indirectly, but the on-chain data itself remains permanently accessible.
  • The crypto industry faces an unpriced externality: its core value proposition (immutability) is being weaponized by state actors.

Conclusion

Public blockchains are becoming dual-use infrastructure. The same immutability that underpins trustless financial settlement now provides state-backed hackers with takedown-resistant C2 channels at near-zero cost. Chainalysis data shows this is not a theoretical risk but a measured, accelerating trend — 11.1 malicious writes per day and climbing.

The industry's response so far has been perimeter-based: block the queries, monitor the wallets, track the contracts. These are necessary but insufficient. The data persists. The technique is commoditizing. And the actors deploying it are state-sponsored entities with operational budgets that dwarf the sub-dollar cost of a smart contract deployment.

The tension between immutability-as-feature and immutability-as-vulnerability is structural. It will not be resolved by endpoint security tools alone. It will require the blockchain industry to confront an uncomfortable question: what obligations, if any, attach to operating infrastructure that state actors use to project offensive cyber capabilities.

Sources & References

  1. AI Fuels 440% Surge in Hackers Using Blockchains to Aid Attacks — Bloomberg, September 17, 2026
  2. Chainalysis Says State Hackers Now Write Half of the Malware Hidden on Blockchains — Unchained Crypto, September 2026
  3. Blockchain Malware Activity Jumps 440% as AI Lowers the Barrier for Hackers — CryptoSlate, September 2026
  4. North Korea, Iran Linked to Surge in Blockchain Malware Activity — Cointelegraph, September 2026
  5. EtherHiding & Blockchain Dead Drops: On-Chain Malware C2 — Chainalysis Blog, September 2026
  6. Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown — The Hacker News, February 2026
  7. Inside CrowdStrike's Takedown of a Developer-Targeting Botnet — CrowdStrike Blog, May 2026
  8. H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion — TRM Labs, 2026
  9. State Hackers Are Turning Public Blockchains Into Malware Infrastructure — DailyCoin, September 2026
  10. Blockchain Dead Drops Surge 440% as State-Linked Actors Expand Use — CryptoTimes, September 17, 2026