State hackers drive 420% surge in onchain malware, Chainalysis finds
Chainalysis reports a 420% rise over the last year in instances where attackers embed malware instructions or infrastructure pointers on public blockchains, with state-linked groups responsible for about two-thirds of new activity each quarter. The analytics firm tied North Korea-linked UNC5342 to coordinated writes across Tron, Aptos and BNB Smart Chain, and identified suspected Iran-linked operators writing command-and-control routing data into Bitcoin transactions.

Why It Matters
Storing malware routing and configuration data on blockchains makes campaigns more resilient to takedowns because on-chain records persist after servers or domains are removed. The rise of accessible AI code models coincides with a sharp uptick in malicious blockchain writes, raising concerns about scaling of these techniques.
Key Facts
- Increase in onchain malware writes: 420% rise over the past 12 months
- Share by state-linked actors: Roughly two-thirds of new activity each quarter attributed to state-linked hackers
- North Korea-linked group: UNC5342 linked to activity spanning Tron, Aptos and BNB Smart Chain (BSC)
- Technique observed: Encoded pointers in Tron and Aptos transactions directed devices to a BSC transaction containing encrypted server addresses and configuration data
- Prior similar technique: North Korean actors used 'EtherHiding' in 2025 to embed crypto-stealing code in smart contracts
Chainalysis says the number of times attackers have written malware instructions or infrastructure information to public blockchains climbed 420% over the last year, with state-linked threat actors accounting for about two-thirds of newly attributed activity each quarter. The analytics firm linked activity on multiple chains — Tron, Aptos and BNB Smart Chain — to UNC5342, a group previously associated with North Korea by Google Threat Intelligence. According to Chainalysis, encoded pointers placed in Tron and Aptos transactions led infected machines to the same BSC transaction; Tron served as the initial route while Aptos functioned as a fallback. That BSC transaction held encrypted server addresses and configuration details that paired compromised devices with offchain infrastructure used for remote access and data exfiltration. The firm noted this approach increases the durability of malware campaigns because the on-chain data remains accessible even after traditional infrastructure takedowns. Chainalysis also reported a 440% increase in malicious blockchain writes since July 2025, a period it links to the availability of high-capacity open-source Chinese AI models capable of generating malicious code with few safeguards. Eric Jardine, the company’s cybercrimes research lead, told Cointelegraph the firm observed a clear temporal association between the AI models’ availability and the spike in writes but could not confirm the attackers used those models to scale their activity. Separately, Chainalysis identified activity it assesses as connected to actors suspected of ties to Iran’s Ministry of Intelligence, who embedded encoded command-and-control routing data on the Bitcoin blockchain. In that campaign, attacker-controlled wallets made small payments to a long-standing Bitcoin address with historical links to Satoshi Nakamoto; Chainalysis said the address itself was not controlled by the attackers but served as a permanent public location that infected devices could query for updated directions. Once devices retrieved the on-chain instructions, subsequent operations moved offchain and could include remote access, credential theft and delivery of further malware.
Keep Reading

How Circle’s institutional Arc blockchain got taken over by memecoins on day one

Zcash miner Fortitude names former Hut 8 chief Jaime Leverton CEO ahead of Nasdaq deal

Ethereum’s upcoming Glamsterdam upgrade clears rehearsal for a big jump in capacity

SEC rolls out long-awaited 'innovation exemption' for tokenized securities venues
Original source: Cointelegraph