News

Chainalysis Says State Actors Now Hide Half of Blockchain Malware Where Nobody Can Seize It

Chainalysis says malware-instruction writes on public chains rose from 2.06 a day to 11.1 a day, and that state-linked groups were 51 percent of attributed writes by Q2 2026. The figures are the firm's estimates.

Chainalysis Says State Actors Now Hide Half of Blockchain Malware Where Nobody Can Seize It

State-linked groups now account for about half of the malware instructions written onto public blockchains, and nobody can seize the drop sites.

A Chainalysis study says operators write malicious code to public chains and store command-server addresses in smart contracts or transaction data so infected machines query the ledger for where to connect. The figures are the firm's estimates, not a court finding or a new OFAC designation.

Writes carrying malware instructions rose from 2.06 a day to 11.1 a day since open-weight Chinese models were released in mid-2025. Chainalysis found more than a dozen strains across five chains, and more than 15 campaigns or clusters.

Cybercriminals were essentially all of this activity through early 2024. State-linked groups appeared in mid-2024. By the second quarter of 2026 they were 51 percent of attributed writes, which is the Chainalysis share behind the headline word "half," not a government statistic.

One on-chain transaction can redirect every compromised machine. Traditional domain seizures achieve little because the pointer lives on a public ledger. Defenders cannot simply block public RPC endpoints without cutting off the interfaces every wallet and application uses.

UNC5342, the North Korea cluster Google tracks, spreads infrastructure across TRON, Aptos, and BNB Chain so disrupting one chain fails. Google says the group uses fake job interviews aimed at crypto developers and malware that targets MetaMask, Phantom, and saved browser credentials.

Operators Chainalysis suspects are linked to Iran's Ministry of Intelligence write instructions into Bitcoin transactions that send small payments to an address historically associated with Satoshi Nakamoto. The firm bases that link on the malware, not the chain activity alone. That is a Chainalysis assessment, not a court finding that Iran's ministry ran the wallets, and it is a different claim from Treasury's BitBank Hormuz designation.

A third model, in Russian-language criminal crews, rents fleets of resolver contracts on Polygon to other groups. One deployer wallet appears linked to fake stablecoin tokens and more than 50 near-identical BNB contracts.

Chainalysis ties the surge to open-weight Chinese models, marking Kimi K2 and Qwen3-Coder as the releases that "removed the barrier to entry" for generating malicious code. The idea dates to 2013. Guardio Labs documented the first smart-contract version in October 2023 after a September 2023 BNB contract served fake browser-update lures.

Some offers on this page may be paid placements or contain affiliate links.

Finpresso: daily AI & finance brief

Free daily newsletter, read in 5 minutes.

Subscribe free