AI Makes It Easier for Hackers to Hide Malware in Blockchain, Attacks Surge 440%
Baca dalam 60 detik
- Aktivitas blockchain berbahaya naik 440% setelah model AI open source China tanpa filter mempermudah peretasan.
- Kelompok terkait negara seperti Korea Utara dan Iran memakai TRON, Aptos, dan Bitcoin untuk menyimpan perintah malware.
- Memblokir lalu lintas blockchain berisiko mengganggu dompet digital dan layanan keuangan terdesentralisasi global.

Hackers are now exploiting public blockchains to hide malware instructions, creating communication channels that stay alive even after conventional servers are shut down. The latest data from Chainalysis shows a 440% surge in malicious blockchain activity, with daily entries rising from 2.06 to 11.1 since the emergence of new-generation AI systems.
This blockchain technique, known as a "dead drop," uses transaction data or smart contracts as a lookup point. Infected computers can retrieve commands, addresses, or configuration information from a ledger distributed across many nodes. Because blockchain records are distributed, taking down ordinary servers does not erase information already stored on the block chain.
An operation linked to North Korea, known as UNC5342, uses TRON and Aptos as alternative routes before retrieving encrypted instructions via BNB Chain. Their malware can check one network, switch to another if needed, and fetch the latest address without having to receive a new malware package. Meanwhile, Iranian actors suspected of ties to the intelligence ministry embed encoded routing information inside Bitcoin transactions for malware retrieval. Russian-speaking cybercriminals have even commercialized the technique, using Polygon contracts to provide blockchain-based infrastructure to various customers.
The surge is inseparable from the role of AI. According to Chainalysis, the emergence of high-capacity Chinese open source models that are more permissive about malware development requests has accelerated the trend. Previously, building blockchain-based malware infrastructure required expertise in malicious software, cryptocurrency networks, and distributed communication systems. Now, AI tools lower the knowledge barrier by helping less experienced operators understand unfamiliar technology and produce the necessary components.
"While blockchain exploitation by state-linked organizations such as North Korea is becoming more sophisticated, the on-chain records attackers leave behind can actually serve as important clues to track them," said Kwon Jun-hyeok, General Manager of Chainalysis Korea. "Tracking these traces and identifying attackers and related infrastructure through blockchain intelligence will become increasingly crucial in responding to new cyber threats."
For Indonesia, this development poses a double challenge. On one hand, cryptocurrency and blockchain adoption continues to grow, with Bappebti recording a significant value of national crypto asset transactions. On the other hand, regulators and law enforcement face difficulties because blocking blockchain traffic risks disrupting legitimate digital wallets, decentralized applications, exchanges, and decentralized finance services. Authorities such as BSSN and Kominfo need to strengthen on-chain monitoring without hindering innovation.
Defenders also face a dilemma: attackers can operate their own blockchain nodes, reducing reliance on external providers that can be pressured. Some operators hide server addresses inside wallet identifiers with no usable private key, then use zero-value transfers to trigger malware retrieval. Such transactions leave a public trail that investigators can examine, potentially becoming valuable clues even as attackers try to obscure their infrastructure.
Going forward, the question is not only how to block, but how to use public blockchain records as a tracking tool. If AI keeps lowering the expertise threshold, will global regulators be able to adapt before blockchain-based malware infrastructure becomes the new standard?



