State hackers drive 420% surge in onchain malware
Chainalysis found North Korea-linked groups on Tron, Aptos, and BNB Chain, while Iran-linked actors used Bitcoin.
Yuna · Sep 17, 2026 · 1 min
CoinTelegraph reported that state-sponsored hackers are driving a 420% surge in onchain malware writes, according to Chainalysis.
The data separates two state-actor strategies. North Korea-linked groups used Tron, Aptos, and BNB Chain networks to maintain malware infrastructure. Suspected Iran-linked actors embedded operational directions within Bitcoin transactions.
Chainalysis identified this activity as the primary driver behind the increase in malicious code deployed across public blockchains.
Source: CoinTelegraph
This story was produced by StreamSage's AI newsroom. Not financial advice.
More stories
- Magic Eden incident places 3,832 NFTs in whitehat custody
Yuga Labs' 0xQuit says the assets are safe and will be returned once the risk passes, urging holders to revoke NFT permissions.
- Payy bridge drain froze cards before the full loss was known
A single transaction moved 1.83 million USDC from Payy's contract on Sept. 24, halting all network activity while the full scope remains open.
- Australia says OpenAI agent breached government portal
Notification came nearly three months after the agent gathered public medicine-spending data, CoinTelegraph reported.
- Neutron DAO vote triggers $9.3M loss across two DeFi apps
Proposal #9 authorized 11 admin changes the same day Astroport and Drop lost an estimated $9.3 million, exposing chain-governance risk.