The same qualities that make blockchains appealing to developers and investors, immutability, decentralization, and permissionless access, are now being weaponized at scale by cybercriminals. The unlock wasn’t some zero-day exploit or quantum computing breakthrough. It was open-source AI.
According to a Chainalysis report, blockchain-based malware incidents have surged 440% over the past year. Average daily cases of what researchers call “blockchain dead drops” (BDDs) climbed from roughly two per day to eleven. State-linked hacking groups, particularly those tied to North Korea and Iran, now account for approximately two-thirds of all new BDD activity, up from near-zero dominance previously.
How blockchain dead drops actually work
Hackers embed malicious code, command instructions, or malware payloads directly within blockchain transactions and smart contracts. Because blockchains are designed to be permanent and tamper-proof, those instructions sit there waiting to be retrieved. Systems can pull payloads from the blockchain using read-only calls that cost nothing or next to nothing on most networks. The actual malware transactions in BDDs often run below $2 each.
Conventional takedown methods are essentially useless here. You can’t call a hosting provider and ask them to remove a malicious smart contract the way you’d report a phishing domain.
This isn’t entirely new territory. A technique called “EtherHiding” first surfaced in 2023, demonstrating how malware could be embedded in smart contracts on EVM-compatible blockchains. What’s changed dramatically is the scale, sophistication, and barrier to entry, all of which have shifted because of widely available AI tools.
The AI accelerant
The proliferation of powerful open-source AI models, including unrestricted versions released in mid-2025, has essentially democratized the creation of harmful blockchain scripts. Writing malicious smart contract code used to require specialized knowledge. Now, accessible AI tools can help generate, obfuscate, and optimize that code for attackers who might not have had the technical chops a year ago.
North Korean group UNC5342 has expanded its operations to utilize multi-chain relays spanning TRON and Aptos, diversifying beyond Ethereum and BNB Smart Chain to distribute malicious payloads across multiple blockchain ecosystems simultaneously.
Google researchers flagged the trajectory back in October 2025, publishing intelligence on credential thefts conducted via smart contracts that specifically targeted developers. The Chainalysis data now confirms that the problem has accelerated well beyond those initial warnings.
What this means for the crypto ecosystem
Chainalysis has not quantified the total successful thefts or losses attributed specifically to BDDs. But going from two incidents a day to eleven in twelve months, with state-sponsored actors driving the majority of that growth, suggests the technique is working well enough to scale.
Most BDD activity targets developers and infrastructure rather than individual wallets. But compromised developer tools, infected smart contracts, and tainted code libraries can cascade through DeFi protocols and dApps in ways that eventually reach end users and their funds.
Blockchains were designed to be censorship-resistant and immutable. Those same properties make them remarkably effective malware distribution channels when misused. Solving this without undermining the core value proposition of public blockchains is a design challenge that the industry hasn’t meaningfully addressed yet.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

3 hours ago
9








English (US) ·