Blockchain-based malware infrastructure is expanding rapidly as crypto businesses face mounting security and compliance pressures. Chainalysis says Blockchain Dead Drop activity has increased 420% over the past 12 months, while separate developments have pushed CoinEx into an orderly shutdown after nine years of exchange operations. The two trends are not directly linked, but they illustrate different layers of operational risk across the crypto sector.
Chainalysis describes Blockchain Dead Drops, or BDDs, as onchain locations where malware retrieves command-and-control instructions, payload references or infrastructure pointers. By Q2 2026, state-linked groups represented roughly two-thirds of new BDD activity each quarter and half of total observed activity, with researchers identifying campaigns connected to North Korean and suspected Iranian state operators.
State-Linked Hackers Move Malware Onchain
One North Korean-linked campaign used TRON and Aptos transactions as redundant pointers leading infected devices to malicious instructions stored on BNB Smart Chain. The multi-chain design makes command infrastructure harder to disrupt because defenders would need to interfere with several independent blockchain paths simultaneously. Chainalysis connected the activity to UNC5342, a group previously tracked by Google Threat Intelligence Group.
Researchers also identified suspected Iranian operators using Bitcoin’s OP_RETURN field to publish encoded routing information. The blockchain acts as a persistent lookup layer rather than carrying out the eventual compromise itself, with infected machines retrieving instructions onchain before connecting to off-chain infrastructure for remote access or data theft.
Chainalysis links part of the acceleration to increasingly capable open-source AI coding tools. BDD activity has risen 440% since the emergence of high-capacity open-weight models that can generate malicious code without comparable restrictions, although that correlation does not establish AI as the sole cause of the growth.
CoinEx Begins Its Final Wind-Down
Separately, CoinEx began a phased shutdown on September 15, citing prolonged crypto-market weakness, shrinking trading volumes and liquidity, rising regulatory requirements and escalating compliance costs. The exchange will stop spot trading on September 29 and permanently close the platform on December 22, while withdrawals remain available through the final date.
CoinEx has also faced significant historical security and compliance scrutiny. Elliptic estimated that roughly $54 million was stolen from CoinEx in September 2023 and identified transaction patterns suggesting Lazarus Group involvement. Separately, TRM Labs traced more than $3.84 billion in flows between CoinEx and sanctioned Iranian entities over seven years, including $2.7 billion involving Nobitex.
Those findings should not be treated as established causes of CoinEx’s closure. CoinEx itself attributes the decision to market conditions, liquidity contraction, regulatory requirements and operating uncertainty, while maintaining that user assets are more than 100% reserved. The immediate security lesson is broader: persistent onchain malware increases the importance of blockchain-specific threat monitoring, while centralized venues simultaneously face rising costs around custody, sanctions screening and compliance.
