Malicious Use of Cryptocurrency Networks Increases by 440% in One Year

By: www.criptonoticias.com|09/29/2026 21:53:54
  • Attackers went from publishing 2.06 to 11.1 malware control data per day.
  • State-linked actors generate two-thirds of the new malicious activity.

Malicious writings on cryptocurrency networks surged over the past year, driven by actors linked to states such as North Korea and Iran, according to a report by Chainalysis. The firm warns that these groups are using networks as a coordination layer for malicious programs, a practice that complicates the disruption of their operations.

The report notes that this activity increased by 420% in 12 months and 440% since mid-2025. The average rose from 2.06 to 11.1 daily writings, a growth that Chainalysis associates with the emergence of high-capacity open-source artificial intelligence models developed in China.

Attackers leave a message on public networks that the malicious program reads once installed to know what to do or which servers to connect to. Chainalysis refers to this technique as "clandestine deposits in cryptocurrency networks" and considers it an evolution of methods employed for over a decade.

The firm tracks more than 15 campaigns across five networks and over a dozen families of malicious programs. Until early 2024, cybercriminals concentrated virtually all activity. State-linked groups began to appear significantly in mid-2024, and by the second quarter of 2026, they represented nearly two-thirds of the new activity recorded each quarter and half of all detected clandestine deposit activity. Malicious Use of Cryptocurrency Networks Increases by 440% in One Year The graph shows how state-linked actors went from almost non-existent in 2024 to concentrating 51% of that activity in the second quarter of 2026. Source: Chainalysis

One case corresponds to a group attributed to North Korea that uses the TRON and Aptos networks to direct infected devices to BNB Chain, where it stores encrypted instructions for programs aimed at stealing credentials and cryptocurrencies. Attackers can update that infrastructure through new transactions without reinstalling the malicious program.

Chainalysis also identified operators linked to Iran who store data to direct the communication of malicious programs via the OP_RETURN field of Bitcoin transactions. The Iranian nexus is based on characteristics of the malicious program, its decryption logic, the timing of operations, and the infrastructure used, not solely on the activity recorded in Bitcoin.

The third case involves Russian-speaking groups that use smart contracts on Polygon to store references to servers controlled by the attackers, as reported by CriptoNoticias. Chainalysis linked one of these operators to campaigns of stablecoin impersonation, theft through clipboard modification, and over 50 similar contracts on BNB Chain.

The main risk of these techniques is not necessarily a greater destructive power, but rather that they allow a campaign to remain operational even if its servers or domains change. However, that permanence also leaves a useful trace for defenders: each update is recorded on the network and can help security researchers reconstruct the attackers' infrastructure, link operations that seemed independent, and detect new movements.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com