Recently, a report by Chainalysis revealed an alarming increase in malware instructions hosted on blockchains, recording a rise of 440% since the emergence of Chinese open-source artificial intelligence (AI) models. This phenomenon has transformed the landscape of cybercrime, allowing attackers to store malicious code on public blockchains, safe from traditional seizures. In this article, we will examine the implications of this growing trend and the groups responsible for this malicious activity.
The Rise of Chinese AI Models
The rise of AI models developed in China, particularly those available as open-source, has played a major role in the skyrocketing of malware. According to experts, these models have challenged the technical barriers that limited access to malicious coding tools, making this activity accessible to a larger number of malicious operators. The availability of these models without restrictions has thus opened the door to more sophisticated and diverse attacks.
The “Blockchain Dead Drops” Technique
Chainalysis refers to this new method of storing malicious code as “blockchain dead drops” (BDD). This technique allows hackers to keep their payloads within on-chain transactions and smart contracts. Compromised devices can then retrieve the malware on demand. This operational mode offers unprecedented protection against interventions by authorities and ensures the longevity of cybercrime campaigns.
Resistance to Censorship
BDDs have the advantage of circumventing traditional needs for centralized servers, which are often subject to arrest or closure by regulatory bodies. By migrating to public blockchains, cybercriminals ensure the longevity of their campaigns, allowing persistent communication with infected machines without fearing the loss of their command and control infrastructure.
State Actors and the Rise of Cyberattacks
State-linked groups such as North Korea and Iran are now major players in this influx of malware. Initially, cybercriminals represented the majority of activities related to BDDs, but it is now observed that state operators generate a significant share of this dynamic. According to Chainalysis, these groups are responsible for nearly two-thirds of new activity each quarter.
Evolution and Resilience of Malicious Campaigns
The first manifestations of using blockchains in malware operations date back to 2013, when the Necurs botnet began storing information on a Bitcoin fork. Since then, the technique has evolved to include blockchains compatible with the Ethereum virtual machine, allowing for greater flexibility and expanded capabilities for hackers.
Impact Beyond Crypto
The scope of this technique is not limited solely to the cryptocurrency sector. Research shows that attacks like those conducted by ChainDrop have infiltrated hundreds of npm packages, illustrating the expansion of this threat across many sectors. The spread of malware techniques via modern infrastructures highlights the need for increased vigilance against contemporary cyber threats.
To learn more about the economic and digital implications of these technologies, one can read articles such as the one on the future of artificial intelligence in France, or discover analyses on the challenges of modern AI.
In the context of increased technological competition, it is clear that these new operational modes are irreversibly changing the cybersecurity landscape and raising ethical and practical questions regarding the use of artificial intelligence in global hacking strategies.
Experts like Giorgio Parisi in the field of AI also highlight the importance of this technology in the face of rising cyber threats. Nations find themselves in a digital arms race, where mastering AI tools becomes a strategic priority. At the same time, the battle around the development of OpenAI also illuminates the struggles for influence in the tech sector and its implications for cybersecurity and hacking practices.






