← All stories
🦠

State-linked groups weaponizing public blockchains

Multiple Chainalysis reports paint a consistent picture: state-linked or state-sponsored cyber groups are increasingly using public blockchains as malware infrastructure, and the technical and financial scale of the activity has surged. Chainalysis documented a 420% rise in onchain malware activity and a 440% increase in malicious blockchain writes after mid-2025, when powerful open-weight Chinese AI models without guardrails became available. Daily malicious on-chain writes rose from 2.06 to 11.1 in under a year, a jump the firm attributes to the removal of the skill barrier for crafting and embedding payloads.

Actors have used several networks, including Tron, Aptos, BNB Chain, BNB Smart Chain and Bitcoin, to host payloads, pointers, and command-and-control (C2) routing. Chainalysis reported suspected Iran-linked operators embedding operational directions within Bitcoin transactions and sending tiny payments to a well-known address with historical ties to Satoshi Nakamoto; that address served as a permanent public retrieval point for infected devices to decode and update attacker infrastructure. North Korea-linked groups, including activity attributed to UNC5342, have been deploying payloads and multi-chain relays that steer compromised machines across chains so that disrupting the operation would require simultaneous action on multiple networks.

The findings intersect with broader illicit-finance data in the reports: Chainalysis estimates North Korea-linked actors stole roughly $2 billion in digital assets in 2025, a 51% year-over-year increase, with the $1.5 billion Bybit exploit as the single largest contributor. Cumulative theft attributed to North Korea now exceeds $6.75 billion. Total illicit cryptocurrency flows in 2025 reached at least $154 billion, up 162% year-over-year, and at least $104 billion in on-chain transactions went to sanctioned entities, a 694% increase; stablecoins dominated that volume. Researchers also trace the technique back to earlier cases such as Namecoin and EtherHiding, while noting that state-linked actors now produce a large share of new ā€œblockchain dead dropā€ activity. The reports warn defenders that the permanence and censorship-resistance of public ledgers make these schemes durable: defenders cannot simply block blockchain traffic without disrupting legitimate wallets and apps, and detecting embedded instructions complicates compliance and investigative work.

Open-source AI fuels scaling

New items confirm and expand the earlier picture: Chainalysis reports link the availability of unrestricted Chinese open‑source AI models since mid‑2025 to an approximate 440% rise in malware instructions embedded on chains, with daily ā€œblockchain dead dropā€ cases climbing from about two to eleven. The updates specify that roughly two‑thirds of new BDD activity is now attributable to state‑linked groups, and that many malicious on‑chain transactions cost under $2 each. Notably, North Korea‑linked UNC5342 has extended operations using multi‑chain relays that include TRON and Aptos in addition to earlier targets, meaning disruption would require coordinated action across networks. The reports also reiterate that open‑source models’ local modifiability removes guardrails while on‑chain transparency can nevertheless yield investigative clues.

This summary is composed by the cFlash AI agent from multiple public sources, under human supervision. The content is for informational purposes only and does not constitute investment, financial, legal, or tax advice.

Sources