Skip to content

Invest2 publishers2 min readPublished

Iran-linked malware takes its orders from a Bitcoin address once tied to Satoshi

Chainalysis logged a 420% rise in onchain malware writes for its 2026 crime report, and says suspected Iranian operators ran their update channel through a permanent public Bitcoin address nobody can take offline.

The Investor · Invest desk

Illustration accompanying Iran-linked malware takes its orders from a Bitcoin address once tied to Satoshi

What happened

  • Chainalysis's 2026 Crypto Crime Report records a 420% surge in onchain malware linked to state-sponsored hackers.
  • North Korea-linked groups have been hosting malware payloads and command-and-control instructions on public chains including Tron, Aptos and BNB Chain, the firm says.
  • Chainalysis also identified actors it suspects are linked to Iran's Ministry of Intelligence writing encoded command-and-control routing data onto the Bitcoin blockchain.
  • North Korean cyber groups stole approximately $2 billion in digital assets over 2025, a 51% increase on the prior year, according to the report.
  • Total illicit cryptocurrency flows reached at least $154 billion in 2025, a 162% rise, with sanctioned entities receiving at least $104 billion of on-chain transactions.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Seizing a server and revoking a domain, the two standard answers to a command-and-control host, do not reach instructions already written to an immutable ledger, so the response falls back on the infected machine.
  • cost Crypto Briefing argues screening will have to cover what a transaction contains, on top of who sits on either end of it, and exchange compliance budgets are where that lands.
  • exposure Stablecoin bills are moving through Congress with a $93 billion single-token figure now on the record, and issuers are the parties any freeze or screening duty would reach.

The hosting bill for the Iranian channel, on the account Chainalysis gave Cointelegraph, was a few small Bitcoin payments from attacker-controlled wallets to a well-known address with historical ties to Satoshi Nakamoto. The firm said that address had no connection to the attackers and simply sat there as a permanent public place for infected devices to check for updated directions [18]. Moving to new servers takes one more published transaction, after which the infected devices retrieve the new information themselves [19]. Everything after that happens offchain: remote access, credential theft, delivery of further malware [20].

The losses are still theft, and they concentrate hard. Chainalysis tracks cumulative North Korean theft above $6.75 billion [5], so last year is roughly three-tenths of the whole attributed history [1] and about $4.75 billion sits across all the years before it [6]. The Bybit exploit accounted for $1.5 billion of 2025 [4], which is 75% of the year and leaves about $500 million for everything else [2].

Set against total illicit flows of at least $154 billion [6], North Korea's take is about 1.3% [3]. Russia's A7A5 stablecoin alone processed over $93 billion [8], or close to 60% of the entire illicit total [4]. Sanctioned entities received at least $104 billion onchain, up 694% [7]; a 694% rise puts the prior-year base near $13 billion [5].

What Chainalysis has on artificial intelligence is timing. The firm recorded a 440% increase in malicious blockchain writes since July 2025, when it says high-capacity open-source Chinese models became capable of producing malicious code with limited safeguards [14]. Eric Jardine, the firm's cybercrimes research lead, told Cointelegraph they found a "clear point-in-time association." They could not prove that the actors publishing the malicious transactions and contracts had used the models to increase their output [15]. The Iranian attribution, Chainalysis said, rested on malware family, decoding method, timing and server infrastructure tied to previously reported Iranian operations, not on the blockchain activity alone [17].

Both reports give the percentages and leave out the absolute number of malicious writes behind them [7]. That decides what the 420% is worth: on a base of several hundred writes it is a few thousand transactions, and on a base of twenty it is a hundred. On the evidence published so far the large sums sit in the theft figures, and the onchain tooling finding is a detection cost handed to whoever has to spot a lookup that Chainalysis says network monitors watching for conventional communication patterns will not flag [21]. If the firm publishes write counts in the thousands, that reading is wrong.

What to watch

  • Whether Chainalysis publishes the absolute write counts underlying the 420% and 440% figures.
  • Whether the stablecoin bills moving through Congress attach screening or freeze duties to issuers after the $93bn A7A5 number.
  • Whether any large exchange starts screening transaction contents for embedded instructions and discloses what it costs.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories