BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

AI helps hackers hide malware on blockchains as attacks surge 440%

Instances of malware instructions hidden on public blockchains have surged 440% in under a year, averaging 11 cases per day, according to a report published by Chainalysis on Thursday. Before

AnonymousCryptoCompass newsroom
September 20, 2026
3 min read
NEWS
AI helps hackers hide malware on blockchains as attacks surge 440%
CryptoCompass editorial visual for policy coverage.

Instances of malware instructions hidden on public blockchains have surged 440% in under a year, averaging 11 cases per day, according to a report published by Chainalysis on Thursday. Before mid-2025, the average was two per day.

Chainalysis is one of the largest blockchain analytics firms, providing investigative tools to governments, law enforcement agencies and financial institutions worldwide. 

A blockchain is a shared digital ledger that permanently records every transaction made on a network, a feature that makes it useful for tracking money, but also, as the report shows, for hiding malicious code in plain sight.

Related: Satoshi-era Bitcoin stash untouched for 16 years, here's what it's worth now

What is a "blockchain dead drop"

The technique Chainalysis describes works like a digital dead drop. Attackers write malware instructions, such as commands telling infected computers where to send stolen data, directly into blockchain transactions or smart contracts

Because blockchains are permanent and publicly accessible, the instructions can't be taken down or blocked the way a traditional server can. Any infected device that knows where to look can read the instructions without the attacker needing to maintain a separate command server.

The report calls this technique "EtherHiding" when it uses Binance Smart Chain, though similar methods have been observed across multiple networks.

Open-source AI as the accelerant

Chainalysis ties the 440% spike directly to the release of powerful open-source AI models in mid-2025 that carry no restrictions on generating malicious code. 

These tools have lowered the technical barrier for less-experienced hackers, allowing them to build blockchain-based malware infrastructure that earlier required specialized knowledge.

North Korean and Iranian state-linked groups are among those using the technique, the report said, alongside financially motivated cybercriminals.

A feature turned into a vulnerability

The same property that makes blockchains valuable, immutability, meaning data once recorded cannot be altered or deleted, is what makes them attractive to attackers. 

Traditional cybersecurity defenses focus on taking down malicious servers or blocking known IP addresses. When the instructions live on a blockchain, those defenses don't apply. The data is permanent, publicly readable and hosted across thousands of nodes worldwide.

Chainalysis said the trend represents an emerging front in blockchain-related cybercrime, one that requires new detection approaches beyond traditional takedown methods.

Related: CFTC makes it easier for software platforms to offer crypto trading