Chainalysis has flagged a massive spike in abuse of public blockchains: over the past year, the number of malicious instructions and infrastructure data recorded on-chain jumped by 420%. These entries are directly written into blockchain networks and serve as part of malicious operations.
What Chainalysis Found
The research highlights a sharp rise specifically in entries containing malicious instructions and infrastructure info ending up on public ledgers. With a 420% year-over-year increase, it’s clear that blockchains are increasingly being used as a channel for storing and distributing this type of data.
State-Backed Hackers’ Share
Roughly two-thirds of this new activity each quarter is tied to state-sponsored hackers. Chainalysis identified campaigns by groups out of North Korea and likely Iran, where blockchain entries were used as part of coordinated malicious operations.
What It Means for the Industry
This trend shows public blockchains are becoming a go-to for attackers looking for resilient, distributed storage for operational data. For the ecosystem, this means on-chain artifacts need to be closely monitored, and incident response procedures must adapt to the challenges of immutable ledgers.
