State Sponsors Drive Onchain Malware Surge Amid Rising AI-Powered Threats
State-sponsored hackers are increasingly using public blockchains to store malware instructions and infrastructure information, leading to a 420% surge in onchain malware over the past year. According to a recent report by Chainalysis, North Korea- and Iran-linked operators have been among those adopting this technique.
One notable example cited by Chainalysis involves a group linked to UNC5342, a North Korea-linked entity tracked by Google Threat Intelligence. The group used encoded pointers in transactions on the Tron and Aptos blockchains to direct infected devices to a BNB Smart Chain (BSC) transaction containing encrypted server addresses and configuration data.
Chainalysis notes that using public blockchains makes malware campaigns more durable, as the stored information remains accessible even if domains, servers, or code repositories are taken down. This technique is not new, as North Korean hackers used a similar method called EtherHiding in 2025 to place crypto-stealing code in smart contracts.
The report also highlights a 440% increase in malicious blockchain writes since July 2025, when high-capacity open-source Chinese AI models became capable of producing malicious code with limited safeguards. While Chainalysis could not confirm whether the actors publishing these transactions had used these models to increase their output, the association between the two events is clear.
Another example cited by Chainalysis involves threat actors suspected of being linked to Iran's Ministry of Intelligence writing encoded command-and-control routing data onto the Bitcoin blockchain. The attackers used a well-known Bitcoin address with historical ties to Satoshi Nakamoto as a permanent public location for infected devices to retrieve updated directions.