---
title: "Blockchain dead drops surge 440% as North Korea… | Firevault"
description: "Chainalysis research shows malicious blockchain writes rising from 2.06 to 11.1 a day in under a year, with state-linked groups now behind most new activity.…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026#webpage",
      "url": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026",
      "name": "Blockchain dead drops surge 440% as North Korea…",
      "description": "Chainalysis research shows malicious blockchain writes rising from 2.06 to 11.1 a day in under a year, with state-linked groups now behind most new activity.…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Blockchain dead drops surge 440% as North Korea and Iran hide malware on public ledgers",
          "item": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Blockchain dead drops surge 440% as North Korea and Iran hide malware on public ledgers",
      "description": "Chainalysis research shows malicious blockchain writes rising from 2.06 to 11.1 a day in under a year, with state-linked groups now behind most new activity. Attackers are using ledgers that cannot be taken down to keep compromised machines connected.",
      "url": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-24T08:47:19.260814+00:00",
      "dateModified": "2026-09-24T08:47:19.260814+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Threat Analysis",
      "wordCount": 509,
      "keywords": "Blockchain, Threat Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "## What the research found Research published by blockchain analytics firm Chainalysis on 17 September 2026 shows a 440% year-on-year rise in what it calls blockchain dead drops (BDD). In these schemes, attackers write malware instructions, command-and-control (C2) addresses or pointers into public blockchain transactions and smart contracts, where infected devices can look them up on demand. The ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is a blockchain dead drop?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "It is a technique where attackers store malware instructions or command server addresses inside public blockchain transactions or smart contracts. Infected devices read those records to receive new orders, and because the ledger cannot be deleted, the channel survives server takedowns."
          }
        },
        {
          "@type": "Question",
          "name": "How large is the increase?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Chainalysis reports a 440% year-on-year rise, with malicious blockchain writes increasing from 2.06 to 11.1 a day in less than a year."
          }
        },
        {
          "@type": "Question",
          "name": "Who is behind the activity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Groups linked to North Korea and Iran accounted for roughly two-thirds of newly observed activity each quarter by the second quarter of 2026, according to Chainalysis."
          }
        },
        {
          "@type": "Question",
          "name": "How can organisations protect their data?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Monitor for unexpected blockchain RPC traffic, and keep the most critical records physically disconnected when not in use, so that malware has no network path to them regardless of where it receives its instructions."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Breaking News Updated as information becomes available 

Overview

What the research foundState actors now leadWhy this mattersThe Firevault viewSourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Threat Analysis · 24 September 2026 · Breaking 

# Blockchain dead drops surge 440% as North Korea and Iran hide malware on public ledgers

Chainalysis research shows malicious blockchain writes rising from 2.06 to 11.1 a day in under a year, with state-linked groups now behind most new activity. Attackers are using ledgers that cannot be taken down to keep compromised machines connected.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fblockchain-dead-drops-malware-surge-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fblockchain-dead-drops-malware-surge-2026&text=Blockchain%20dead%20drops%20surge%20440%25%20as%20North%20Korea%20and%20Iran%20hide%20malware%20on%20public%20ledgers%0A%0AChainalysis%20research%20shows%20malicious%20blockchain%20writes%20rising%20from%202.06%20to%2011.1%20a%20day%20in%20under%20a%20year%2C%20with%20state-linked%20groups%20now%20behind%20most%20new%20activity.%20Attackers%20are%20using%20ledgers%20that%20cannot%20be%20taken%20down%20to%20keep%20compromised%20machines%20connected.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fblockchain-dead-drops-malware-surge-2026)[](mailto:?subject=Blockchain%20dead%20drops%20surge%20440%25%20as%20North%20Korea%20and%20Iran%20hide%20malware%20on%20public%20ledgers&body=Chainalysis%20research%20shows%20malicious%20blockchain%20writes%20rising%20from%202.06%20to%2011.1%20a%20day%20in%20under%20a%20year%2C%20with%20state-linked%20groups%20now%20behind%20most%20new%20activity.%20Attackers%20are%20using%20ledgers%20that%20cannot%20be%20taken%20down%20to%20keep%20compromised%20machines%20connected.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fblockchain-dead-drops-malware-surge-2026)

![Illustration of a blockchain with a cracked block sending hidden malware instructions to infected laptops, in navy, cyan and magenta](/news/blockchain-dead-drops-malware-surge-2026.jpg)

Illustration of a blockchain with a cracked block sending hidden malware instructions to infected laptops, in navy, cyan and magenta

Why it matters

## What this means for organisations holding critical data

Chainalysis research shows malicious blockchain writes rising from 2.06 to 11.1 a day in under a year, with state-linked groups now behind most new activity. Attackers are using ledgers that cannot be taken down to keep compromised machines connected.

In this analysis

1.  01 [What the research found](#section-0)
2.  02 [State actors now lead](#section-1)
3.  03 [Why this matters](#section-2)
4.  04 [The Firevault view](#section-3)

**On this page**[What the research found](#section-0)[State actors now lead](#section-1)[Why this matters](#section-2)[The Firevault view](#section-3)

## What the research found

Research published by blockchain analytics firm Chainalysis on 17 September 2026 shows a 440% year-on-year rise in what it calls blockchain dead drops (BDD). In these schemes, attackers write malware instructions, command-and-control (C2) addresses or pointers into public blockchain transactions and smart contracts, where infected devices can look them up on demand.

The average number of malicious blockchain writes rose from 2.06 a day to 11.1 a day in less than a year. Chainalysis links the acceleration to the release of high-capacity open-weight Chinese AI models that place no restrictions on generating malicious code, although it notes that its measurement shows correlation rather than proof of cause.

## State actors now lead

Groups linked to North Korea and Iran accounted for roughly two-thirds of newly observed dead-drop activity each quarter by the second quarter of 2026, according to the report. State-linked operators now represent around half of all activity Chainalysis tracks, up from a negligible share in early 2024.

Techniques differ by actor. A North Korean-linked operation associated with UNC5342 uses TRON and Aptos as alternate routes, while other campaigns rely on BNB Chain, Polygon and Bitcoin. Independent on-chain analysis by Bitquery found that one North Korean wallet named by Google in October 2025 has continued posting payloads, 251 in total, with the most recent on 8 September 2026. Bitquery estimates the whole setup cost around $85 in gas fees.

## Why this matters

The danger is not greater destructive power. It is durability. Conventional attack infrastructure depends on servers and domains that hosting providers and law enforcement can seize or block. A public ledger cannot be switched off by any central authority, so instructions written to it remain reachable. Attackers can change their C2 servers simply by writing a new record, without reinfecting a single victim.

Blocking the traffic is also difficult. Blockchain RPC endpoints serve legitimate cryptocurrency services worldwide, so defenders cannot simply cut them off without collateral disruption. Chainalysis and others suggest that detection will increasingly depend on monitoring wallets, contracts and RPC traffic from corporate networks.

## The Firevault view

Blockchain dead drops are a reminder that takedown is not a strategy. If attacker infrastructure can survive every seizure, the only reliable control is to remove the path between the malware and the data it is sent to find.

Malware can only retrieve instructions and exfiltrate records from systems it can reach. Data held on [Offline Secure Storage](/offline-secure-storage)® is physically disconnected when not in use, so there is no network path for a dead-drop command to exploit, however permanent the ledger that carries it. Organisations should ask a simple question: which of our critical records would still be reachable if an implant on our network received new orders tomorrow?

## Sources

-   Chainalysis, "DPRK and Iran are Leading a 5.2x Surge YoY in Blockchain-Assisted Cyberattacks", 17 September 2026
-   Bitquery, "EtherHiding and Blockchain Malware, Measured On-Chain", 18 September 2026
-   Cyber Security Intelligence, "Hackers Fuel Blockchain Dead Drops", 21 September 2026
-   TechRadar Pro and Insurance Journal reporting, September 2026

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.cybersecurityintelligence.com/blog/hackers-fuel-blockchain-dead-drops-9752.html)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg)

Threat Analysis 

### Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery

Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.

22 Jun 2026 4 min 







](/news/scattered-spider-tfl-guilty-plea-offline-recovery)[

![UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fncsc-uk-cni-incidents-hero.jpg)

Threat Analysis 

### UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns

NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about three-quarters tied to state actors.

20 Jun 2026 5 min 







](/news/ncsc-uk-critical-infrastructure-incidents-double)[

![24 billion credentials exposed in record infostealer leak](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2F24bn-credentials-infostealer-hero.jpg)

Threat Analysis 

### 24 billion credentials exposed in record infostealer leak

Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from infostealer logs.

19 Jun 2026 4 min 







](/news/24-billion-credentials-infostealer-leak)[

![FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials](/__l5e/assets-v1/4b28b391-6cbf-4fc1-abad-5910c154bba8/news-fortibleed-fortinet-firewalls-hero-2x.jpg)

Threat Analysis 

### FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

18 Jun 2026 4 min 







](/news/fortibleed-74000-fortinet-firewalls-credentials-exposed)[

![OpenAI agent hacked Australian government Medicare portal, prime minister reveals](/news/openai-agent-medicare-portal-breach-australia-2026.jpg)

Artificial Intelligence 

### OpenAI agent hacked Australian government Medicare portal, prime minister reveals

An autonomous OpenAI agent gained unauthorised access to an Australian government Medicare statistics portal in June, accessing public and non-public files. The government says it was not told until September, and a forensic investigation is under way.

24 Sept 2026 4 min 







](/news/openai-agent-medicare-portal-breach-australia-2026)[

![FBI investigates claims that hackers stole personnel and applicant data](/news/fbi-employee-applicant-data-breach-shinyhunters-2026.jpg)

Breach Analysis 

### FBI investigates claims that hackers stole personnel and applicant data

The FBI is investigating unauthorised activity affecting its recruitment website after ShinyHunters claimed it stole sensitive records on current and former personnel and job applicants. The claimed scale remains unconfirmed.

22 Sept 2026 4 min 







](/news/fbi-employee-applicant-data-breach-shinyhunters-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)