Chainalysis reported on September 17, 2026, that malicious blockchain writes linked to dead drops rose from 2.06 per day before high-capacity open-source Chinese AI models to 11.1 per day afterward. Its estimates put state-linked groups behind roughly two-thirds of new quarterly activity and half of all activity by Q2 2026.

What Chainalysis reported about blockchain dead drops

A blockchain dead drop is a persistent location on a public blockchain where malware can retrieve a payload, command-and-control (C2) settings, or a pointer to other infrastructure. C2 is the system malware uses to receive instructions or contact an operator’s server.

Chainalysis gave two separate growth comparisons: a 420% increase in dead-drop activity over the prior 12 months, and a 440% increase since open-source AI coding tools rose. It associates the broader increase with the availability of capable open-weight AI tools, which it says lowered the technical barrier to deploying dead drops.

How blockchain dead drops work

The blockchain acts as a durable place to store data or look up directions. Malware already running on a compromised device queries that data; the dead drop does not itself start the infection. Depending on the method, the malware may retrieve a payload, read C2 settings, or find a pointer to an off-chain server where further activity takes place.

Three ways malware can use on-chain data

MethodOn-chain locationWhat malware retrieves
Transaction-based storageTransaction data, such as Bitcoin OP_RETURN or BNB Smart Chain input dataC2 settings, a payload reference, or a pointer to infrastructure
Smart-contract storage, including EtherHidingSmart-contract stateC2 settings, a payload reference, or malicious code
Phantom-wallet encodingBytes of a blockchain address with no corresponding private-key pairAn encoded C2 IP address

In one cross-chain example described by Chainalysis, malware associated with the DPRK-linked group UNC5342 checks TRON first and Aptos if that route fails; both point to data on BNB Smart Chain. The arrangement uses separate chains as routes to the same destination.

What the figures say about actors and AI

By Q2 2026, Chainalysis attributed roughly two-thirds of new blockchain dead-drop activity each quarter and half of total activity to state-linked groups. These are estimates of the activity it tracked.

The reported AI link is an association: Chainalysis connects the increase with the availability of open-weight coding tools. Its two growth percentages use different comparison periods, so they describe separate measures rather than one combined rate.

What defenders can monitor

Unexpected outbound JSON-RPC requests—JSON-formatted calls software uses to query blockchain nodes—from devices with no legitimate reason to access a public blockchain may be a useful detection signal. Such traffic can prompt investigation, but it does not by itself prove a device is compromised.

Chainalysis also points to tracing changes in on-chain transactions and contracts. Broadly blocking public blockchain traffic could disrupt legitimate services, and attackers may operate their own nodes.