Chainalysis Reports Surge in Onchain Malware Tied to State-Sponsored Hackers
A new report from Chainalysis highlights a concerning trend in the rise of onchain malware associated with state-sponsored hackers. The report indicates that North Korean and Iranian threat actors are increasingly using public blockchains to host malware payloads and command-and-control instructions.
Key Findings from the Report
- North Korean cyber groups stole approximately $2 billion in digital assets in 2025, marking a 51% increase from the previous year.
- Total illicit cryptocurrency flows reached at least $154 billion in 2025, a staggering 162% year-over-year increase.
- Stablecoins have become the primary medium for these illicit transactions, with significant amounts processed by sanctioned entities.
Chainalysis has identified a technique termed 'blockchain dead drops' (BDDs), where attackers embed malware instructions directly into blockchain transactions. This method leverages the immutability and censorship resistance of blockchains, making it difficult to remove malicious content once it is posted.
As state-sponsored actors ramp up their operations, compliance teams at exchanges and digital asset platforms will need to adapt their monitoring strategies to detect not only sanctioned addresses but also transactions that may contain embedded malware instructions.
FAQ
What is the main focus of the Chainalysis report?
The report highlights the rise of onchain malware associated with state-sponsored hackers, particularly from North Korea and Iran, who are using public blockchains to host malware payloads and command-and-control instructions.
How much digital assets did North Korean cyber groups steal in 2025?
North Korean cyber groups stole approximately $2 billion in digital assets in 2025, which represents a 51% increase from the previous year.
What is the total illicit cryptocurrency flow reported for 2025?
The total illicit cryptocurrency flows reached at least $154 billion in 2025, marking a staggering 162% year-over-year increase.
What are blockchain dead drops (BDDs)?
Blockchain dead drops (BDDs) are a technique identified by Chainalysis where attackers embed malware instructions directly into blockchain transactions, leveraging the immutability and censorship resistance of blockchains.
How should compliance teams at exchanges adapt according to the report?
Compliance teams at exchanges and digital asset platforms need to adapt their monitoring strategies to detect not only sanctioned addresses but also transactions that may contain embedded malware instructions.
Comments
Comments are moderated before publish.
No comments yet — be the first.