Blockchain "dead drop" attacks storing malicious payloads and command configurations in on-chain transactions have increased approximately 420% over the past 12 months, according to a new Chainalysis report. Average daily malicious writes rose from 2.06 to 11.1, with more than 15 distinct campaigns identified across five major public chains. State-backed actors now account for roughly two-thirds of this activity as of Q2 2026. North Korea’s UNC5342 has targeted crypto developers via fake job offers using TRON, Aptos, and BSC since February 2025, while Iranian-linked entities have utilized Bitcoin OP_RETURN fields for data encoding since late 2024. Additionally, Russian-speaking criminal groups are operating malware-as-a-service models on the Polygon network.