AI assisted tools are arriving at the same time as a sharp rise in malware that treats public blockchains as part of its infrastructure. Chainalysis reports roughly a 440 percent jump in what it calls onchain malware writes, meaning malicious data stored on blockchains. The overall increase in malicious data written to blockchains over the past year is about 420 to 440 percent, and state linked hackers from North Korea and Iran are behind most of that growth.
North Korea and Iran linked groups account for roughly two thirds of the new activity. They embed encrypted routing data and server information in transactions on Bitcoin, Tron, Aptos, and BNB Chain. One campaign tied to the North Korea linked group UNC5342 used Tron and Aptos transactions to point infected machines to a specific BNB Chain transaction that held configuration data for remote access and data theft.
Chainalysis notes that the surge began shortly after high capacity open source Chinese AI models became able to generate malicious code with minimal safeguards. The timing overlap is striking. Their cybercrime lead describes a clear point in time association between those AI releases and the increase, while also noting that direct attacker use of those models is not proven in every campaign.
Other research supports the idea that AI acts as a force multiplier. Anthropic and others have shown AI agents quickly finding exploitable smart contract bugs. Security leaders warn that small protocol teams now face adversaries who can iterate malware far faster than before. AI is best viewed as an accelerant for existing threat actors rather than a brand new type of exploit, but it compresses the time defenders have to react.
Recent campaigns show how onchain malware intersects directly with crypto. Elastic’s KREMLIN malware uses Ethereum smart contracts as a dead drop to update attack servers without redeploying the malware. Another campaign hijacked HBO Max’s Reddit account to push malware that stole browser credentials and deployed crypto address clippers, while using Binance Smart Chain contracts as part of its command and control rotation.
These designs do not break consensus or steal funds directly from chains. Instead, they use blockchains as a permanent, censorship resistant bulletin board for malware instructions that ultimately target wallets, browsers, and DeFi users offchain. Even if onchain approvals look safe, compromised devices and browsers can silently redirect transactions or exfiltrate keys. Endpoint security and phishing resistance therefore matter as much as smart contract risk.
Confidence in this picture is high, based on the Chainalysis report and multiple independent security write ups from 2025 to 2026.
In conclusion, AI has made it easier for sophisticated actors to produce and maintain malware that leans on public blockchains for resilience, driving a large increase in onchain malware writes. For crypto users and builders, the main shift is not a new exploit class but a faster, more automated version of existing threats that now blend onchain infrastructure with offchain phishing and malware. Monitoring AI driven threats, hardening user devices and wallets, and adopting stronger verification and auditing practices will be key to keeping blockchains and DeFi usable as AI capabilities continue to advance.





