crypto hacking
A shadow of man is seen on a banner during the start of the 6th Annual Hackers Congress Paralelni Polis on October 4, 2019 in Prague. Getty Images

Hackers are increasingly using public blockchains to store instructions for malware, combining artificial intelligence with technology designed to make data difficult to alter or remove as cybercrime targeting the cryptocurrency industry continues to grow.

Malicious instructions and infrastructure information written onto blockchains have increased 440% since the emergence of high-capacity Chinese open-source AI models without restrictions on generating malicious code, Chainalysis said in research published Thursday. The average increased from 2.06 malicious blockchain writes a day to 11.1 in less than a year, while the increase measured over the past 12 months was 420%.

Using a technique that Chainalysis calls a "blockchain dead drop," or BDD, attackers place information in blockchain transactions and smart contracts that malware running on an infected device can retrieve. That allows them to avoid relying entirely on conventional command-and-control servers that authorities or cybersecurity companies can shut down, while taking advantage of blockchain records that are difficult to remove.

Although blockchains generally are not used to infect a device in the first place, they can provide instructions to malware after a computer has already been compromised through methods such as malicious downloads or supply-chain attacks, Eric Jardine, head of research at Chainalysis, told Bloomberg. The company is now tracking BDD activity across five major blockchains and more than a dozen named malware strains.

While blockchain dead drops have existed for years, their use has expanded sharply alongside the latest generation of AI models. Chainalysis traced an early example to 2013, when a variant of the Necurs botnet stored command-and-control domains on Namecoin, a Bitcoin fork, with similar activity later appearing on Ethereum-compatible blockchains through techniques including EtherHiding.

After powerful open-weight Chinese AI models became widely available in mid-2025, the average number of malicious blockchain writes began climbing more rapidly, Chainalysis said. Because those models can be downloaded and operated independently, users can modify them without relying on safeguards imposed by commercial AI providers, reducing some of the technical expertise previously required to build blockchain-based command-and-control infrastructure.

"This gives malicious developers greater control over the model and more privacy," Vitaly Kamluk, founder of cybersecurity consultancy TitanHex, told Bloomberg.

Commercial AI services operate under a different structure because their providers retain control over access and can restrict accounts when abuse is detected. Open-weight models, by contrast, can be downloaded and run independently, leaving their original developers with little control over how individual copies are modified or used.

State-linked operators have also taken a growing role in blockchain dead-drop activity, accounting for roughly two-thirds of new BDD activity each quarter and about half of overall activity by the second quarter of 2026, Chainalysis found. Groups linked to North Korea and suspected Iranian state actors have used different versions of the technique in their cyber operations.

Actors suspected of ties to Iran's Ministry of Intelligence began embedding command-and-control information in Bitcoin transactions in late 2024, placing encoded routing information where infected devices could retrieve it and locate attacker-controlled infrastructure. North Korean operators later began using EtherHiding in early 2025 as part of fake job interview campaigns targeting cryptocurrency developers.

One North Korean group identified by Google Threat Intelligence Group as UNC5342 used smart contracts on public blockchains to deliver malware to victims approached by bogus recruiters, Chainalysis said. The tactic fits into a broader pattern of North Korean operations targeting cryptocurrency companies, developers and digital assets.

Iranian cyber activity has also drawn fresh attention during the continuing Middle East conflict, with governments tracking operations attributed to Tehran-linked groups beyond the cryptocurrency sector. Britain, the United States and the Netherlands issued a joint cybersecurity advisory this week detailing spyware attributed to Iranian state-linked actors that targeted dissidents, activists and journalists through spear-phishing campaigns on services including WhatsApp and Telegram, Reuters reported Tuesday.

North Korea, meanwhile, remains one of the largest state-linked sources of cryptocurrency theft, with its hackers repeatedly targeting exchanges, protocols and crypto companies. North Korea-linked activity accounted for about $643 million, or roughly two-thirds of cryptocurrency stolen during the first half of 2026, according to TRM Labs.

Across the crypto industry, the number of hacks jumped roughly 150% to 207 during the first six months of 2026 from 83 during the same period a year earlier, TRM Labs found. Total losses fell to $972 million from $2.3 billion in the first half of 2025 because the period included fewer exceptionally large thefts.