The report details a technique the researchers call Blockchain Dead Drops (BDD). Instead of storing malicious payloads on servers that can be disrupted, attackers store them on public blockchains, where data is public, immutable and replicated worldwide. Infected devices retrieve the payloads on demand.
This durability is what makes BDD dangerous. Because blockchain data cannot easily be removed, takedowns become immensely difficult. Threat actors can use the infrastructure for command and control without worrying about domain seizures, repository removals, hosting takedowns or other disruptions.
The report identifies two main storage approaches. In transaction-based storage, attackers embed command-and-control configurations, payload references or infrastructure pointers inside blockchain transactions, in fields such as memos or calldata, on a single chain or across several. In contract-based storage, smart contracts hold the data, with the contract's state containing the current C2 pointer. This is the model behind EtherHiding, where malware queries the contract for up-to-date information while the attacker's visible on-chain activity is limited to deploying and periodically updating the contract.
BDD is used in two kinds of setups. In command-and-control configurations, the on-chain data holds configuration information, such as domains or IP addresses, that directs compromised devices to the attacker's current infrastructure off-chain. In payload-delivery setups, malicious code or encrypted payload components are stored on-chain for victim machines to retrieve and execute locally. In both cases, the actual compromise moves off-chain, and can involve infostealers targeting crypto wallets and credentials, or remote access trojans that give attackers persistent control over systems.
Chainalysis also links the rise in attacks to the widespread availability of Chinese open-source AI tools, which the report says have significantly lowered the technical barrier to entry for cybercrime, allowing less experienced attackers to launch complex attacks. The report puts the increase in BDD attacks at 440%.