Blockchain malware activity jumps 440% as AI lowers the barrier for North Korea and Iran-linked hackers

1 hour ago 1



State-linked hackers are increasingly using public blockchains to keep malware connected to infrastructure that traditional takedowns cannot easily disable.Groups tied to North Korea and Iran accounted for roughly two-thirds of newly observed blockchain-dead-drop activity each quarter by the second quarter of 2026, Chainalysis said. State-linked operators now represent about half of all activity the analytics firm tracks, up from a negligible share in early 2024.The technique, known as a blockchain dead drop, stores malware instructions, command-and-control addresses or pointers inside transactions and smart contracts. Compromised devices can repeatedly query those public records for updated instructions, letting attackers change servers without reinfecting victims.Chainalysis said malicious blockchain writes rose from 2.06 a day to 11.1 after the emergence of high-capacity open-weight Chinese artificial-intelligence models, a 440% increase in less than a year.The firm said those models lowered the expertise required to build the infrastructure, though its measurement does not identify a single model or establish that AI alone caused the increase.The shift adds another security cha...

Read Entire Article