Chainalysis Warns Malware Operators Are Turning Blockchains Into Dead Drops
Cybercriminals are increasingly using public blockchains as resilient command-and-control infrastructure for malware. Chainalysis calls this technique Blockchain Dead Drops (BDDs), part of a broader approach known as EtherHiding. Instead of relying on a removable server or domain, attackers store configuration data, addresses, or pointers directly on-chain in transactions or smart contract state, then have malware read that data from the blockchain. This makes the infrastructure hard to take offline because the data is public and persistent. Chainalysis reports a sharp rise in malicious on-chain writes, up about 440% since mid-2025. The technique does not break blockchain security; it exploits the permanence of public data. Defenders can remove malware from devices, but the on-chain instructions may remain accessible indefinitely, so blockchain monitoring must cover more than stolen funds and suspicious transfers.
