- On-chain malware activity has surged 420-440% over the past year, according to Chainalysis
- State-backed hackers from North Korea and Iran now drive roughly two-thirds of new malicious code targeting crypto users
- Researchers attribute the increase directly to AI tools making malware development faster and cheaper
On-chain malware activity has surged between 420% and 440% over the past year, according to research from blockchain analytics firm Chainalysis, with state-backed hacking groups from North Korea and Iran now responsible for roughly two-thirds of newly identified malicious code targeting crypto users and infrastructure. Researchers attribute the sharp increase directly to AI coding tools, which have made it significantly faster and cheaper for attackers to develop, customize, and deploy malware than traditional manual development allowed.
North Korea’s state-linked hacking operations have targeted crypto exchanges and infrastructure for years, historically generating hundreds of millions of dollars annually to help fund the country’s weapons programs under international sanctions. What has changed, according to the Chainalysis research, is not the identity of the attackers but the volume and speed at which they can now produce new attack tools, since AI coding assistants can generate functional malicious code, adapt it to evade specific security defenses, and iterate on failed attempts far faster than a team of human developers working through the same process manually.
The finding aligns with a separate incident this same week in which security researchers reportedly used a major AI lab’s own model to breach a competing lab’s internal systems, illustrating from a different angle how quickly AI tools have moved from theoretical security concern to demonstrated offensive capability. Crypto infrastructure has historically been an attractive target for this kind of tooling because successful attacks can be monetized quickly and, in some cases, with less traceability than attacks on traditional financial infrastructure, though blockchain analytics firms including Chainalysis have increasingly been able to trace and, in some cases, help recover stolen funds after the fact.
Security teams at exchanges and wallet providers have responded by increasing their own use of AI tools for defensive purposes, including automated code review and anomaly detection, though Chainalysis’s data suggests attackers are currently adapting faster than defenders in aggregate. The firm’s report does not identify a single fix for the imbalance, noting instead that the trend will likely require closer coordination between exchanges, wallet developers, and blockchain analytics firms to keep pace with the increasing speed at which new attack tools can now be produced.
Blockchain analytics firms including Chainalysis have increasingly partnered directly with exchanges and law enforcement agencies to trace and, in some cases, freeze or recover funds tied to state-sponsored hacking groups shortly after an incident is detected, a capability that has improved substantially compared with the earlier years of North Korea-linked crypto theft. That improved tracing has not yet been enough to offset the sheer increase in attack volume the report describes, underscoring why researchers are framing the current moment as an arms race between AI-assisted attack tooling and defensive analytics rather than a problem either side has solved.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.










