Hackers hide malware commands in blockchains as malicious activity jumps 440%
Chainalysis reports a 440% rise in malicious blockchain activity, with daily entries growing from 2.06 to 11.1 after open AI models emerged. Attackers use transactions and smart contracts as dead drops that survive server takedowns.
- Malicious blockchain activity rose 440% after high-capacity open AI models appeared
- North Korea-linked UNC5342 uses TRON, Aptos and BNB Chain to deliver commands
- Iranian and Russian-speaking actors use Bitcoin and Polygon for malware infrastructure
- State-linked groups accounted for two-thirds of new activity in Q2 2026
Read next
Security