Abuse of Open-Weight AI Spreads as On-Chain Malware Attacks Jump 440%
Summary
- Chainalysis said on-chain cyberattacks using open-weight AI models have risen to an average of 11 a day, up about 440% from a year earlier.
- TRM Labs said there were 207 cryptocurrency hacks in the first half of this year, up about 150% from a year earlier, and that open-weight AI is being used as a tool to increase both the scale and sophistication of attacks.
- The report said state-backed hacking groups, including organizations linked to North Korea and Iran, account for a large share of on-chain malware attacks, and that blockchain-based infections are often combined with traditional methods such as supply-chain attacks.
Forecast Trend Report by Period



Cyberattacks that use open-weight artificial intelligence models to embed malicious instructions on blockchains are surging.
Bloomberg reported on September 17 that blockchain analytics firm Chainalysis said in a recent report that on-chain cyberattacks using open-weight AI models are rising rapidly. Incidents involving malicious code embedded in on-chain transactions and smart contracts have climbed to an average of 11 a day, up about 440% from an average of two a day a year earlier.
Attackers use open-weight AI to create malware or manipulated smart contracts and then deploy them on a blockchain. They then lure victims into interacting with those contracts to steal digital assets or account credentials. On-chain transactions are records of transfers such as Bitcoin and Ether written to a blockchain. Smart contracts are programs that execute automatically when preset conditions are met.
Chainalysis said such attacks increased noticeably after Chinese open-weight AI models were released in mid-2025. Some models either lack safeguards that block requests to generate malware or allow users to remove those controls themselves.
Open-weight models can be downloaded and run directly on a user's own computer. That makes it easier for developers to weaken or remove safety features and relatively easier to avoid outside monitoring. By contrast, closed AI systems such as ChatGPT and Claude are controlled by their operators, which can block malicious requests or restrict user accounts.
Hackers are also using a tactic known as a blockchain dead drop. Under that method, malware is designed to retrieve the destination for transmitting stolen data or receive additional instructions from a blockchain. Because data recorded on a blockchain is difficult to delete or alter, the attack infrastructure is also harder to disrupt. The report said state-backed hacking groups, including organizations linked to North Korea and Iran, account for a large share of these attacks.
Cyberattacks targeting digital assets more broadly are also increasing. According to blockchain analytics firm TRM Labs, there were 207 crypto hacks in the first half of this year, up about 150% from a year earlier. Eric Jardine, Chainalysis's cybercrimes research lead, said blockchain-based infections are often combined with traditional methods such as supply-chain attacks or malicious file downloads.
Chainalysis said open-weight AI is being used as a tool to expand the scale of hackers' operations and make their methods more sophisticated. Vitali Kamluk, founder of cybersecurity consulting firm TitanHex, said open-weight AI gives malicious developers control over models and a high degree of anonymity.
YM Lee
20min@bloomingbit.ioCrypto Chatterbox_ tlg@Bloomingbit_YMLEE