Chainalysis reports that state-linked hackers, particularly those tied to North Korea and Iran, are increasingly using public blockchains to maintain malware infrastructure, accounting for roughly two-thirds of new blockchain-dead-drop activity by Q2 2026. Malicious blockchain writes surged 440% from 2.06 to 11.1 per day after the emergence of high-capacity open-weight AI models, which lowered the expertise required to build such infrastructure. This shift poses new security challenges for crypto companies and developers, as traditional takedowns are ineffective against malware instructions stored on public chains.