State-Sponsored Actors Take the Lead in Blockchain Threats

A recent report from blockchain analytics firm Chainalysis paints a concerning picture of the evolving security landscape. The volume of malicious code deployed on public blockchains has skyrocketed, increasing more than fivefold within a single year. By Q2 2026, state-backed attackers were responsible for a majority—51%—of this malicious activity, signaling a fundamental shift in the source of major threats.

The AI Model Catalyst

The report links a significant surge in attacks to the mid-2025 release of an open-source Chinese AI model. Following its publication, the daily average of on-chain writes containing malicious commands jumped from 2.06 to 11.1. These operations now span at least five different blockchain networks, with researchers tracking over 15 distinct threat groups.

The 'Blockchain Dead Drop': An Unblockable Command Channel

These advanced actors are leveraging a technique known as the 'blockchain dead drop.' This method embeds command-and-control server addresses directly into smart contracts or standard blockchain transactions.

  • How It Works: Compromised devices are programmed to constantly monitor specific blockchain addresses or transactions. When attackers update the data on-chain (dropping new instructions), all infected machines globally can retrieve the new connection points or commands almost instantly.
  • The Defense Challenge: This approach renders traditional defense tactics like domain or IP blocking largely ineffective. A single, low-cost transaction can simultaneously redirect every victim machine. Due to the immutable nature of blockchain data, these malicious instructions become practically impossible to seize or delete once confirmed.

Notable Actors and Their Tactics

The report highlights several active groups to illustrate the sophistication of these campaigns.

One group, UNC5342, linked to North Korea, has been observed operating across multiple chains including TRON, Aptos, and BNB Chain. This actor commonly uses fake job interviews as a lure to deliver malicious files, primarily targeting users of popular cryptocurrency wallets like MetaMask and Phantom to steal funds.

Another group, suspected of ties to Iranian intelligence, has opted to hide its commands within Bitcoin transaction data. This method increases detection difficulty, as the instructions are camouflaged within the vast volume of regular Bitcoin transactions.

These cases demonstrate how state-level attackers are exploiting the transparency and censorship-resistant properties of blockchains to build persistent, covert, and resilient command infrastructure, posing a severe and growing risk to digital asset security worldwide.