Chainalysiscompany
StableHack

State-linked hackers drive sharp rise in malware instructions hidden on public blockchains, Chainalysis says

Chainalysis found malicious code stored on public blockchains rose sharply over a year, with North Korea- and Iran-linked hackers behind most of the new activity.

Why it matters

The findings point to state-linked hacking groups increasingly using public blockchains as resilient infrastructure that is difficult for investigators to take down, a challenge for security firms and wallet providers like MetaMask and Phantom whose users are named as targets.

Where the sources disagree

Share of onchain malware activity attributed to state-linked hackers

roughly two-thirds per quarter

Cointelegraph, BTC-ECHO, Cointelegraph

roughly half

Unchained

Cointelegraph and BTC-ECHO report state-linked hackers accounted for roughly two-thirds of new activity per quarter, while Unchained reports state-backed operators are behind roughly half of the malware written to blockchains.

Key facts

Chainalysis found that instances of malware instructions or infrastructure information stored on public blockchains rose 420% over the past 12 months.

420 %Reported by Cointelegraph

Unchained reported daily malware writes climbed from 2.06 per day to 11.1 per day since open-weight Chinese AI models were released in mid-2025.

11.1Reported by Unchained

Chainalysis linked previously unattributed activity on Tron, Aptos and BNB Smart Chain to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.

Reported by Cointelegraph

Pointers encoded in Tron and Aptos transactions directed infected devices to a single BNB Smart Chain transaction containing encrypted server addresses and configuration data.

Reported by Cointelegraph

Unchained reported UNC5342 reaches victims through fake job interviews targeting crypto developers, with malware aimed at MetaMask and Phantom wallets and saved browser credentials.

Reported by Unchained

What happened

Chainalysis reported that instances of attackers storing malware instructions or infrastructure data on public blockchains rose 420% over the past 12 months, with state-linked hackers accounting for roughly two-thirds of new activity each quarter, according to Cointelegraph and BTC-ECHO. Unchained, citing the same report, described the increase differently, saying daily malicious writes climbed from 2.06 to 11.1 since mid-2025 and that state-backed operators now write roughly half of the malware on chains. Chainalysis linked previously unattributed activity on Tron, Aptos and BNB Smart Chain to UNC5342, a North Korea-linked group also tracked by Google Threat Intelligence, which used Tron and Aptos transactions as pointers to a single BSC transaction holding encrypted server addresses and configuration data. Suspected Iran-linked actors were reported to have embedded similar routing information in Bitcoin transactions, per Cointelegraph and BTC-ECHO, while Unchained said operators it suspects are linked to Iran's Ministry of Intelligence write instructions using a comparable method. Chainalysis said storing this data onchain makes campaigns harder to dismantle because the information stays accessible even after domains, servers or code repositories are taken down. Unchained additionally reported that UNC5342 targets crypto developers through fake job interviews and that its malware goes after MetaMask and Phantom wallets and saved browser credentials.

How the story developed

  1. First report

    First report by Cointelegraph

    State hackers drive 420% surge in onchain malware, Chainalysis finds

    Cointelegraph

  2. Update

    Chainalysis publishes report on 420% rise in onchain malware

    Cointelegraph first reports the Chainalysis findings on state-linked hackers using blockchains to store malware infrastructure data.

    Cointelegraph

  3. Independent corroboration

    Independently corroborated by BTC-ECHO

    Krypto als Hacker-Werkzeug: Chainalysis warnt vor neuem Trend

    BTC-ECHO

  4. Update

    BTC-ECHO corroborates the Chainalysis findings in German-language coverage

    BTC-ECHO reports the same 420% figure and two-thirds state-actor share, adding detail on multi-chain redundancy.

    BTC-ECHO

  5. Update

    Cointelegraph revisits the report in an Asia-focused roundup

    Cointelegraph repeats the findings alongside unrelated North Korea and CoinEx news items.

    Cointelegraph

  6. Update

    Unchained publishes detailed account with different figures and campaign specifics

    Unchained reports daily write counts rising from 2.06 to 11.1, describes UNC5342's three-chain setup and fake job interview lures, and attributes roughly half of malware to state-backed operators.

    Unchained

How coverage built up

Independent sources over time, counted the way the consensus panel counts them: a republication of a wire story does not move the line.

17 Sept, 12:004 independent sources19 Sept, 15:15
  • 17 Sept 2026, 12:00 UTC: Cointelegraph 1 independent source, 1 reports
  • 17 Sept 2026, 17:30 UTC: BTC-ECHO 2 independent sources, 2 reports
  • 17 Sept 2026, 23:58 UTC: Unchained 3 independent sources, 4 reports
  • 19 Sept 2026, 15:15 UTC: NewsBTC 4 independent sources, 5 reports

Affected entities

Also mentioned: Aptos, Hong Kong, South Korea, Ethereum, China, Chainlink, Polygon

Original sources

PublisherReportRolePublished
Cointelegraph
Crypto media
State hackers drive 420% surge in onchain malware, Chainalysis findsOriginal
Unchained
Crypto media
Chainalysis Says State Hackers Now Write Half of the Malware Hidden on BlockchainsIndependent
Cointelegraph
Crypto media
North Korea drives onchain malware surge, CoinEx shuts: Asia ExpressIndependent
BTC-ECHO
Crypto media
Krypto als Hacker-Werkzeug: Chainalysis warnt vor neuem TrendIndependent
NewsBTC
Crypto media
Chainalysis Warns Malware Operators Are Turning Blockchains Into Dead DropsIndependent
State-linked hackers drive sharp rise in malware instructions hidden on public blockchains, Chainalysis says — Crypto News Intelligence