AI fuels 440% surge in hackers using blockchains in attacks

Read the original at The Straits Times ↗
The Straits Times · collected 2026-09-18 · by The Straits Times

Quick Summary

Artificial intelligence is enabling a significant increase in hacking activities involving blockchains, with incidents rising 440% from two per day before mid-2025 to eleven cases daily. According to a report by Chainalysis published on September 17, hackers are using AI to hide malicious code within blockchain transactions and smart contracts, making attacks harder to detect and stop due to the immutable nature of blockchains. State-backed groups, especially those linked to North Korea and Iran, now dominate this type of cyber activity, leveraging blockchains for their operations where conventional methods might face restrictions or obstacles.
Written locally by qwen2.5:14b on 2026-09-18, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

Open-source artificial intelligence is enabling hackers to more easily hide malicious code within blockchains, leading to a significant rise in cyber threats. According to a report published by Chainalysis on September 17, instances of malware instructions embedded in on-chain transactions and smart contracts have surged by 440% over the past year, with an average of 11 cases per day. Prior to the release of powerful Chinese open-source AI models in mid-2025, such incidents occurred at a rate of just two per day. Hackers are now using blockchains as "dead drops" to leave instructions for malware, making these attacks harder to detect and neutralize due to the immutable nature of blockchain records.

Written for “AI Enabled Cyber Attacks Increase” on 2026-09-18, grounded in this article and the 0 other(s) covering the same event.
Why this leaning score
This article does not take a side on a contested political question, so it has no leaning score. That is an answer rather than a gap: a match report or a rescue can be warmly or critically written without being left or right, and scoring it anyway is how approval of a subject gets recorded as a political position.
No political leaning scored for article 17773 · logged 2026-09-18

Signals How these are calculated →

Claims extracted
16
claim-shaped sentences
Uncertain
31%
5 of 16 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
58.9
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
1
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-18 · how these are computed

Story

📰 AI Enabled Cyber Attacks Increase
Technology · 1 article(s) covering the same event.

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 31% of its claims. Each row says how that neighbour differs.
Daily Mail
⚖️ leaning not scored 🔴 19% hedged 6 of 31 📰 publisher trust 59
“The articles describe different aspects of cybersecurity threats related to AI, but they are not reporting on the exact same incident.”
September 13, 2026 different event · 98%
Letters from an American
⚖️ Leans left 🔴 15% hedged 10 of 65
“Article A discusses a CEO's essay about AI advancements and safety concerns, while Article B reports on an increase in blockchain-based cyber attacks fueled by AI.”
Persuasion
⚖️ leaning not scored 🔴 19% hedged 22 of 113
“The articles describe different aspects and incidents related to AI security, not the same specific occurrence.”
Washington Examiner
⚖️ Leans left 🔴 11% hedged 6 of 57 📰 publisher trust 96
“The articles discuss different aspects of AI impact, one focusing on opposition to data centers and the other on increased use of blockchains in cyber attacks.”
Al Jazeera
⚖️ Leans left 🔴 15% hedged 8 of 55 📰 publisher trust 96
“The articles discuss different aspects of AI, one focusing on calls to slow down AI development and potential risks, while the other reports on an increase in hackers using blockchains for malicious purposes due to advancements in open-source AI.”
Fox News
⚖️ Leans strongly right 🔴 11% hedged 4 of 38 📰 publisher trust 95
“The articles discuss different aspects of AI-related concerns, with Article A focusing on general warnings about AI safety and control, while Article B reports on a specific increase in hackers using blockchains for attacks fueled by AI.”
The Straits Times
⚖️ Leans left 🔴 24% hedged 17 of 70 📰 publisher trust 59
“The articles discuss different aspects of AI and cybersecurity, with Article A covering general fears about loss of control over AI while Article B focuses on a specific increase in blockchain-based cyber attacks fueled by AI.”
Semafor
⚖️ Leans strongly left 🔴 8% hedged 4 of 48 📰 publisher trust 95
“The articles discuss different aspects of AI and blockchain, with Article A focusing on Democratic political action against AI and Article B reporting a surge in hackers using blockchains for attacks due to AI.”
CBS News
⚖️ leaning not scored 🔴 28% hedged 5 of 18 📰 publisher trust 71
“The articles describe different aspects of AI-related cyber threats; one warns about potential future attacks while the other reports on a recent surge in hackers using blockchains.”
New York Post
⚖️ leaning not scored 🔴 28% hedged 7 of 25 📰 publisher trust 59
“Article A discusses Andrew Yang's concerns about AI self-replicating code on the internet, while Article B reports on a surge in hackers using blockchains for malicious purposes due to open-source AI. These are different specific events.”

Publisher

The Straits Times · 633 article(s) · 1 correction(s) detected
Running correction rate · 1 correction(s)
2026-09-13
Russia hits Ukrainian-Polish border area, Kyiv says

Who wrote this

The Straits Times
425 article(s) here · 1 carrying a prediction
🔮 Worsening the threat, open-source AI models can be run independently, allowing hackers to modify them or remove safeguards against cybercrime. “This gives malicious developers greater control over the model and more privacy, because they do not have to submit their source code to large cloud providers that may monitor their platforms for abuse,” Kamluk said.
🔮 The unusually direct rebuke from a Republican comes as the party controlling Congress and the White House faces growing concern that aggressive immigration enforcement could erode gains the president made among Latino voters in 2024.
🔮 Inside Microsoft and OpenAI, worry about damaging the publishing industry Karen Weise and Mike Isaac SAN FRANCISCO - Newly unsealed court documents showed considerable concern within Microsoft and its close partner OpenAI over the use of millions of news articles to develop artificial intelligence systems. As OpenAI was forging ahead with its work, Microsoft employees debated whether what OpenAI was doing represented the “largest theft of labour in human history” and could create a “doom loop” that could ultimately threaten the quality of the large language models they were building.
🔮 “On the other side of the Atlantic, we are seeing a change in political attitudes, a change in the assessment of the transatlantic alliance, which we might not have thought possible.”
🔮 Anthony James Kazmierczak pleaded guilty in May and admitted to attacking Omar because he disagreed with her progressive political views.
🔮 CSIS said two new communications compounds that had appeared at the base since mid-2024 likely form part of a broader intelligence and military command architecture, and would strengthen communications between Chinese forces operating in the Middle East and Africa and military headquarters in China. “The type and orientation of the base’s new equipment is varied, enabling transmission and detection across a wide range of signals and frequencies,” the report said.
🔮 Anthony James Kazmierczak pleaded guilty in May and admitted to attacking Omar because he disagreed with her progressive political views.
🔮 US said to delay excess capacity tariffs until after Xi summit AI generated The US is expected to delay the announcement of new tariffs over allegations of trading partners’ excess manufacturing capacity at least until after next week’s planned summit between Chinese President Xi Jinping and US President Donald Trump, according to people familiar with the matter.
🔮 Under the announced guidance, women were also set to be screened through a questionnaire and could then move to treatment for conditions related to hormonal imbalances.
🔮 The US government’s use of Qwen emerged amid a global reckoning about AI safety and a US debate over whether regulatory safeguards on AI are needed or would put the country at a competitive disadvantage.
More on this subject from The Straits Times
Are we losing control of AI? What’s driving new fears
2026-09-15 · The Straits Times · 65% similar
AI could pose 'existential' risk to humanity, UN rights chief warns
2026-09-07 · The Straits Times · 56% similar
All 425 articles by The Straits Times →

Topics

Chainalysis Chinese North Korea SAN FRANCISCO – TitanHex

Subjects

Chainalysis ORG · 4× Kamluk ORG · 2× Chinese NORP · 1× Eric Jardine PERSON · 1× Iran GPE · 1× North Korea GPE · 1× SAN FRANCISCO – GPE · 1× TRM Labs ORG · 1× TitanHex ORG · 1× Vitaly Kamluk PERSON · 1×

Narrative

AI fuels 440% surge in hackers using blockchains in attacks AI generated SAN FRANCISCO – Open-source artificial intelligence is making it easier for hackers to hide malicious code on blockchains, opening a new front in a crypto industry already grappling with rising cybercrime. Instances of malware instructions written into on-chain transactions and smart contracts are up 440 per cent in less than a year, averaging 11 cases per day, blockchain analytics firm Chainalysis said in a report published on Sept 17.
framing: mixed · carried by 1 article(s) · first seen 2026-09-18
🔮 Worsening the threat, open-source AI models can be run independently, allowing hackers to modify them or remove safeguards against cybercrime. “This gives malicious developers greater control over the model and more privacy, because they do not have to submit their source code to large cloud providers that may monitor their platforms for abuse,” Kamluk said.
2026-09-18 · The Straits Times
AI fuels 440% surge in hackers using blockchains in attacks · mixed framing

Claims (16 extracted, 5 hedged)

AI fuels 440% surge in hackers using blockchains in attacks AI generated SAN FRANCISCO – Open-source artificial intelligence is making it easier for hackers to hide malicious code on blockchains, opening a new front in a crypto industry already grappling with rising cybercrime. Instances of malware instructions written into on-chain transactions and smart contracts are up 440 per cent in less than a year, averaging 11 cases per day, blockchain analytics firm Chainalysis said in a report published on Sept 17. asserted
Chainalysis → fuel → Sept
Such cases averaged two per day prior to the release in the middle of 2025 of powerful Chinese open-source AI models with no restrictions on generating malicious code, according to the report. uncertain
cases → average → report
A malware attack uses malicious software planted on a computer or network to steal information, passwords or funds. asserted
attack → use → information
In the attacks documented by the report, hackers use a blockchain to leave instructions for that software, such as the location of the server that controls it, a technique known as a “blockchain dead drop.” asserted
that → document → drop
This can make an attack harder to stop because information recorded on a blockchain cannot be easily removed. “When malware uses a blockchain to relay key information – for example, where to find its latest active command-and-control server – its attempts to reconnect with the attacker become much harder to block effectively,” said Vitaly Kamluk, founder of cybersecurity consultancy TitanHex. asserted
Kamluk → make → TitanHex
State-backed groups – including those linked to North Korea and Iran – now account for the majority of this activity, the report said. asserted
report → back → activity
Blockchains can appeal to state-linked groups in countries where renting servers or paying for hosting can trigger security checks or run into payment obstacles, according to Kamluk. uncertain
renting → appeal → Kamluk
The findings add to evidence of generative AI contributing to a boom in cyber threats by spotting more software vulnerabilities and allowing cybercriminals to carry out more attacks. asserted
cybercriminals → add → attacks
In crypto, the number of hacks rose roughly 150 per cent to 207 in the first half of the year, according to blockchain intelligence firm TRM Labs. uncertain
number → rise → Labs
Blockchains are typically not involved in the initial infection of a machine, which often happens through conventional means such as supply-chain attacks or malicious downloads, Eric Jardine, head of research at Chainalysis, said in response to questions over email. asserted
Jardine → involve → email
The firm cannot determine from blockchain data how many attacks succeeded or how much money was lost, he added. asserted
he → determine → data
Hiding malware on a blockchain is not new, Chainalysis said, but powerful new open-source AI models are allowing hackers to carry out attacks on a larger scale, while growing involvement by state actors is making them more sophisticated. asserted
them → hide → actors
Worsening the threat, open-source AI models can be run independently, allowing hackers to modify them or remove safeguards against cybercrime. “This gives malicious developers greater control over the model and more privacy, because they do not have to submit their source code to large cloud providers that may monitor their platforms for abuse,” Kamluk said. uncertain
Kamluk → worsen → abuse
By contrast, companies such as OpenAI and Alphabet Inc’s Google can block access to their AI services when they detect abuse. asserted
they → block → abuse
The transparency of blockchains cuts both ways, though. asserted
transparency → cut → ways
Every update attackers post is permanently recorded, letting investigators map their infrastructure and connect campaigns that would otherwise look unrelated, according to Chainalysis. uncertain
that → post → Chainalysis
💬 Give feedback
🕘 History 🎫 Support