How do Chinese open-source AI models drive the 440% spike in blockchain dead drops?

Unrestricted Chinese open-source AI models are fueling a 440% surge in blockchain-hosted malware commands, known as 'blockchain dead drops' (BDDs). By automating the generation of malicious code, state-linked actors from North Korea and Iran have increased daily on-chain malicious writes from 2.06 to 11.1 in less than a year.
How do Chinese open-source AI models drive the 440% spike in blockchain dead drops?

A 2026 report from Chainalysis reveals that the proliferation of unrestricted Chinese open-source AI models is directly responsible for a 440% increase in malicious instructions hosted on public blockchains. These AI tools allow hackers to rapidly generate and deploy 'blockchain dead drops' (BDDs), a technique where malware retrieves its command-and-control (C2) instructions from transaction metadata. This method exploits the immutability of the blockchain, making it nearly impossible for cybersecurity firms to take down the instructions once they are published on-chain.

The activity has escalated significantly, with daily malicious writes jumping from a baseline of 2.06 to 11.1 over the last several months. Unlike traditional malware that relies on centralized servers—which can be seized by law enforcement—BDDs use the decentralized nature of crypto ledgers to ensure that infected systems can always receive new orders. Chainalysis identifies state-linked operators from North Korea and Iran as the primary drivers of this trend, utilizing the lack of safety guardrails in certain international AI models to bypass conventional security filters.

This development marks a critical shift in the geopolitical landscape of cyber warfare. The intersection of generative AI and blockchain technology has provided adversarial nations with a resilient infrastructure for cyberattacks that is difficult to regulate. While the volume of these transactions remains small relative to total network traffic, the high success rate of these persistent 'dead drops' poses a significant threat to enterprise security and the perceived safety of public ledgers.

For the crypto market, this trend likely invites stricter regulatory scrutiny regarding transaction metadata and the 'know-your-transaction' (KYT) responsibilities of validators and node operators. Investors should watch for potential US Treasury or OFAC guidance specifically targeting the addresses used by these state-linked actors. As AI continues to lower the barrier for sophisticated cybercrime, the industry may face increased pressure to develop on-chain filtering mechanisms to prevent blockchains from becoming permanent hosts for state-sponsored malware.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.