Edited by Editor-in-Chief, The Indus Pulse 18 Sept 2026, 06:23 PM 3 min readtech
Open-Source AI Triggers 440% Surge in Blockchain Malware Attacks
Open-source artificial intelligence models have driven a 440 per cent surge in hackers embedding malware instructions directly into blockchains, creating a persistent technical hurdle for cybersecurity teams. According to findings published on Sept 17 by blockchain analytics firm Chainalysis, malicious code embedded in on-chain transactions and smart contracts now averages 11 cases per day.
Prior to the release of powerful Chinese open-source AI models in mid-2025 featuring minimal restrictions on generating malicious code, similar blockchain-based malware incidents averaged just two per day. Cybersecurity analysts note that these unrestricted models give attackers unprecedented independence and privacy, bypassing cloud-service monitoring systems that typically scan and block abusive development.
Mechanics of Blockchain Dead Drops
In the attacks documented by researchers, hackers utilize a technique known as a blockchain dead drop. Rather than executing payloads immediately, the malicious software reads permanent on-chain transactions to locate its active command-and-control server.
Because blockchain records cannot be easily modified or deleted, shutting down these relay points proves significantly more difficult than traditional web infrastructure. Vitaly Kamluk, founder of cybersecurity consultancy TitanHex, explained that when malware relies on a blockchain to relay critical connection instructions, reconnect attempts become substantially harder to block effectively.
State-backed groups, particularly those linked to North Korea and Iran, currently account for the majority of this activity. Security analysts indicate that decentralized ledgers offer structural advantages to state-linked operatives in sanctioned jurisdictions, allowing them to bypass traditional payment obstacles and hosting security checks associated with conventional server rentals.
Scale of Crypto Cybercrime and Infection Vectors
While the blockchain facilitates persistent instruction delivery, security researchers emphasize that distributed ledgers are rarely involved in the initial system compromise. Eric Jardine, head of research at Chainalysis, stated that primary device infections typically occur via conventional pathways such as malicious software downloads or supply chain compromises.
This trend coincides with a broader escalation in digital asset security threats. Data from blockchain intelligence firm TRM Labs indicates that cryptocurrency-related hacks rose approximately 150 per cent to 207 incidents during the first half of 2026.
Although Chainalysis cannot determine exact financial losses or success rates from immutable blockchain data alone, the sheer volume of embedded instructions highlights how generative AI tools scale attack complexity.
Tracing Infrastructure Through Immutable Records
Despite complicating containment efforts, the inherent transparency of distributed ledgers provides investigators with a distinct investigative advantage. Every data update posted by an attacker is permanently recorded on-chain, enabling cybersecurity professionals to map adversary infrastructure and link previously isolated threat campaigns.
As open-source AI models continue to evolve without centralized platform oversight, law enforcement and blockchain intelligence firms rely on this immutable ledger trail to connect disparate attacks and trace large-scale malicious operations.
Sources & Citations
The Indus Pulse is committed to accuracy and transparency.

