Open-source AI boosts blockchain hacking 440%

Open-source artificial intelligence facilitates the concealment of malicious code on blockchains, thereby introducing a new challenge for an already beleaguered crypto industry facing escalating cybercrime. According to a report released on Thursday, there has been a staggering 440% increase in instances of malware instructions embedded within on-chain transactions and smart contracts over the past year, with an average of 11 cases occurring daily. According to the report, such cases averaged two per day before the release of powerful Chinese open-source AI models in the middle of last year, which had no restrictions on generating malicious code. A malware attack employs malicious software embedded within a computer or network to appropriate information, passwords, or financial resources. In the attacks outlined in the report, hackers employ a blockchain to embed instructions for the software, including the server’s location that governs it, a method referred to as a “blockchain dead drop.” This can complicate efforts to halt an attack, as information documented on a blockchain is not readily deletable.

“When malware uses a blockchain to relay key information – for example, where to find its latest active command-and-control server – its attempts to reconnect with the attacker become much harder to block effectively,” stated Vitaly Kamluk. The report indicated that state-backed groups, particularly those associated with North Korea and Iran, now represent the majority of this activity. According to Kamluk, blockchains may attract state-affiliated entities in nations where the act of renting servers or securing hosting services could provoke security scrutiny or encounter financial transaction hurdles. The findings contribute to the body of evidence indicating that generative AI is facilitating a surge in cyber threats by identifying an increasing number of software vulnerabilities and enabling cybercriminals to execute a greater volume of attacks. In the realm of cryptocurrency, the incidence of hacks surged approximately 150%, reaching a total of 207 in the first half of the year, as reported by blockchain intelligence firm TRM Labs.

Blockchains are generally not implicated in the initial compromise of a machine, which frequently occurs through traditional methods like supply-chain attacks or harmful downloads, stated Eric Jardine, head of research at Chainalysis, in an email response to enquiries. The firm is unable to ascertain from blockchain data the number of successful attacks or the extent of financial losses incurred, he added. According to Chainalysis, the concealment of malware within blockchain technology is not a novel concept. However, the emergence of advanced open-source AI models is enabling cybercriminals to execute attacks on a more extensive scale. Additionally, the increasing participation of state actors is contributing to the sophistication of these threats.

Worsening the threat, open-source AI models can be operated autonomously, enabling hackers to alter them or eliminate protections against cybercrime. “This gives malicious developers greater control over the model and more privacy, because they do not have to submit their source code to large cloud providers that may monitor their platforms for abuse,” Kamluk stated. In contrast, firms like OpenAI and Alphabet Inc.’s Google possess the capability to restrict access to their AI services upon identifying instances of misuse. The transparency of blockchains presents a dual-edged characteristic, however. Every update posted by attackers is permanently recorded, allowing investigators to map their infrastructure and link campaigns that might otherwise appear unrelated, as noted by Chainalysis.

We use cookies to improve your experience.
Privacy Policy