State hackers drive 420% surge in onchain malware, Chainalysis finds
North Korea-linked hackers used Tron, Aptos and BNB Chain to maintain malware infrastructure, while suspected Iran-linked actors embedded directions in Bitcoin transactions.
Onchain malware activity surged 420% in recent periods, driven largely by state-sponsored hacking groups, according to new research from blockchain analytics firm Chainalysis. North Korea-linked actors were identified as primary contributors, leveraging networks including Tron, Aptos, and BNB Chain to build and sustain malware infrastructure. Separately, threat actors suspected of ties to Iran were found embedding operational directions directly within Bitcoin transactions.
State-sponsored cyber operations targeting the crypto ecosystem are not new, but the scale and sophistication of blockchain-based infrastructure abuse marks a notable escalation. North Korean hacking groups, particularly those associated with the Lazarus collective, have long been linked to high-profile crypto thefts used to fund state programs. The use of multiple blockchain networks suggests deliberate efforts to diversify infrastructure and complicate attribution and takedown efforts by authorities.
The findings carry significant implications for the broader crypto industry, raising fresh concerns about the resilience of public blockchain networks against hostile exploitation. Exchanges, custodians, and DeFi protocols may face increased regulatory scrutiny as governments respond to evidence that decentralized infrastructure is being weaponized by sanctioned nation-states. Compliance and security teams across the sector are likely to reassess their threat models in light of the Chainalysis data.
Analysts will be watching for further regulatory responses from bodies such as the U.S. Treasury's OFAC, as well as any coordinated international enforcement actions targeting the identified blockchain networks and associated wallet clusters.
Source: Cointelegraph