Blockchain Malware Surges 440% as AI Fuels State-Backed Hacking
Blockchain-based malware activity has surged by an alarming 440% in less than a year, largely due to the proliferation of artificial-intelligence coding tools that have lowered the barrier for state-backed hackers and smaller operators alike.
The trend is particularly concerning as groups tied to North Korea and Iran now account for roughly two-thirds of newly observed blockchain-dead-drop activity each quarter, with Chainalysis tracking such activity across five major networks and over a dozen named malware strains.
North Korean-linked operators have taken advantage of the new landscape by implementing cross-chain redundancy, using TRON and Aptos as redundant routes into BNB Smart Chain to make their malware campaigns more resilient. Meanwhile, Iranian actors have embedded command-and-control routing information inside Bitcoin transactions sent to a well-known address historically associated with Satoshi Nakamoto.
The same AI-powered tools that have facilitated this surge in blockchain-based malware activity also enable smaller operators and Russian-language criminal groups to deploy smart contracts on Polygon as command resolvers, further complicating the security landscape.