Chainalysis reports 440% surge in on-chain malware command storage since mid-2025
Chainalysis reports a rise in cyber attackers storing malware command-and-control data directly on public blockchains, a technique it terms Blockchain Dead Drops. The approach uses blockchains’ public, persistent data layers as resilient noticeboards rather than compromising the chains themselves.
Key Points
- Attackers embed configuration data, addresses or pointers in transactions or smart contract state. Malware then reads instructions on-chain.
- Chainalysis labels the broader technique EtherHiding and notes malicious on-chain writes have increased about 440% since mid-2025.
- Attribution in the research links variants of this technique to actors associated with North Korea and Iran, and to financially motivated Russian-language groups. These attributions reflect Chainalysis’ analysis.
- The blockchain’s cryptography remains intact: attackers exploit the public, immutable data layer by design, not a protocol vulnerability.
- Defenders cannot delete on-chain data once written, which increases persistence for adversaries and complicates takedowns compared to traditional server-based infrastructure.
Implications
- Security operations must expand blockchain monitoring beyond stolen funds and transfers to include on-chain indicators used for malware command-and-control.
- Infected devices can be cleaned, but the referenced on-chain data can persist indefinitely, sustaining retooling or future campaigns.
- Wallet providers and infrastructure operators face added operational requirements: detecting and filtering interactions with known malicious on-chain data sources.
Source: Chainalysis research — https://www.chainalysis.com/blog/etherhiding-blockchain-dead-drops/








