AI-Powered Malware Floods Blockchains, Sparking Crypto Security Fears
Malicious code is being embedded directly on blockchains at an alarming rate, thanks in part to open-source AI tools that have democratized the creation of harmful scripts. According to a Chainalysis report, blockchain-based malware incidents have surged by 440% over the past year, with average daily cases of 'blockchain dead drops' (BDDs) climbing from two per day to eleven.
The technique, known as BDDs, involves hackers embedding malicious code or command instructions directly within blockchain transactions and smart contracts. Because blockchains are designed to be permanent and tamper-proof, these instructions sit there waiting to be retrieved, often at a low cost of around $2 per transaction.
State-linked hacking groups, particularly those tied to North Korea and Iran, account for approximately two-thirds of all new BDD activity. The use of open-source AI tools has made it easier for attackers to generate, obfuscate, and optimize their code, making the technique more accessible than ever before.
The growth in BDDs poses a significant threat to the crypto ecosystem, as compromised developer tools, infected smart contracts, and tainted code libraries can cascade through DeFi protocols and dApps, eventually reaching end users and their funds. The industry has yet to address this challenge without undermining the core value proposition of public blockchains.