State-linked groups weaponizing public blockchains
Multiple Chainalysis reports paint a consistent picture: state-linked or state-sponsored cyber groups are increasingly using public blockchains as malware infrastructure, and the technical and financial scale of the activity has surged. Chainalysis documented a 420% rise in onchain malware activity and a 440% increase in malicious blockchain writes after mid-2025, when powerful open-weight Chinese AI models without guardrails became available. Daily malicious on-chain writes rose from 2.06 to 11.1 in under a year, a jump the firm attributes to the removal of the skill barrier for crafting and embedding payloads.
Actors have used several networks, including Tron, Aptos, BNB Chain, BNB Smart Chain and Bitcoin, to host payloads, pointers, and command-and-control (C2) routing. Chainalysis reported suspected Iran-linked operators embedding operational directions within Bitcoin transactions and sending tiny payments to a well-known address with historical ties to Satoshi Nakamoto; that address served as a permanent public retrieval point for infected devices to decode and update attacker infrastructure. North Korea-linked groups, including activity attributed to UNC5342, have been deploying payloads and multi-chain relays that steer compromised machines across chains so that disrupting the operation would require simultaneous action on multiple networks.
The findings intersect with broader illicit-finance data in the reports: Chainalysis estimates North Korea-linked actors stole roughly $2 billion in digital assets in 2025, a 51% year-over-year increase, with the $1.5 billion Bybit exploit as the single largest contributor. Cumulative theft attributed to North Korea now exceeds $6.75 billion. Total illicit cryptocurrency flows in 2025 reached at least $154 billion, up 162% year-over-year, and at least $104 billion in on-chain transactions went to sanctioned entities, a 694% increase; stablecoins dominated that volume. Researchers also trace the technique back to earlier cases such as Namecoin and EtherHiding, while noting that state-linked actors now produce a large share of new āblockchain dead dropā activity. The reports warn defenders that the permanence and censorship-resistance of public ledgers make these schemes durable: defenders cannot simply block blockchain traffic without disrupting legitimate wallets and apps, and detecting embedded instructions complicates compliance and investigative work.
Open-source AI fuels scaling
New items confirm and expand the earlier picture: Chainalysis reports link the availability of unrestricted Chinese openāsource AI models since midā2025 to an approximate 440% rise in malware instructions embedded on chains, with daily āblockchain dead dropā cases climbing from about two to eleven. The updates specify that roughly twoāthirds of new BDD activity is now attributable to stateālinked groups, and that many malicious onāchain transactions cost under $2 each. Notably, North Koreaālinked UNC5342 has extended operations using multiāchain relays that include TRON and Aptos in addition to earlier targets, meaning disruption would require coordinated action across networks. The reports also reiterate that openāsource modelsā local modifiability removes guardrails while onāchain transparency can nevertheless yield investigative clues.
This summary is composed by the cFlash AI agent from multiple public sources, under human supervision. The content is for informational purposes only and does not constitute investment, financial, legal, or tax advice.
Sources
-
š
Open-source AI is helping hackers hide malicious code directly on blockchainsā
-
š
Chainalysis Report: Open-Source AI Models Drive 440% Surge in Malware Instructions Written into On-Chain Transactions and Smart Contractsā
-
š§¾
Chinese AI Models Drive 440% Jump in Blockchain-Hosted Malware Commandsā
-
š
Chainalysis reports 420% surge in onchain malware linked to state hackersā
-
š°š·
State hackers drive 420% surge in onchain malware, Chainalysis findsā