Newscast

Hackers are turning Blockchains into malware command centers

By Nik

September 22, 2026

Cybercriminals are finding a new use for public blockchains: keeping malware connected even after traditional servers are taken offline.

According to Chainalysis, malicious blockchain activity jumped 440%, with daily entries increasing from 2.06 to 11.1 as newer AI systems became widely available. The idea is relatively simple. Instead of storing malware instructions on a conventional server, attackers can hide addresses, commands, or configuration data in blockchain transactions and smart contracts.

These so-called blockchain dead drops are difficult to remove because blockchain records are distributed across thousands of systems. Taking down one server, therefore, doesn’t necessarily break the malware’s communication channel.

The technique is already being used by several threat groups. A North Korean-linked operation has used TRON and Aptos as backup communication routes before retrieving encrypted instructions through BNB Chain. Iranian-linked actors have reportedly hidden routing information inside Bitcoin transactions, while Russian-speaking criminals have turned blockchain infrastructure into a service for other malware operators.

AI may be helping accelerate the trend. Chainalysis says the arrival of high-capacity Chinese open models lowered the technical barrier for attackers who previously needed considerable expertise in both malware development and blockchain systems.

State-linked groups accounted for roughly two-thirds of newly observed activity in Q2 2026, according to the report.

The problem for defenders is that simply blocking blockchain traffic isn’t practical. Doing so could also interfere with legitimate wallets, exchanges, decentralized applications, and DeFi services.