Chainalysis: North Korean and Iranian hackers drive 420% surge in onchain malware
Chainalysis reports a 420% surge in malicious code or infrastructure data stored on public blockchains over the last 12 months, with state-backed actors accounting for two-thirds of new activity. North Korea-linked group UNC5342 has been linked to activity on Tron, Aptos, and BNB Smart Chain, using encoded pointers to direct infected devices to BSC transactions containing encrypted server data. Additionally, malicious blockchain writes increased by 440% since July 2025, coinciding with the rise of high-capacity open-source AI models. Separately, actors linked to the Iranian Ministry of Intelligence have been identified embedding command-and-control data into the Bitcoin blockchain.
Summaries are written by AI from the original article. Not investment advice.