to leave a comment.

▲ Cryptocurrency Hacking, Cryptocurrency Crime/AI Generated Image
As loosely regulated Chinese open-source artificial intelligence (AI) models have become widespread, cyberattacks concealing malicious code commands on blockchains have surged by 440%. It is diagnosed that state-sponsored hacking organizations are rapidly expanding their command and control (C2) infrastructure by exploiting the immutable characteristics of blockchain.
According to BeInCrypto on September 17 (local time), blockchain data analytics firm Chainalysis announced that the number of malicious code command creations on blockchains has soared by 440% since mid-2025. In particular, as of Q2 2026, two-thirds of new on-chain malicious activities were identified as the work of state-linked hacking organizations. Hackers linked to North Korea and Iran were found to be leading the attacks.
The cause of this surge in attacks was attributed to Chinese open-source AI models with safety features removed. Analysts suggest that hackers are exploiting these open-source models for malicious code generation because they can be downloaded to local environments and their guardrails can be easily circumvented. Chainalysis pointed out that the timing of the proliferation of high-performance Chinese open-source models coincides with the surge in blockchain malware. This means that even without professional development capabilities, on-chain malicious commands can be easily created.
Hackers are using the decentralized nature of public blockchains, which cannot be forcibly shut down, as malicious strongholds. A typical method involves distributing and concealing malicious communication commands on major networks such as TRON (TRX). Unlike traditional web servers, blockchain ledgers cannot be arbitrarily deleted, thus neutralizing blocking measures by security authorities.
On-chain attacks combined with AI tools are spreading across the entire software supply chain. As state-sponsored organizations use AI technology to build more sophisticated malicious infrastructure, the threat of bypassing security monitoring networks is growing.
The combination of regulatory blind spots for AI and the immutability of blockchain is fundamentally changing the landscape of security threats. Establishing a proactive defense system across the entire virtual asset ecosystem and strengthening on-chain monitoring have emerged as urgent tasks.
[Key Summary of Article]
-After the proliferation of Chinese open-source artificial intelligence (AI) models, malicious code commands hidden on blockchains surged by 440%.
-According to Chainalysis, state-sponsored hacking organizations, including those from North Korea and Iran, accounted for two-thirds of on-chain attacks.
-As command and control infrastructure exploiting the immutability of blockchain spreads, strengthening virtual asset security monitoring has become urgent.
*Disclaimer: This article is for investment reference only, and we are not responsible for any investment losses based on it. The content should be interpreted for informational purposes only.*
Newsletter
Get key news delivered to your email every morning
to leave a comment.