Hackers are hiding malware on blockchains that are nearly impossible to take down, and unrestricted AI models have pushed these attacks up 440%
AI-summarised brief · reviewed before publication
Hackers are increasingly embedding malware instructions in public blockchain ledgers, creating “dead‑drop” channels that persist even after traditional servers are shut down. Chainalysis reports a 440 % surge in such activity, with daily malicious entries climbing from 2.06 to 11.1 after the rollout of unrestricted AI models. The method uses transaction data or smart‑contract calls on networks such as TRON, Aptos, BNB Chain, Polygon and Bitcoin to store encrypted commands, addresses and configuration details that infected computers can retrieve on demand. A North Korean‑linked group (UNC5342) and Iranian actors linked to their intelligence ministry have been identified employing the technique, while Russian‑speaking cybercriminals commercialize it for multiple clients. The approach lowers the technical barrier for attackers, as high‑capacity Chinese open‑source AI models now generate malware code with fewer safeguards.
💡 Why It Matters
- · By turning immutable ledgers into covert command‑and‑control hubs, hackers gain a resilient, censorship‑proof foothold that conventional takedown efforts cannot erase.