Malicious Use of Cryptocurrency Networks Increases by 440% in One Year
- Attackers went from publishing 2.06 to 11.1 malware control data per day.
- State-linked actors generate two-thirds of the new malicious activity.
Malicious writings on cryptocurrency networks surged over the past year, driven by actors linked to states such as North Korea and Iran, according to a report by Chainalysis. The firm warns that these groups are using networks as a coordination layer for malicious programs, a practice that complicates the disruption of their operations.
The report notes that this activity increased by 420% in 12 months and 440% since mid-2025. The average rose from 2.06 to 11.1 daily writings, a growth that Chainalysis associates with the emergence of high-capacity open-source artificial intelligence models developed in China.
Attackers leave a message on public networks that the malicious program reads once installed to know what to do or which servers to connect to. Chainalysis refers to this technique as "clandestine deposits in cryptocurrency networks" and considers it an evolution of methods employed for over a decade.
The firm tracks more than 15 campaigns across five networks and over a dozen families of malicious programs. Until early 2024, cybercriminals concentrated virtually all activity. State-linked groups began to appear significantly in mid-2024, and by the second quarter of 2026, they represented nearly two-thirds of the new activity recorded each quarter and half of all detected clandestine deposit activity.
The graph shows how state-linked actors went from almost non-existent in 2024 to concentrating 51% of that activity in the second quarter of 2026. Source: Chainalysis
One case corresponds to a group attributed to North Korea that uses the TRON and Aptos networks to direct infected devices to BNB Chain, where it stores encrypted instructions for programs aimed at stealing credentials and cryptocurrencies. Attackers can update that infrastructure through new transactions without reinstalling the malicious program.
Chainalysis also identified operators linked to Iran who store data to direct the communication of malicious programs via the OP_RETURN field of Bitcoin transactions. The Iranian nexus is based on characteristics of the malicious program, its decryption logic, the timing of operations, and the infrastructure used, not solely on the activity recorded in Bitcoin.
The third case involves Russian-speaking groups that use smart contracts on Polygon to store references to servers controlled by the attackers, as reported by CriptoNoticias. Chainalysis linked one of these operators to campaigns of stablecoin impersonation, theft through clipboard modification, and over 50 similar contracts on BNB Chain.
The main risk of these techniques is not necessarily a greater destructive power, but rather that they allow a campaign to remain operational even if its servers or domains change. However, that permanence also leaves a useful trace for defenders: each update is recorded on the network and can help security researchers reconstruct the attackers' infrastructure, link operations that seemed independent, and detect new movements.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

TRON DAO Rings Cboe Closing Bell for TRXS ETF Launch

Stolen $387 million and complained on Discord. In response, they received a photo of Kim Jong Un

WalletConnect Pay Supports USDT on TRON

USDT grew on Ethereum through 2024, but smart contract holdings stalled, BIS data show

U.S. Senate Investigation Finds Iran Uses USDT for 84% of Sanctioned Wallets

Crypto: Circle Freezes 611,000 USDC on Ethereum in One Transaction

Visa cuts reported stablecoin volume but there’s no proof payments fell

Cryptocurrency Exchanges Lost Hundreds of Millions of Dollars in 2026. Which Ones to Choose for Peace of Mind?

Tether Discusses USDT Return to Bitcoin with Morgan Stanley

OpenZeppelin Integrates with TRON to Bring Its Security Standard to the Network

TRON Surpasses $30T in Total Transaction Volume as it Secures its Place as Leading Chain for Stablecoins

Privy Expands Support for TRON with Enhanced Wallet and Payment Infrastructure for Developers

TRON Ecosystem Wallet MeshWallet Completes $10 Million Private Placement Financing

Coinbase traced $1.1 million crypto trail behind AI phishing service EvilTokens

iPhone App Leads to Crypto Theft of Half a Million Euros - Here's What We Know Now

Unknown Victim's Private Key Leaked, Loss Exceeds $4.3 Million

USDT on TRON Becomes Most Used Onchain Payment Option on CoinsBee as Stablecoin Spending Grows

Morph Payments Adds Support for Solana, TRON, and Exchange Account Payments

HotShort to present short-drama RWA model at GWDC Korea 2026

Blockchain Dead Drop Attacks Rise 420%, State Hackers Dominate

Non-Small Number and AIX Incubator Host GWDC 2026 Innovation Forum

North Korea, Iran-linked hackers increase blockchain malware use by 420%

Unlocking the Trillion-Token Era: B.AI’s Global Settlement Layer for the Agent Economy

Chainflip resets TRON USDT provider balances to zero after 736000 USDT exploit

Hamas Military Wing Advises Donors to Avoid Binance

Justin Sun Establishes the 'Justin Sun Prize' in Mathematics

Bitcoin Transaction Volume Can Vary by Up to 6 Times Depending on Calculation Method

Tonkeeper Rebranded to Keeper, Supporting 6 Blockchains

TRON’s quantum plan could leave some wallets able to pay but unable to replace their keys
![[Kwon Seong-min Column] In the Stablecoin War, the Side with 'Use Cases' Will Ultimately Win](/public-static/12_7a0866abc1.png?format=avif)







