Overview
- Chainalysis reported on Thursday that malicious on-chain writes rose from about 2 per day to roughly 11 per day, a roughly 420–440% increase over the past year.
- Attackers are embedding small malware instructions, command-and-control addresses, and pointers inside transactions and smart contracts so infected machines can fetch new orders even after servers are taken down.
- State-linked groups tied to North Korea and Iran now account for about two-thirds of newly observed blockchain-dead-drop activity each quarter, and they use cross-chain redundancy to make campaigns harder to disrupt.
- Chainalysis says the spread of high-capacity open-source AI coding models has lowered the technical bar for building on-chain malware, enabling more criminal groups and malware-as-a-service offerings to adopt the technique.
- Defenders are shifting from takedowns to continuous tracing of wallets, resolver contracts and outbound RPC/API calls because blockchains are immutable, which means centralized node and gateway providers will be the practical pressure points for blocking malicious queries.