← Back to News
Crypto

State hackers drive 420% surge in onchain malware, Chainalysis finds

North Korea-linked hackers used Tron, Aptos and BNB Chain to maintain malware infrastructure, while suspected Iran-linked actors embedded directions in Bitcoin transactions.

Cointelegraph

North Korea-linked hackers used Tron, Aptos and BNB Chain to maintain malware infrastructure, while suspected Iran-linked actors embedded directions in Bitcoin transactions.

State-linked hackers accounted for roughly two-thirds of new activity each quarter as the number of times attackers stored malware instructions or infrastructure information on public blockchains rose 420% over the past 12 months, according to a Chainalysis report.

Chainalysis identified North Korea and Iran-linked operators among the state actors adopting the technique. In one of the report’s findings, the analytics firm connected previously unattributed activity spanning Tron, Aptos and BNB Smart Chain (BSC) to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.

The company also recorded a 440% increase in malicious blockchain writes since July 2025, when it said high-capacity open-source Chinese artificial intelligence models became capable of producing malicious code with limited safeguards.