Blockchain Malware Commands Skyrocket 440% With AI-Powered Hacking
Chinese open-source AI models have given hackers an unprecedented boost in storing and executing malware on blockchains. According to Chainalysis, daily malicious on-chain writes increased by a staggering 440% since these models were unleashed in mid-2025. This has led to a surge in 'blockchain dead drops' (BDDs), where attackers store payloads in on-chain transactions and smart contracts that infected devices can retrieve on demand.
The permanence of blockchains allows threat actors to maintain their cyber campaigns' longevity, even if their command-and-control (C2) relayer is seized or shut down. This technique has been around since 2013, but the recent explosion in usage is attributed to the ease of writing malicious code without any guardrails.
State-linked groups from North Korea and Iran are now responsible for most of the activity, with Pyongyang's UNC5342 running a three-chain relay across TRON (TRX), Aptos (APT), and BNB Smart Chain. Russian-language criminals also sell this capability as a service, with one operator wallet on Polygon (POL) controlling a fleet of resolver contracts.