Skip to content
Surge in Blockchain Dead Drops Driven by AI Models

Surge in Blockchain Dead Drops Driven by AI Models

First seen 17 Sep 2026, 16:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 18:24 UTC
  • Blockchain dead drops have surged 440% since mid-2025 due to AI advancements.
  • State-linked actors from North Korea and Iran dominate this new attack vector.
  • Traditional cybersecurity measures are struggling to detect on-chain malicious activities.

Cyber threat actors have significantly increased the use of blockchain dead drops (BDDs) to hide malware instructions, with a 440% surge in activity since mid-2025, attributed to unrestricted Chinese open-source AI models. This technique allows attackers, particularly state-linked groups from North Korea and Iran, to store malicious payloads on public blockchains, making them difficult to disrupt. The average daily malicious on-chain writes rose from 2.06 to 11.1, with state actors now accounting for two-thirds of this activity. The BDD method enhances campaign durability by allowing communication with compromised devices without fear of takedowns. Notable incidents include the Glupteba campaign, which has evolved to exploit vulnerabilities in network routers and utilize Bitcoin transactions for command and control. The rise in BDDs poses a growing challenge for cybersecurity, as traditional threat intelligence platforms struggle to detect on-chain activities. Overall, the combination of AI advancements and blockchain technology has created a new landscape for cyber threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-06-24
First public PoC for CVE-2018-14847
CVE-2018-14847, a vulnerability affecting MikroTik routers, was publicly demonstrated.
Trend Micro
2023-08-02
CVE-2018-14847 published
CVE-2018-14847 was officially published, detailing a vulnerability in MikroTik routers.
Trend Micro
2025-01-05
Chinese AI models released
Unrestricted Chinese open-source AI models launched, enabling easier generation of malicious code.
Chainalysis
2026-08-01
ChainDrop supply chain attack
The ChainDrop attack impacted over 440 npm packages, showcasing the escalating risks in crypto security.
Tech.Yahoo
2026-09-17
Chainalysis report on BDDs
Chainalysis reported a 440% increase in blockchain dead drops, primarily driven by state actors.
Chainalysis

More articles in this cluster (12)

Following this threat?

Track Unc5342, ClearFake and Polygon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed