AI fuels 440% surge in hackers using blockchains in attacks
Chainalysis has run the numbers, and the numbers say 440 per cent — a rise in hackers embedding malicious code into blockchains, which is the crypto equivalent of hiding a landmine in the pavement. Two such cases a day was the baseline before the middle of 2025, a figure the report treats as the quiet before something. Then came the open-source models, and the quiet stopped. Four hundred and forty per cent is not a drift; it's a change of address. The charming detail is that these attacks are now harder to detect and block, which is what a permanent ledger does when someone writes something permanent into it and nobody can rub it out.
The detail worth savouring is the phrasing: 'powerful Chinese open-source AI models with no restrictions on generating malicious code.' Not models that were jailbroken, not models whose guardrails slipped — models that shipped without guardrails because nobody had written a rule requiring any. The open-weights movement has spent years insisting unrestricted release is a public good, and Chainalysis has helpfully provided the receipts, denominated in malware. Somewhere a venture partner is still calling this 'democratising capability' into a microphone. Two incidents a day was a manageable line item; 440 per cent is a budget.
And who is cashing the cheque? State-backed groups from North Korea and Iran, per the report — the world's least sentimental early adopters, running blockchain malware at industrial scale while the rest of us convene working groups about whether to convene a working group. The models landed in mid-2025; the 440 per cent arrived right on schedule, which is the sort of punctuality you'd praise in a contractor. Every safety researcher who said open weights would be weaponised was told they were stifling innovation, and told it by people with term sheets. They were not stifling innovation. They were counting.