Crypto World

Chinese AI Models Drive 440% Jump in Blockchain-Hosted Malware Commands

Published

on

Attackers are posting malware instructions to blockchains 440% more often since unrestricted Chinese open-source AI models arrived, Chainalysis reported. Daily malicious on-chain writes climbed from 2.06 to 11.1 in under a year.

Chainalysis calls the technique blockchain dead drops (BDDs). State-linked operators from North Korea and Iran now generate most of the activity, the firm found.

Censorship Resistance Turns Into a Hacking Asset

In its latest report, Chainalysis noted that hackers stored malicious code on centralized servers that could get seized, blocked, or pulled offline. However, now attackers store them on public blockchains.

“We call this technique ‘blockchain dead drops’ (BDD). BDDs store payloads in on-chain transactions and smart contracts where infected devices can retrieve them on demand. The permanence of blockchains gives threat actors’ cyber campaigns longevity; they can communicate with compromised machines without fear of losing their command-and-control (C2) relayer,” the report read.

The firm stresses that the danger lies in durability, not firepower. Campaigns survive domain seizures, hosting takedowns, and repository removals. The technique dates to 2013, when a Necurs botnet variant stored domains on a Bitcoin (BTC) fork called Namecoin. 

Advertisement

It reached Ethereum Virtual Machine (EVM) chains in 2023 as EtherHiding. Google later caught North Korea’s UNC5342 using it in fake job interviews.

Chainalysis pins the recent explosion to mid-2025. That is when powerful open-weight Chinese models launched with no guardrails against writing malicious code. That erased the skill barrier that once kept dead drops rare, the firm said.

The spread now reaches well beyond crypto. Netskope researchers say the ChainDrop supply chain attack hit more than 440 npm packages in August 2026. 

Follow us on X to get the latest news as it happens

Advertisement

Pyongyang, Tehran, and Russian Forums Write Their Own Playbooks

Cybercriminals accounted for nearly all dead drop activity through early 2024. By Q2 2026, state-linked groups produced roughly two-thirds of new activity each quarter and half the total.

Blockchain Dead Drop Threat Actors. Source: Chainalysis

North Korea’s UNC5342 now runs a three-chain relay. Pointers on TRON (TRX) and Aptos (APT) steer infected devices to encrypted devices on BNB Smart Chain.

“The attacker rotates infrastructure by publishing new transactions, and every previously infected device picks up the change automatically. Disrupting the operation would require action across all three chains simultaneously,” the team noted.

Suspected Iranian intelligence operators send tiny Bitcoin payments to a well-known address linked to Satoshi Nakamoto. Chainalysis said the malware searches for data inside each transaction, then decodes it to retrieve the current attacker infrastructure. 

Russian-language criminals, meanwhile, sell the capability as a service. One operator wallet on Polygon (POL) controls a fleet of resolver contracts, each apparently serving a different paying customer. 

Defenders cannot simply block blockchain traffic without breaking every legitimate wallet and app, the report noted. The same permanence that shelters attackers, however, leaves every update on a public ledger. 

Advertisement

Whether investigators can turn that trail into arrests faster than AI tools mint new operators is the open question.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

The post Chinese AI Models Drive 440% Jump in Blockchain-Hosted Malware Commands appeared first on BeInCrypto.

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version