Edited by Editor-in-Chief, The Indus Pulse 18 Sept 2026, 07:22 PM 2 min readai

Open-Source AI Fuels 440% Surge in Blockchain-Based Malware Attacks

The use of blockchain technology to facilitate malware attacks has surged by 440 percent over the past year, a trend researchers attribute to the proliferation of unrestricted open-source artificial intelligence models. According to a report published by blockchain analytics firm Chainalysis on September 17, 2026, the frequency of malicious instructions embedded within on-chain transactions and smart contracts has risen to an average of 11 cases per day, up from two cases daily prior to mid-2025.

The Role of Open-Source AI in Cybercrime

The sharp increase coincides with the release of powerful open-source AI models that lack the safety guardrails typically found in commercial offerings from companies like OpenAI or Google. Because these models can be operated independently, malicious actors can modify them to generate code for cyberattacks without oversight. Vitaly Kamluk, founder of the cybersecurity consultancy TitanHex, noted that this autonomy provides developers with greater control and privacy, as they are not required to submit their source code to cloud providers that might monitor for abusive behavior.

Blockchain Dead Drops and State-Backed Actors

Hackers are increasingly utilizing a technique known as a blockchain dead drop, where malicious software is programmed to retrieve instructions or command-and-control server locations directly from blockchain transactions. Because data recorded on a blockchain is immutable and difficult to remove, this method makes it significantly harder for security teams to disrupt the connection between the malware and its operator. Chainalysis identified state-backed groups, particularly those linked to North Korea and Iran, as the primary drivers of this activity. For these actors, blockchains offer a way to bypass traditional hosting and payment hurdles that might otherwise trigger security scrutiny.

Investigative Challenges and Transparency

While the technique complicates traditional defense, the inherent transparency of blockchain ledgers provides a counter-advantage for investigators. Every update posted by attackers remains permanently recorded on the chain, allowing security researchers to map infrastructure and link previously disparate cybercrime campaigns. Despite this, the scale of the threat continues to grow, with the cryptocurrency sector seeing a 150 percent rise in hacks to 207 incidents in the first half of 2026, according to TRM Labs. Chainalysis emphasized that while blockchains are rarely the initial infection vector, they have become a critical component in the sophistication and resilience of modern malware operations.
The Indus Pulse is committed to accuracy and transparency.