Blockchain Dead Box Attacks Increase by 420%, State Owned Actors Lead Activities
According to the Chainalysis report, the number of attacks using blockchain dead mailboxes to store malicious payloads has increased by 420% in the past 12 months, with daily malicious writes rising from 2.06 to 11.1. More than 15 activities have been identified on five major public chains. As of the second quarter of 2026, national actors accounted for two-thirds of the newly added activities. Among them, North Korea's UNC5342 will launch targeted attacks on encryption developers from February 2025, using TRON, Aptos, and BSC; Iranian intelligence agency affiliates have been using Bitcoin OP-RETURN to encode data since the end of 2024; Russian criminal gangs operate a malware as a service model on Polygon.