State-Sponsored Hackers Build Malware Infrastructure on Public Blockchains
State-sponsored hackers have started using public blockchains as their attack infrastructure to host malware payloads and command-and-control instructions. According to Chainalysis's 2026 Crypto Crime Report, North Korea-linked threat actors have been deploying malware on Tron, Aptos, and BNB Chain, taking advantage of the immutability and censorship-resistance of blockchain technology.
The report reveals that these hackers are no longer just stealing crypto; they're building their attack infrastructure directly on top of it. By embedding malware instructions in transactions, they can ensure that their commands are executed without raising suspicion from network monitors.
Iran-linked actors have also been using Bitcoin's ledger to embed operational directions within transactions themselves. Since Bitcoin's ledger is permanent and publicly accessible, these embedded commands can be read by malware agents anywhere in the world without being detected.
The numbers behind this threat are staggering: North Korean cyber groups stole approximately $2 billion in digital assets over 2025, a 51% increase compared to the prior year. The single largest contributor was the $1.5 billion Bybit exploit. Cumulative theft attributed to North Korea now exceeds $6.75 billion.