Open-source AI drives surge in malware hidden on blockchains

Photo: Tima Miroshnichenko / Pexels

Open-source AI drives surge in malware hidden on blockchains

Chainalysis says malware instructions embedded in transactions and smart contracts rose 440% in less than a year.

Open-source artificial intelligence is helping hackers hide malware instructions on blockchains, creating a new cybercrime front as attacks against the crypto industry increase.

Blockchain analytics firm Chainalysis said cases involving malware instructions embedded in on-chain transactions and smart contracts rose 440% in less than a year. The activity averaged 11 cases per day, up from two daily cases before powerful open-source Chinese AI models became widely available in the middle of last year.

The technique, known as a blockchain dead drop, uses transactions or smart contracts to tell malware where to send stolen information, passwords or funds. Because blockchain records are difficult to remove, the instructions can be harder to erase or disrupt.

Advertisement

State-backed groups linked to North Korea and Iran now account for most of the activity, according to Chainalysis. The firm said it has not determined how many of the attacks succeeded or how much money was lost.

Eric Jardine, Chainalysis’s head of research, said blockchains are usually not involved in the initial infection, which often comes through supply-chain attacks or malicious downloads. Hiding malware on a blockchain is not new, but open-source AI models are allowing hackers to operate at greater scale and state actors are making campaigns more sophisticated.

Open-source models can be run independently, modified or stripped of safeguards against cybercrime. Vitaly Kamluk, founder of cybersecurity consultancy TitanHex, said that gives malicious developers more control and privacy.

The transparency of public blockchains also gives investigators a way to map attackers’ infrastructure and connect campaigns that might otherwise appear unrelated. Chainalysis said every update posted by attackers remains permanently recorded.

The findings come as crypto hacks increase. TRM Labs said the number of hacks rose about 150% to 207 in the first half of the year, although losses remained below $1 billion.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Open-source AI drives surge in malware hidden on blockchains
Open-source AI drives surge in malware hidden on blockchains

Chainalysis says malware instructions embedded in transactions and smart contracts rose 440% in less than a year.

Share

Add us on Google

Photo: Tima Miroshnichenko / Pexels

Open-source artificial intelligence is helping hackers hide malware instructions on blockchains, creating a new cybercrime front as attacks against the crypto industry increase.

Blockchain analytics firm Chainalysis said cases involving malware instructions embedded in on-chain transactions and smart contracts rose 440% in less than a year. The activity averaged 11 cases per day, up from two daily cases before powerful open-source Chinese AI models became widely available in the middle of last year.

The technique, known as a blockchain dead drop, uses transactions or smart contracts to tell malware where to send stolen information, passwords or funds. Because blockchain records are difficult to remove, the instructions can be harder to erase or disrupt.

Advertisement

State-backed groups linked to North Korea and Iran now account for most of the activity, according to Chainalysis. The firm said it has not determined how many of the attacks succeeded or how much money was lost.

Eric Jardine, Chainalysis’s head of research, said blockchains are usually not involved in the initial infection, which often comes through supply-chain attacks or malicious downloads. Hiding malware on a blockchain is not new, but open-source AI models are allowing hackers to operate at greater scale and state actors are making campaigns more sophisticated.

Open-source models can be run independently, modified or stripped of safeguards against cybercrime. Vitaly Kamluk, founder of cybersecurity consultancy TitanHex, said that gives malicious developers more control and privacy.

The transparency of public blockchains also gives investigators a way to map attackers’ infrastructure and connect campaigns that might otherwise appear unrelated. Chainalysis said every update posted by attackers remains permanently recorded.

The findings come as crypto hacks increase. TRM Labs said the number of hacks rose about 150% to 207 in the first half of the year, although losses remained below $1 billion.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.