Overview
- Chainalysis reported in September 2026 that malicious blockchain writes rose roughly 420–440%, increasing from about 2 per day to about 11 per day as attackers posted malware instructions on public chains.
- Groups linked to North Korea and Iran now drive most new activity, with state-linked operators accounting for roughly two thirds of new quarterly cases by mid-2026 and about half of all tracked operations.
- Attackers store malware payloads, command-and-control pointers, or resolver contracts inside transactions and smart contracts so infected devices can fetch updated instructions even after servers or domains are taken down.
- Operators are using cross-chain redundancy and permanent on-chain references — for example UNC5342 routing through TRON and Aptos into BNB Smart Chain and Iran-linked actors embedding C2 pointers in Bitcoin transactions — to make campaigns resilient.
- Defenders face limited options because on-chain records are permanent, so practical mitigation focuses on mapping wallets and contracts, filtering at RPC and API providers, and increased continuous surveillance rather than broad protocol changes.