Photo: Julio Lopez / Pexels
Chainalysis reports 420% surge in onchain malware linked to state hackers
North Korean and Iranian cyber groups are now using public blockchains like Tron, Aptos, and BNB Chain as infrastructure for malware operations, according to new findings from the blockchain analytics firm.
State-sponsored hackers aren’t just stealing crypto anymore. They’re building their attack infrastructure directly on top of it.
Chainalysis’s 2026 Crypto Crime Report reveals that North Korea-linked threat actors have begun using public blockchains to host malware payloads and command-and-control instructions. Separately, suspected Iran-linked actors have been embedding operational commands directly into Bitcoin transactions, using the network’s immutability as a feature rather than a bug.
The numbers behind the threat
North Korean cyber groups stole approximately $2 billion in digital assets over 2025, a 51% increase compared to the prior year. The single largest contributor was the $1.5 billion Bybit exploit. Cumulative theft attributed to North Korea, as tracked by Chainalysis, now exceeds $6.75 billion.
Total illicit cryptocurrency flows reached at least $154 billion in 2025, a 162% year-over-year increase. Sanctioned entities received at least $104 billion in on-chain transactions, up 694% from the previous year. Stablecoins dominated that illicit volume, with Russia’s A7A5 token alone processing over $93 billion.
Blockchains as malware infrastructure
North Korea-linked groups have been deploying malware payloads and instructions on public blockchains including Tron, Aptos, and BNB Chain. Data stored on a blockchain is immutable and censorship-resistant by design. Once malware instructions are embedded in a transaction, no single entity can take them down. There’s no server to seize, no domain to revoke.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Iran-linked actors embedded operational directions within Bitcoin transactions themselves. Because Bitcoin’s ledger is permanent and publicly accessible, these embedded commands can be read by malware agents anywhere in the world without raising suspicion from network monitors looking for traditional communication patterns.
Stablecoins at the center
With stablecoins dominating illicit cryptocurrency volumes in 2025, the findings arrive at a particularly inconvenient moment for the industry. US lawmakers are actively working on stablecoin legislation, with multiple bills advancing through Congress. Tether has previously frozen wallets associated with sanctioned entities, but the scale of flows documented in the report suggests that reactive measures aren’t keeping pace with the problem.
What this means for the industry
For exchanges and digital asset platforms, compliance teams will need to screen not just for sanctioned addresses but for transactions that might contain embedded malware instructions. The Bybit exploit alone, at $1.5 billion, demonstrated that even major exchanges remain vulnerable to sophisticated state-backed attacks.
North Korean crypto theft increased 51% year-over-year. Sanctioned entity flows surged 694%. Total illicit volumes rose 162%.