State Hackers Now Write Most of the Malware Hidden on…

3

Blockchain malware, the instructions hackers hide inside public-blockchain transactions, rose about 440% in under a year, and state-linked groups from North Korea and Iran now account for most of it, according to a Chainalysis report published Thursday and first detailed by Bloomberg. Daily malicious on-chain writes climbed from about two to eleven over the period, a jump Chainalysis ties to the mid-2025 arrival of powerful Chinese open-source AI models with no guardrails against generating malicious code. The technique turns the permanence that makes blockchains useful into a weapon, giving state cyber campaigns a command channel that cannot be shut down.Chainalysis calls the method a blockchain dead drop. Rather than hosting blockchain malware on a server that police can seize or a domain that can be revoked, attackers embed the payload, or a pointer to it, inside an on-chain transaction, where infected machines fetch it on demand. “The permanence of blockchains gives threat actors’ cyber campaigns longevity; they can communicate with compromised machines without fear of losing their command-and-control relayer,” the firm wrote, as quoted by BeInCrypto. Once written to a public ledger, that instruction stays reachable no matter how many servers are taken down. Nation-state actors have overtaken cybercriminal groups, producing 51% of attributed blockchain dead-drop writes by the second quarter of 2026. Data: Chainalysis, via Bloomberg · Chart: FinanceFeeds.

Inside the Three-Chain Relay North Korea Uses to Hide Blockchain Malware

Attackers write encoded pointers or configuration data into transactions and smart contracts, and their malware scans those transactions, decodes the embedded data, and uses it to locate the off-chain servers that run the attack. The blockchain never does the hacking itself; it acts as an indestructible bulletin board that tells already-infected machines where to go next. When defenders take down a server, the operators publish a new on-chain transaction, and every infected device picks up the change automatically.North Korea’s UNC5342, a group tracked by Google Threat Intelligence, shows how sophisticated this has become. Chainalysis connected previously unattributed activity across Tron, Aptos and BNB Smart Chain to the group, with pointers on Tron and Aptos steering infected devices to an encrypted BNB Smart Chain transaction that held the server addresses. Tron served as the primary route and Aptos as a fallback, so, in the firm’s words, “disrupting the operation would require action across all three chains simultaneously.” Suspected Iranian operators used a variation, writing tiny Bitcoin payments to an address historically tied to Satoshi Nakamoto and hiding routing data inside them.

State Hackers Wrote 51% of Blockchain Malware in 2026

The report’s starkest finding is the shift in who uses this method. Cybercriminals accounted for nearly all blockchain malware activity through early 2024, but by the second quarter of 2026 state-linked groups produced roughly two-thirds of new activity each quarter and about half of all attributed writes, crossing to 51% versus 49% for criminal groups, according to the Chainalysis data reported by Bloomberg. That crossover matches a broader pattern in which nation-states have come to dominate crypto crime.TRM Labs has attributed about 76% of all crypto hack value in early 2026 to North Korea, and CrowdStrike estimated state-affiliated hackers drove more than $2 billion in crypto losses in 2025, a 51% year-on-year jump. The same actors are widening their reach through foreign remote workers hired to infiltrate US companies before handing the access to operatives.The technique is not new, only newly common. Chainalysis traced early versions to Namecoin in 2013 and to Ethereum-based chains in 2023 under the name EtherHiding, which Google later caught North Korea’s UNC5342 using in fake job interviews, as BeInCrypto noted. What changed is the barrier to entry, and that is where the artificial intelligence comes in.

Investor Takeaway

The danger is durability rather than firepower, because a blockchain malware instruction written to a public network cannot be taken down the way a server or domain can, which extends the life of any campaign that uses it.

Unrestricted Chinese AI Models Erased the Skill Barrier

The 440% jump has a specific trigger in the report’s telling. Chainalysis dated the surge to mid-2025, when high-capacity Chinese open-source AI models launched without restrictions on producing malicious code, erasing the skill barrier that had kept blockchain malware rare, Bloomberg reported. Unlike cloud models that OpenAI or Google can bar from harmful use, open-weight models can be downloaded and modified locally to strip out safeguards, so an attacker can generate the code to write and read on-chain payloads without any technical gatekeeper standing in the way.Cybercrimes research lead Eric Jardine described a “clear point-in-time association” between the models’ availability and the spike, while stressing the firm could not prove operators had directly used those models to increase their output, in comments to Cointelegraph. The wider spread is already visible beyond crypto, with a supply-chain incident in August affecting more than 440 npm software packages, and it fits North Korea’s turn toward offline and AI-assisted tooling for more sophisticated attacks.

Investor Takeaway

Open-weight AI models are the enabling variable here, because their lack of guardrails removed the expertise once needed to build these attacks, which is why the volume rose so sharply so fast.

Close
Your custom text © Copyright 2020. All rights reserved.
Close