Skip to content
AI Fuels Blockchain 'Dead Drops' Malware

AI Fuels Blockchain 'Dead Drops' Malware

Briefs.Co • September 18, 2026

Chainalysis says on-chain malware instructions surged 440% in under a year, now averaging 11 a day.

Before the mid-2023 debut of high-powered Chinese open-source AI models that omitted safeguards against malicious code, the daily count was two.

State-backed groups, including those tied to North Korea and Iran, account for most of the activity.

What Chainalysis found

Hackers are increasingly tucking malware playbooks into transactions and smart contracts, and the trend is accelerating. Chainalysis tallied a 440% increase in less than a year, with 11 such cases per day, versus roughly two per day ahead of mid-2023, when Chinese open-source AI models arrived lacking protections against producing malicious code. The firm says its findings add to growing evidence that generative AI is fueling a broader cybercrime upswing by identifying more software weak spots and helping attackers run more operations.

How attackers use blockchains

Malware is hostile code planted on a device or network to steal data, passwords or funds. In these attacks, the perpetrators post on-chain instructions that tell infected machines where to send stolen information, a technique known as a " blockchain dead drop." Because blockchains are designed to be permanent, scrubbing those directions is difficult. None of this is brand new, but recent open-source AI models let attackers scale up. At the same time, blockchains' openness is a double-edged sword: every change is immutably logged, enabling investigators to chart infrastructure and connect campaigns that could otherwise appear unconnected.

Who is behind it and where infections begin

Government-aligned operators now account for most of this activity, including groups associated with North Korea and Iran, according to Chainalysis. Eric Jardine, the firm's head of research, said over email that initial compromises typically happen through familiar routes like supply-chain breaches or malicious downloads rather than via the blockchain itself. Chainalysis has not measured how many of these attempts succeeded or the amounts stolen.

Keeping your investments safe and growing takes steady attention and good guidance. Join Briefs Finance CEO Jaspreet Singh on September 29th for a FREE live investor workshop, How to Profit From A Dollar That's Losing its Value, where he shows how we're spotting investment opportunities as the dollar falls. Save your spot .

Why it matters for your money

Open-source AI models can run locally, so bad actors can alter them or strip away safeguards. As Vitaly Kamluk, who founded the cybersecurity consultancy TitanHex, put it, "This gives malicious developers greater control over the model and more privacy." By contrast, companies like OpenAI and Alphabet's Google can shut off service when they detect abuse. In crypto specifically, TRM Labs counted roughly a 150% jump in hacks to 207 during the first half of the year. Translation for everyday users: smarter tools and more capable attackers raise the operational risk around the crypto services you touch, from wallets to bridges, even as blockchain transparency gives defenders more to work with.

Lucid wraps up AlixPartners engagement as CEO pushes turnaround

SpaceXAI Weighs Buying Data From Failed Startups to Feed Grok

Schwab Muni-Bond ETF Heads for Record Monthly Outflow as Yields Jump

U.S. Pending Sales Nudge Higher in August, Still Sluggish

India Secures Up To $12 Billion in Chip Investment Pledges After New Policy

GM speeds first PAC-3 missile parts to Lockheed, 22 days after teaming up

CleanSpark Seeks $2.23 Billion Junk Bond to Fund Meta-Linked AI Data Center

ExxonMobil Says Coal Will Push Emissions Far Past Climate Targets

Intersnack's Utz buyout loan gets pricier as lenders sweeten terms

US Housing Starts Slip as Apartment Projects Drop Sharply

Get Market Briefs every morning for free!