State-linked hackers drive sharp rise in malware instructions hidden on public blockchains, Chainalysis says
Chainalysis found malicious code stored on public blockchains rose sharply over a year, with North Korea- and Iran-linked hackers behind most of the new activity.
Why it matters
The findings point to state-linked hacking groups increasingly using public blockchains as resilient infrastructure that is difficult for investigators to take down, a challenge for security firms and wallet providers like MetaMask and Phantom whose users are named as targets.
Where the sources disagree
Share of onchain malware activity attributed to state-linked hackers
roughly two-thirds per quarter
Cointelegraph, BTC-ECHO, Cointelegraph
roughly half
Unchained
Cointelegraph and BTC-ECHO report state-linked hackers accounted for roughly two-thirds of new activity per quarter, while Unchained reports state-backed operators are behind roughly half of the malware written to blockchains.
Key facts
Chainalysis found that instances of malware instructions or infrastructure information stored on public blockchains rose 420% over the past 12 months.
420 %Reported by Cointelegraph
Unchained reported daily malware writes climbed from 2.06 per day to 11.1 per day since open-weight Chinese AI models were released in mid-2025.
11.1Reported by Unchained
Chainalysis linked previously unattributed activity on Tron, Aptos and BNB Smart Chain to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.
Reported by Cointelegraph
Pointers encoded in Tron and Aptos transactions directed infected devices to a single BNB Smart Chain transaction containing encrypted server addresses and configuration data.
Reported by Cointelegraph
Unchained reported UNC5342 reaches victims through fake job interviews targeting crypto developers, with malware aimed at MetaMask and Phantom wallets and saved browser credentials.
Reported by Unchained
What happened
Chainalysis reported that instances of attackers storing malware instructions or infrastructure data on public blockchains rose 420% over the past 12 months, with state-linked hackers accounting for roughly two-thirds of new activity each quarter, according to Cointelegraph and BTC-ECHO. Unchained, citing the same report, described the increase differently, saying daily malicious writes climbed from 2.06 to 11.1 since mid-2025 and that state-backed operators now write roughly half of the malware on chains. Chainalysis linked previously unattributed activity on Tron, Aptos and BNB Smart Chain to UNC5342, a North Korea-linked group also tracked by Google Threat Intelligence, which used Tron and Aptos transactions as pointers to a single BSC transaction holding encrypted server addresses and configuration data. Suspected Iran-linked actors were reported to have embedded similar routing information in Bitcoin transactions, per Cointelegraph and BTC-ECHO, while Unchained said operators it suspects are linked to Iran's Ministry of Intelligence write instructions using a comparable method. Chainalysis said storing this data onchain makes campaigns harder to dismantle because the information stays accessible even after domains, servers or code repositories are taken down. Unchained additionally reported that UNC5342 targets crypto developers through fake job interviews and that its malware goes after MetaMask and Phantom wallets and saved browser credentials.
How the story developed
- First report
First report by Cointelegraph
State hackers drive 420% surge in onchain malware, Chainalysis finds
- Update
Chainalysis publishes report on 420% rise in onchain malware
Cointelegraph first reports the Chainalysis findings on state-linked hackers using blockchains to store malware infrastructure data.
- Independent corroboration
Independently corroborated by BTC-ECHO
Krypto als Hacker-Werkzeug: Chainalysis warnt vor neuem Trend
- Update
BTC-ECHO corroborates the Chainalysis findings in German-language coverage
BTC-ECHO reports the same 420% figure and two-thirds state-actor share, adding detail on multi-chain redundancy.
- Update
Cointelegraph revisits the report in an Asia-focused roundup
Cointelegraph repeats the findings alongside unrelated North Korea and CoinEx news items.
- Update
Unchained publishes detailed account with different figures and campaign specifics
Unchained reports daily write counts rising from 2.06 to 11.1, describes UNC5342's three-chain setup and fake job interview lures, and attributes roughly half of malware to state-backed operators.
How coverage built up
Independent sources over time, counted the way the consensus panel counts them: a republication of a wire story does not move the line.
- 17 Sept 2026, 12:00 UTC: Cointelegraph — 1 independent source, 1 reports
- 17 Sept 2026, 17:30 UTC: BTC-ECHO — 2 independent sources, 2 reports
- 17 Sept 2026, 23:58 UTC: Unchained — 3 independent sources, 4 reports
- 19 Sept 2026, 15:15 UTC: NewsBTC — 4 independent sources, 5 reports
Affected entities
Also mentioned: Aptos, Hong Kong, South Korea, Ethereum, China, Chainlink, Polygon
Original sources
| Publisher | Report | Role | Published |
|---|---|---|---|
| Cointelegraph Crypto media | State hackers drive 420% surge in onchain malware, Chainalysis finds | Original | |
| Unchained Crypto media | Chainalysis Says State Hackers Now Write Half of the Malware Hidden on Blockchains | Independent | |
| Cointelegraph Crypto media | North Korea drives onchain malware surge, CoinEx shuts: Asia Express | Independent | |
| BTC-ECHO Crypto media | Krypto als Hacker-Werkzeug: Chainalysis warnt vor neuem Trend | Independent | |
| NewsBTC Crypto media | Chainalysis Warns Malware Operators Are Turning Blockchains Into Dead Drops | Independent |