{"slug": "hackers-are-hiding-more-malware-instructions-on-blockchains-ai-has-helped-drive", "title": "Hackers Are Hiding More Malware Instructions On Blockchains. AI Has Helped Drive A 440% Surge.", "summary": "Malicious instructions and infrastructure information written onto public blockchains have increased 440% since the emergence of high-capacity Chinese open-source AI models without restrictions on generating malicious code, according to research published Thursday by Chainalysis. The average rose from 2.06 malicious blockchain writes a day to 11.1 in less than a year, and Chainalysis said state-linked operators now account for roughly two-thirds of new blockchain dead-drop activity each quarter and about half of overall activity by the second quarter of 2026. Chainalysis head of research Eric Jardine told Bloomberg that blockchains are not used to infect devices initially but can deliver instructions to malware after a computer is compromised through malicious downloads or supply-chain attacks.", "body_md": "# Hackers Are Hiding More Malware Instructions On Blockchains. AI Has Helped Drive A 440% Surge.\n\n## Malicious blockchain activity jumped from about two writes a day to more than 11 after powerful open-source AI models lowered technical barriers for attackers.\n\nHackers are increasingly using public blockchains to store instructions for malware, combining artificial intelligence with technology designed to make data difficult to alter or remove as cybercrime targeting the cryptocurrency industry continues to grow.\n\nMalicious instructions and infrastructure information written onto blockchains have increased 440% since the emergence of high-capacity Chinese open-source AI models without restrictions on generating malicious code, [Chainalysis](https://www.chainalysis.com/blog/etherhiding-blockchain-dead-drops/) said in research published Thursday. The average increased from 2.06 malicious blockchain writes a day to 11.1 in less than a year, while the increase measured over the past 12 months was 420%.\n\nUsing a technique that Chainalysis calls a \"blockchain dead drop,\" or BDD, attackers place information in blockchain transactions and smart contracts that malware running on an infected device can retrieve. That allows them to avoid relying entirely on conventional command-and-control servers that authorities or cybersecurity companies can shut down, while taking advantage of blockchain records that are difficult to remove.\n\nAlthough blockchains generally are not used to infect a device in the first place, they can provide instructions to malware after a computer has already been compromised through methods such as malicious downloads or supply-chain attacks, Eric Jardine, head of research at Chainalysis, told [Bloomberg](https://uk.finance.yahoo.com/news/ai-helps-hackers-open-front-120000950.html/). The company is now tracking BDD activity across five major blockchains and more than a dozen named malware strains.\n\nWhile blockchain dead drops have existed for years, their use has expanded sharply alongside the latest generation of AI models. Chainalysis traced an early example to 2013, when a variant of the Necurs botnet stored command-and-control domains on Namecoin, a Bitcoin fork, with similar activity later appearing on Ethereum-compatible blockchains through techniques including EtherHiding.\n\nAfter powerful open-weight Chinese AI models became widely available in mid-2025, the average number of malicious blockchain writes began climbing more rapidly, Chainalysis said. Because those models can be downloaded and operated independently, users can modify them without relying on safeguards imposed by commercial AI providers, reducing some of the technical expertise previously required to build blockchain-based command-and-control infrastructure.\n\n\"This gives malicious developers greater control over the model and more privacy,\" Vitaly Kamluk, founder of cybersecurity consultancy TitanHex, told Bloomberg.\n\nCommercial AI services operate under a different structure because their providers retain control over access and can restrict accounts when abuse is detected. Open-weight models, by contrast, can be downloaded and run independently, leaving their original developers with little control over how individual copies are modified or used.\n\nState-linked operators have also taken a growing role in blockchain dead-drop activity, accounting for roughly two-thirds of new BDD activity each quarter and about half of overall activity by the second quarter of 2026, [Chainalysis](https://www.chainalysis.com/blog/etherhiding-blockchain-dead-drops/) found. Groups linked to North Korea and suspected Iranian state actors have used different versions of the technique in their cyber operations.\n\nActors suspected of ties to Iran's Ministry of Intelligence began embedding command-and-control information in Bitcoin transactions in late 2024, placing encoded routing information where infected devices could retrieve it and locate attacker-controlled infrastructure. North Korean operators later began using EtherHiding in early 2025 as part of fake job interview campaigns targeting cryptocurrency developers.\n\nOne North Korean group identified by Google Threat Intelligence Group as UNC5342 used smart contracts on public blockchains to deliver malware to victims approached by bogus recruiters, Chainalysis said. The tactic fits into a broader pattern of North Korean operations targeting cryptocurrency companies, developers and digital assets.\n\nIranian cyber activity has also drawn fresh attention during the continuing Middle East conflict, with governments tracking operations attributed to Tehran-linked groups beyond the cryptocurrency sector. Britain, the United States and the Netherlands issued a joint cybersecurity advisory this week detailing spyware attributed to Iranian state-linked actors that targeted dissidents, activists and journalists through spear-phishing campaigns on services including WhatsApp and Telegram, [Reuters](https://www.reuters.com/world/uk-us-netherlands-issue-advisory-iran-spyware-2026-09-15/) reported Tuesday.\n\nNorth Korea, meanwhile, remains one of the largest state-linked sources of cryptocurrency theft, with its hackers repeatedly targeting exchanges, protocols and crypto companies. North Korea-linked activity accounted for about $643 million, or roughly two-thirds of cryptocurrency stolen during the first half of 2026, according to [TRM Labs](https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion).\n\nAcross the crypto industry, the number of hacks jumped roughly 150% to 207 during the first six months of 2026 from 83 during the same period a year earlier, [TRM Labs](https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion) found. Total losses fell to $972 million from $2.3 billion in the first half of 2025 because the period included fewer exceptionally large thefts.\n\n© Copyright IBTimes 2026. All rights reserved.", "url": "https://wpnews.pro/news/hackers-are-hiding-more-malware-instructions-on-blockchains-ai-has-helped-drive", "canonical_source": "https://www.ibtimes.com/hackers-are-hiding-more-malware-instructions-blockchains-ai-has-helped-drive-440-surge-3807580", "published_at": "2026-09-18 10:39:01+00:00", "updated_at": "2026-09-18 10:54:19.611185+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "large-language-models", "ai-policy"], "entities": ["Chainalysis", "Eric Jardine", "Bloomberg", "Vitaly Kamluk", "TitanHex", "North Korea", "Iran Ministry of Intelligence", "Necurs"], "alternates": {"html": "https://wpnews.pro/news/hackers-are-hiding-more-malware-instructions-on-blockchains-ai-has-helped-drive", "markdown": "https://wpnews.pro/news/hackers-are-hiding-more-malware-instructions-on-blockchains-ai-has-helped-drive.md", "text": "https://wpnews.pro/news/hackers-are-hiding-more-malware-instructions-on-blockchains-ai-has-helped-drive.txt", "jsonld": "https://wpnews.pro/news/hackers-are-hiding-more-malware-instructions-on-blockchains-ai-has-helped-drive.jsonld"}}