Crypto news report · source clearly identified

Chinese AI Models Drive 440% Jump in Blockchain-Hosted Malware Commands

Attackers are posting malware instructions to blockchains 440% more often since unrestricted Chinese open-source AI models arrived, Chainalysis reported. Daily malicious on-chain writes climbed from 2.06 to 11.1 in under a year.

Chainalysis reports a sharp rise in the use of public blockchains to host malware commands, a technique it calls blockchain dead drops (BDDs). The frequency of malicious on‑chain writes has increased from 2.06 to 11.1 per day, a 440% jump, after the release of unrestricted Chinese open‑source AI models.

How blockchain dead drops work

BDDs store malicious payloads in on‑chain transactions and smart contracts. Infected devices retrieve the code on demand, allowing threat actors to maintain command‑and‑control (C2) without relying on centralized servers that can be seized or taken offline. The permanence of blockchain ledgers gives these campaigns long‑term durability.

Rise of state‑linked operators

State‑linked groups from North Korea and Iran now generate the majority of new BDD activity. By the second quarter of 2026, such actors accounted for roughly two‑thirds of new malicious writes each quarter and half of the total activity.

Platforms targeted

  • Bitcoin (BTC) – used for tiny payments linked to known addresses.
  • Ethereum Virtual Machine (EVM) chains – including BNB Smart Chain and Polygon.
  • TRON (TRX) and Aptos (APT) – referenced in relay instructions.

Implications for defenders

Blocking blockchain traffic would disrupt legitimate wallets and applications, making mitigation difficult. However, the public nature of blockchain transactions also creates an immutable trail that investigators can analyze.

Historical context

The concept dates back to 2013 with a Necurs botnet variant using the Namecoin fork. In 2023, similar techniques appeared on EVM chains under the name EtherHiding, and later were observed in North Korean operations.

Broader impact

Research from Netskope indicates that a supply‑chain attack leveraging these dead drops affected over 440 npm packages in August 2026, showing the threat extends beyond cryptocurrency ecosystems.

Source & attribution

News Source

Publisher
BeInCrypto
Original date
September 17, 2026, 12:12 PM
Original headline
Chinese AI Models Drive 440% Jump in Blockchain-Hosted Malware Commands
View original report ↗