News

Chainalysis Says State Actors Now Hide Half of Blockchain Malware Where Nobody Can Seize It

A 17 September 2026 Chainalysis research report says malware-instruction writes on public chains rose from 2.06 a day to 11.1 a day, and that state-linked groups were 51 percent of attributed writes by Q2 2026. The figures are the firm's estimates, not a court finding.

Chainalysis Says State Actors Now Hide Half of Blockchain Malware Where Nobody Can Seize It

Unchained (17 September 2026) reported a Chainalysis study of blockchain dead drops. The technique writes malicious code to public chains and stores command-server addresses in smart contracts or transaction data so infected machines query the ledger for where to connect.

This is an industry research report, dated about 17 September 2026. It is not a statute, not a criminal conviction, and not a new OFAC designation.

Writes carrying malware instructions rose from 2.06 a day to 11.1 a day since open-weight Chinese models were released in mid-2025. Chainalysis found more than a dozen strains across five chains, and more than 15 campaigns or clusters.

Cybercriminals were essentially all of this activity through early 2024. State-linked groups appeared in mid-2024. By the second quarter of 2026 they were 51 percent of attributed writes, which is the Chainalysis share behind the headline word "half," not a government statistic.

One on-chain transaction can redirect every compromised machine. Traditional domain seizures achieve little because the pointer lives on a public ledger. Defenders cannot simply block public RPC endpoints without cutting off the interfaces every wallet and application uses.

UNC5342, the North Korea cluster Google tracks, spreads infrastructure across TRON, Aptos, and BNB Chain so disrupting one chain fails. Google, as cited by Chainalysis, says the group uses fake job interviews aimed at crypto developers and malware that targets MetaMask, Phantom, and saved browser credentials.

Operators Chainalysis suspects are linked to Iran's Ministry of Intelligence write instructions into Bitcoin transactions that send small payments to an address historically associated with Satoshi Nakamoto. The firm bases that link on the malware, not the chain activity alone. That is a Chainalysis assessment, not a court finding that Iran's ministry ran the wallets.

A third model, in Russian-language criminal crews, rents fleets of resolver contracts on Polygon to other groups. One deployer wallet appears linked to fake stablecoin tokens and more than 50 near-identical BNB contracts.

Chainalysis ties the surge to open-weight Chinese models, marking Kimi K2 and Qwen3-Coder as the releases that "removed the barrier to entry" for generating malicious code. The idea dates to 2013. Guardio Labs documented the first smart-contract version in October 2023 after a September 2023 BNB contract served fake browser-update lures.

Related sanctions and Iran-rail tape includes Treasury's BitBank Hormuz designation, the DOJ's $61 million USDT Iranian-oil forfeiture, and Treasury's Golden Global Bank listing.

If you run an exchange, wallet, or incident-response desk, treat dead-drop command servers as a Chainalysis volume estimate and decide this week whether your playbooks can follow a pointer across TRON, Aptos, BNB Chain, Bitcoin, and Polygon without depending on a domain seizure.

Finpresso: daily AI & finance brief

Free daily newsletter, read in 5 minutes.

Subscribe free