Why have blockchains become a hiding place for malware, and what does AI have to do with it?
Chainalysis recorded a 440% rise in malicious blockchain writes, from 2.06 to 11.1 per day. We explain how malware pulls commands from smart contracts, why the channel cannot be switched off, what role open-weight AI models played, and what a retail investor can do.
Blockchains have become a hiding place for malware because data written to them is nearly impossible to remove, cheap to update, and reading it looks like an ordinary request to a network node. AI lowered the barrier to entry: according to Chainalysis, after powerful open-weight models that generate malicious code without restrictions appeared, such writes rose roughly 440% — from 2.06 to 11.1 per day.
What is a blockchain dead drop and how does it work?
A dead drop is a spycraft term: a hiding spot where one person leaves a note and another collects it without ever meeting. In the blockchain version, the "note" is a set of instructions for an already infected computer: the address of a command-and-control server, a link to the next module, or a piece of code itself.
Chainalysis describes two storage methods. The first uses transaction fields, such as Bitcoin's OP_RETURN or transaction input data on BNB Smart Chain. The second uses a smart contract that holds the current "pointer". The infected device makes a standard RPC call to a node, decodes the response and connects to the server it names. To rotate infrastructure, the attacker just publishes a new transaction, and every infected machine picks up the change automatically.
Why do attackers prefer to hide commands on a blockchain?
A conventional C2 server can be taken down: the host suspends the domain, or law enforcement seizes the machine. A smart contract cannot be seized that way — records on a public network stay there.
The second advantage is cost. In its analysis of the North Korean group UNC5342, Google Threat Intelligence Group counted more than 20 contract updates in the first four months, at an average of $1.37 in gas each. The third is stealth: the malware reads data via eth_call, a read-only call. It creates no transaction, pays no fee and leaves nothing in the chain's history. From the outside it looks like any wallet or dApp querying a node.
What does AI have to do with it, and why a 440% jump?
The technique itself is old: Chainalysis traces it back to the Necurs botnet in 2013, followed later by Glupteba and ClearFake. It used to require skill — someone had to write the contract, the loader and the decoder. According to Chainalysis, the mid-2025 release of sufficiently capable open-weight Chinese language models with no restrictions on generating malicious code "removed the barrier to entry". The result: malicious writes grew from 2.06 to 11.1 per day in under a year. The firm now tracks this activity across five major blockchains, including Bitcoin, TRON, Aptos and Polygon.
This fits a broader trend. TRM Labs' index scores AI adoption in crypto crime at 54 out of 100, up from 28 in 2024. It also adds an important caveat: AI has not been shown to independently discover the novel exploit chains behind the largest thefts. For now it mostly speeds up routine work and makes known techniques more accessible.
Who uses it, and how does an infection reach an ordinary user?
According to Chainalysis, state-linked groups accounted for about two-thirds of newly observed activity in Q2 2026 and about half of all activity overall. North Korean operators use contracts on TRON, Aptos and BNB Smart Chain; Iranian actors use Bitcoin's OP_RETURN field.
The entry points, however, are mundane:
- fake job interviews: a "recruiter" on LinkedIn moves the chat to Telegram or Discord and asks you to run a "take-home test" from GitHub — this is the Contagious Interview campaign;
- a fake CAPTCHA or "error" page asking you to copy and paste a command (the ClickFix scheme);
- compromised WordPress sites;
- trojanized npm packages aimed at developers;
- clipboard hijacking that swaps wallet addresses.
In the UNC5342 campaign, as Google describes it, the chain looks like this: the JADESNOW downloader fetches the next stage from the blockchain, then the BEAVERTAIL infostealer, which targets crypto wallets among other things, and finally the INVISIBLEFERRET backdoor for persistent access.
How can retail investors and traders reduce the risk?
The blockchain is not hacked here — it is used as a bulletin board. The defence has to happen on your own device:
- do not run code or archives from "test assignments", especially when the job offer arrived in a messenger from a stranger;
- never paste into a terminal or the Run dialog commands that a CAPTCHA or "fix this error" page asks for;
- ignore pop-ups asking you to "update your browser" manually — Google explicitly calls such prompts a scam;
- keep significant amounts on a hardware wallet and verify the recipient address on its screen, not in the clipboard;
- separate devices: the machine you use to try new code and software should not be the one holding your keys and exchange access.
Where does this approach fall short, and what is the reader risking?
The main limitation is that the channel cannot be blocked outright. Chainalysis states plainly that blocking traffic to blockchain nodes would break legitimate applications. Outbound JSON-RPC calls from office machines are therefore useful as an early-warning signal, not as protection.
Second, the figures only cover what analysts found. 11.1 writes per day is detected activity on the monitored networks; the real volume may be higher, and linking the growth to specific AI models is the firm's assessment rather than proven causation.
Third, antivirus software may miss the first stage: the loader is small, and the payload arrives later and can be swapped for a dollar or two. If you have already run a suspicious file, the safer assumption is that every key, seed phrase and exchange API key on that device is compromised, and to reissue them from a clean machine.
Sources
- Chainalysis — EtherHiding & Blockchain Dead Drops: On-Chain Malware C2 — https://www.chainalysis.com/blog/etherhiding-blockchain-dead-drops/
- Google Threat Intelligence Group — DPRK Adopts EtherHiding — https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding
- TRM Labs — 2026 AI-in-Crime Adoption Index — https://www.trmlabs.com/reports-and-whitepapers/the-2026-ai-in-crime-adoption-index
This article is for information only and is not individual investment advice. Trading crypto carries the risk of losing your funds; results on historical data do not guarantee future results.
Check the strategy against your own data
ACARO is a terminal that executes a strategy on your own exchange account. Parameter search and backtesting on history are part of the subscription.
See pricing