North Korea, Iran Linked to Surge in Blockchain Malware Activity
Chainalysis said state-backed groups now account for about half of malicious blockchain writes as attackers use public chains for hard-to-remove command data.
- On Thursday, Chainalysis reported that state-linked actors now account for 51% of malicious blockchain writes, with such activity rising 420% over the past 12 months.
- Open-Weight Chinese AI models like Kimi and Qwen3-Coder have 'removed the barrier to entry' for attackers since mid-2025, driving malware instructions from 2.06 to 11.1 per day.
- Attackers embed command-server addresses in smart contracts on Bitcoin, Tron, and BNB Chain using a 'blockchain dead drop' method that evades traditional domain and server take-downs.
- Google Threat Intelligence tracks the North Korea-linked group UNC5342 across Tron and Aptos, while operators suspected to be Iran-linked hide routing data within the Bitcoin blockchain.
- Defenders cannot block this malicious traffic without disrupting legitimate public endpoints, as one transaction simultaneously redirects every compromised machine, making these campaigns persistent and difficult to seize.
22 Articles
22 Articles
Hackers Are Hiding More Malware Instructions On Blockchains. AI Has Helped Drive A 440% Surge.
Malicious blockchain activity jumped from about two writes a day to more than 11 after powerful open-source AI models lowered technical barriers for attackers.
North Korea Drives Onchain Malware Surge, CoinEx Shuts: Asia Express
State hackers drive 420% surge in onchain malware, Chainalysis finds North Korean and Iran linked hackers were responsible for the majority of the 420% increase this year in malware on public blockchains according to a Chainalysis report. State-linked hackers accounted for roughly two-thirds of new activity whereby attackers stored malware instructions or infrastructure information on […]
Chainalysis Says State Hackers Now Write Half of the Malware Hidden on Blockchains
Chainalysis says state-backed operators now account for about half of the malicious code written to public chains, storing command-server addresses in smart contracts and transaction data that no registrar or host can take down.
Coverage Details
Bias Distribution
- 80% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium












