North Korea and Iran Are Stashing Malware Inside Public Blockchains

iEXExchanger
North Korea and Iran Are Stashing Malware Inside Public Blockchains

Chainalysis found malicious blockchain writes jumped 440% in under a year, with state-linked hackers turning Bitcoin, Tron and BNB Chain into unremovable dead drops for stolen data and commands.

Malicious instructions hidden inside blockchain transactions have surged nearly fivefold in less than a year, according to a new Chainalysis report published on September 17. The firm counted an average of 2.06 malicious writes a day a year ago; that figure now stands at 11.1.

The technique is a digital dead drop. Instead of relying on a command server that defenders can shut down, attackers bury instructions inside transactions or smart contracts. Nothing on a blockchain can be deleted or blocked, so an infected device just checks the same address over and over for fresh orders — where to send stolen data, or which server to switch to next.

Roughly two-thirds of this activity in the most recent quarter traces back to groups linked to North Korea and Iran. North Korean operators, tracked by Google Threat Intelligence under the name UNC5342, lean on Tron, Aptos and BNB Smart Chain. Suspected Iranian actors favor Bitcoin, sending tiny payments to an address historically associated with Satoshi Nakamoto to keep their infrastructure coordinates in one permanent place.

The spike lines up almost exactly with July 2025, when powerful open-weight Chinese AI models became widely available and capable of writing malicious code with few guardrails. Chainalysis researcher Eric Jardine is careful about the causal claim: the timing correlation is clear, he says, but there's no proof yet that the hackers behind these transactions actually used those specific models.

It's an awkward side effect of the exact feature that makes blockchains attractive in the first place. The permanence that protects ordinary users from censorship now also protects malware infrastructure that law enforcement has no real way to take down.

Questions and answers

Frequently asked questions about this article

What is a 'blockchain dead drop'?

It's a way of hiding malware instructions inside blockchain transactions or smart contracts instead of on a traditional command server. An infected device just checks a specific address to pick up fresh orders.

Why can't this infrastructure simply be taken down?

Public blockchain records are permanent by design — they can't be deleted or blocked the way a website or server can. That permanence is exactly what makes the technique attractive to hackers.

Which blockchains do hackers use most for this?

North Korea-linked operators favor Tron, Aptos and BNB Smart Chain, while suspected Iranian groups rely on Bitcoin, sending small payments to a specific address to store infrastructure coordinates.

Does the report prove AI is causing the surge?

No. Chainalysis only found a timing correlation between the surge and the emergence of open-weight Chinese AI models — researchers stopped short of confirming a direct causal link.