Crypto: State hackers increase on-chain attacks by 420% according to Chainalysis
Summarize this article with:

While everyone is watching the price of crypto, state hackers are carefully hiding their hacking instructions directly in the blockchain. According to a Chainalysis report published on September 17, the number of times attackers stored malicious instructions or infrastructure information on public blockchains increased by 420% in twelve months! And as luck would have it, state actors like North Korea and Iran are in the lead.

Chainalysis reveals a 420% increase in on-chain attacks carried out by crypto hackers linked to states such as North Korea and Iran.

In brief

  • On-chain attacks increased by 420% in one year, reaching 51% by States in the second quarter of 2026.
  • A group linked to North Korea (UNC5342) uses Tron, Aptos and BNB Smart Chain as an encrypted relay to its command infrastructure.
  • Actors suspected of being linked to Iranian intelligence hide their instructions in Bitcoin transactions.

Crypto: a North Korean group changes its blockchain three times before delivering its malware

Chainalysis successfully linked previously unattributed activity, spread across Tron, Aptos, and BNB Smart Chain, to UNC5342. This is a North Korean group tracked by Google Threat Intelligence. The procedure is almost elegant but in a twisted way:

  • Pointers encoded in Tron and Aptos crypto transactions redirect infected devices to the same BSC transaction;
  • Tron then serves as the main route, Aptos as plan B if the first fails;
  • This BSC transaction contains encrypted server addresses and configuration data. These therefore connect compromised machines to an offchain infrastructure dedicated to remote access and data theft.

Anything can go wrong in a blockchain except instructions. And that’s why they remain accessible as long as the chain is running. This is the same principle as EtherHiding used by North Korean hackers in 2025 to hide crypto-stealing code in smart contracts. We call this a digital “dead drop”. For those who remember, Cold War spies hid microfilms under public benches; these stash their server addresses in a Tron transaction for just $0.001.

Chinese AI in the loop and Tehran squatting on Satoshi’s bitcoin address

Chainalysis takes the observation further as malicious writes have jumped 440% since July 2025, when high-capacity Chinese open source AI models became capable of producing malicious code with few safeguards. Eric Jardine, head of cybercrime research at Chainalysis, talks about a “clear association over time”. All this, while recognizing the impossibility of proving that the authors of these crypto transactions actually used these AI models to industrialize their production. A down to earth way of saying that there is no evidence despite suspicion.

Your first cryptos with Bitpanda
This link uses an affiliate program

On the Iranian side, the story is almost stranger because actors suspected of being linked to the Iranian Ministry of Intelligence are writing routing data “command and control” directly on the Bitcoin blockchain. And for their public meeting point, they chose an address historically linked to Satoshi Nakamoto. Without any real connection to the attackers, it just serves as a public marker that all infected devices can view. Then simply publish a new Bitcoin transaction to change infrastructure. Infected machines automatically retrieve new crypto instructions, then the operation goes offchain again for remote access, credential theft, or delivery of other malicious payloads.

Wall Street predicts $500,000 for bitcoin by 2030

There is something quite funny about the timing. Because At the same time that Chainalysis is documenting how state intelligence services are transforming bitcoin and public blockchains into sustainable espionage infrastructure, Ric Edelman, founder of a $337 billion asset management company, predicts live on X that bitcoin will reach $500,000 by 2030! Even adding that his forecast is rather low compared to many others.

Two stories for a single blockchain. On the one hand, the technical layer which serves as a PLC for North Korean and Iranian hackers. On the other, the narrative layer that sells dreams for seven figures. Both run on the same crypto network, at the same time, and that’s the real issue. The infrastructure that supports valorization is also that which States exploit to spy. A detail that Twitter threads on the next BTC ATH systematically forget to mention.

What can we learn from on-chain attacks orchestrated by government crypto hackers?

  • On-chain malicious attacks increased by 420% in one year, with state actors responsible for 51% of activity in the second quarter of 2026, compared to less than 10% a year earlier.
  • North Korea (UNC5342) passes its instructions through Tron, Aptos then BNB Smart Chain to cover its tracks before joining its offchain infrastructure.
  • Iran is suspected of using bitcoin and an address linked to Satoshi Nakamoto as a public reference point to update its attack instructions.
  • The 440% increase in malicious attacks since July 2025 coincides with the rise of open source Chinese AI models.

Basically, the blockchain was designed to be tamper-proof and permanent. Two qualities that supporters of the “number go up” as the intelligence services of the North Korean and Iranian states. No one really anticipated this second audience but in the midst of all this, bitcoin now has a target of $500,000.

Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts