Chainalysis: On-chain malicious instructions up about 420% in a year — AI links ≠ proven
Chainalysis reported an unflattering figure: over the past 12 months, the number of times malicious instructions or C2 information were written onto public blockchains as a “dead letter mailbox” has risen by roughly 420%.
The tactics aren’t new—infect devices to look up a particular transaction or contract and grab the latest server address; when the domain is taken down, that on-chain trail still remains. North Korea–South Korea and Iran-related groups account for about two-thirds of the added cases. The report also drew another line to July 2025: after open-source large language models could write malicious code, this kind of on-chain write surged by about 440%. Researchers themselves said it only matched up in timing and they didn’t find hard evidence of “someone used a specific model.”
Here’s the catch: what you can’t delete is the instruction pointer, not your wallet suddenly becoming safe. Don’t hear “AI acceleration” and think hackers have already fully replaced old methods—correlation isn’t causation, and taking down a domain won’t stop the next on-chain update.
Chainalysis reported an unflattering figure: over the past 12 months, the number of times malicious instructions or C2 information were written onto public blockchains as a “dead letter mailbox” has risen by roughly 420%.
The tactics aren’t new—infect devices to look up a particular transaction or contract and grab the latest server address; when the domain is taken down, that on-chain trail still remains. North Korea–South Korea and Iran-related groups account for about two-thirds of the added cases. The report also drew another line to July 2025: after open-source large language models could write malicious code, this kind of on-chain write surged by about 440%. Researchers themselves said it only matched up in timing and they didn’t find hard evidence of “someone used a specific model.”
Here’s the catch: what you can’t delete is the instruction pointer, not your wallet suddenly becoming safe. Don’t hear “AI acceleration” and think hackers have already fully replaced old methods—correlation isn’t causation, and taking down a domain won’t stop the next on-chain update.
