Whale 0x9a80, who bought 30M $ENA($8.3M) 3 days ago, bought another 7.96M $ENA($1.99M)...
Whale that bought 30 million ENA three days ago buys another 7.96 million
100,000,000 $USDC (100,015,350 USD) transferred from #Ethena to unknown wallet...
Arrington Capital transfers $3.44 million worth of HYPE to FalconX
Multicoin Capital announces investment in DePIN project Grass, which generated $17 million in revenue in the first half of 2025 and 2026 respectively
XRP Seoul Brings Tokenization, Yield, and Privacy Firms Together
986 $BTC (82,446,607 USD) transferred from unknown wallet to Coinbase Institutional...
Kalshi is ending its volume incentive program, effective no earlier than Oct. 13,
Kalshi Ends Volume Incentive Program Effective October 13, 2026
1,827 $BTC (152,513,055 USD) transferred from #Paypal to unknown wallet...
Quant Network founder moves about 25,800 QNT worth $6.97 million after 7 years of dormancy
Quant Network founder wallet 0x48E9 moved 25,776 $QNT($6.97M) to new wallets after 7 years of...
1,826 $BTC (152,396,197 USD) transferred from unknown wallet to #Paypal...
Sentora split 50% Aave revenue, but suppliers absorb all losses
Robinhood is launching in-app perpetual futures trading in coming months, allowing
LIT briefly falls below $3.7, with $6.86 million liquidated in 4 hours
Robinhood Introduces 10x Leveraged Crypto Trading for US Users
Machi closes PUMP long for $827,000 profit, then opens $5.26 million 10x leveraged long
1,333 $BTC (111,291,916 USD) transferred from unknown wallet to unknown wallet...
Anthropic Research Highlights Zhipu GLM-5.3's Network Utilization Capabilities
VelocityDEX Launches After Audit Completion Amid Co-Founder Departure
Michael Saylor Sees $100T Digital Asset Industry With Rule Changes
Machi (@machibigbrother) closed his $PUMP long 9 hours ago, realizing a $827K profit.Right after...
1,332 $BTC (111,225,164 USD) transferred from unknown wallet to unknown wallet...
Grayscale's ETF adds $2.36 million worth of LINK
Project Eleven Acquires Riva Labs to Strengthen Post-Quantum Security Research and Engineering Capabilities
SEC sues Cryptoaiml and TSAI over alleged $15 million AI trading scam...
Binance Co-CEO Highlights Early Signs of Recovery Amid Economic Challenges
CZ: Industry Pioneers Don’t Always Remain the Biggest Winners On September 25, 2026, Binance...
177,614,496 $USDC (177,636,521 USD) transferred from unknown wallet to #Coinbase...
Robinhood to launch AI agents, 10x leverage crypto perpetual contracts, and weekend US stock trading
Fake Coinbase Texts Led to $900K Bitcoin Theft, US Seeks Seized Crypto
KLEA Crypto Daily: Tuesday, September 29, 2026
Crypto Fear and Greed Index Index Value : 71 Sentiment : Greed BTC Price : $83660 ...
153,139,246 $USDC (153,192,845 USD) transferred from Coinbase Institutional to...
Project Eleven Acquires Riva Labs to Enhance Post-Quantum Security Capabilities
Stride Proposes Orderly Shutdown of Its Liquid Staking Chain
Zano Network Stabilizes After 30-Day Blockchain Rewind to Fix Inflation Bug...
RobinhoodApp ANNOUNCES PERPS ARE ROLLING OUT FOR U.S. TRADERS ...
618 $BTC (51,432,007 USD) transferred from Coinbase Institutional to unknown wallet...
Robinhood Launches Cryptocurrency Perpetual Contracts in the US
749 $BTC (62,330,840 USD) transferred from unknown wallet to Coinbase Institutional...
Robinhood To Offer Perps In-App Using Bitstamp: Press Release ...
Robinhood Introduces AI Trading Agents and New Trading Features
SEC charged Cryptoaiml Ltd., Cryptoaiml Capital Foundation, as well as TSAI Pro Ltd.
Bitcoin Was the Asset. Now Institutions Are Building Around It
5,035 $BTC (418,671,285 USD) transferred from Coinbase Institutional to unknown...
CryptoQuant says a bitcoin correction could be near after traders' unrealized profit
Robinhood adds AI agents, perps and weekend trading in push to win active traders
Hut 8 locks in $1B credit line, but faces 40% liquidity rules
1,551 $BTC (129,069,580 USD) transferred from unknown wallet to Coinbase...
Aztec relaunches privacy wallet on its Ethereum Layer 2
1,816 $BTC (151,093,512 USD) transferred from unknown wallet to Coinbase...
UPDATE: Coinbase has responded to Paul's allegations, saying it is "not hiding a series of hacks"
Tokenized Stocks Hit $3.6B as Avalanche and Solana Split the Market
250,000,000 $USDC (250,019,125 USD) minted at USDC Treasury...
Bitcoin Futures Notional Value Hits Two-Year Low
Kentucky Rep. James Comer is expanding his insider-trading-in-prediction-markets probe
873 $BTC (72,554,673 USD) transferred from unknown wallet to Coinbase Institutional...
Bitcoin bitcoin:native is testing a key long-term holder supply cluster around
BNB Chain Gains Nearly 1 Million Stablecoin Holders in a Week
2,057 $BTC (171,426,833 USD) transferred from unknown wallet to Coinbase...
Coinbase Faces $25M Loss Claim From Crypto Investor
Bitwise has launched Bitwise NEAR ETF
Bitcoin drops to $82,000 on US data, and inflation fear is blamed
749 $BTC (62,578,820 USD) transferred from unknown wallet to Coinbase Institutional...
Pakistan explores using landfill methane to generate energy as the...
Spark Finance Achieves 190% Loan Growth, Dominates DeFi Lending Market
NEW: Coinbase Ventures and CMCC Global closed a strategic funding round with trading firm Raven at a
Blockchain malware activity jumps 440% as AI lowers the barrier for North Korea and Iran-linked hackers
State-linked hackers are increasingly using public blockchains to keep malware connected to infrastructure that traditional takedowns cannot easily disable.
Groups tied to North Korea and Iran accounted for roughly two-thirds of newly observed blockchain-dead-drop activity each quarter by the second quarter of 2026, Chainalysis said. State-linked operators now represent about half of all activity the analytics firm tracks, up from a negligible share in early 2024.
The technique, known as a blockchain dead drop, stores malware instructions, command-and-control addresses or pointers inside transactions and smart contracts. Compromised devices can repeatedly query those public records for updated instructions, letting attackers change servers without reinfecting victims.
Chainalysis said malicious blockchain writes rose from 2.06 a day to 11.1 after the emergence of high-capacity open-weight Chinese artificial-intelligence models, a 440% increase in less than a year.
The firm said those models lowered the expertise required to build the infrastructure, though its measurement does not identify a single model or establish that AI alone caused the increase.
The shift adds another security challenge for crypto companies, developers and enterprises that increasingly rely on public chains for legitimate applications. Blocking access to an entire network would also disrupt wallets, decentralized-finance platforms and other services using the same infrastructure.
North Korea adds cross-chain redundancy
North Korean-linked operators are already showing how blockchain infrastructure can make a malware campaign more resilient after defenders identify its components.
Chainalysis connected the threat group UNC5342 to a previously unattributed setup that uses TRON and Aptos as redundant routes into BNB Smart Chain. Encoded pointers on the first two networks direct infected devices toward malware instructions stored on BSC. The malware queries TRON first and switches to Aptos if that route fails.
Attackers can rotate their off-chain infrastructure by posting another transaction, after which previously infected machines automatically retrieve the updated location. Chainalysis said disrupting the operation would require action across all three chains at the same time.
Google Threat Intelligence began tracking UNC5342 in February 2025, when it used blockchain-based malware delivery in fake-job campaigns aimed at cryptocurrency and technology developers. The group used smart contracts to help deliver credential-stealing malware targeting browser data, passwords, and crypto wallets.

The approach extends a tactic attackers adopted after conventional hosting providers began shutting down malicious infrastructure. EtherHiding campaigns appeared on EVM-compatible networks in 2023 after operators shifted code into smart contracts that could remain accessible even when websites or servers were removed.
Iran-linked operators have taken a different route. Chainalysis said suspected actors connected to Iran's Ministry of Intelligence have embedded command-and-control routing information inside Bitcoin transactions sent to a well-known address historically associated with Satoshi Nakamoto. The address itself has no connection to the attackers and functions as a permanent public reference point for infected machines.
AI lowers the barrier for smaller operators
The same techniques are spreading beyond state-backed groups as artificial-intelligence coding tools reduce the specialist knowledge once required to build blockchain-based command infrastructure.
Chainalysis said it now tracks blockchain-dead-drop activity across five major networks and more than a dozen named malware strains. Russian-language criminal groups have also deployed smart contracts on Polygon as command resolvers, with infrastructure marketed to other operators through a malware-as-a-service model.
That creates a path for attackers to rent blockchain-based infrastructure rather than design it themselves.
In one operation, Chainalysis identified a primary wallet controlling multiple resolver contracts, with individual contracts apparently serving separate customers or campaign variants. Related addresses were also linked to fraudulent tokens and clipboard-hijacking campaigns targeting crypto users.
The economics favor continued adoption. Posting small amounts of data on public chains can be inexpensive, while the underlying record remains globally available and hard to remove. Attackers can then keep most of the actual compromise off-chain, using the ledger primarily to tell infected machines where to connect next.
Defenders shift from takedowns to surveillance
The permanence that gives attackers resilience also leaves a record that cybersecurity teams can monitor.
Every transaction used to rotate infrastructure remains timestamped and publicly visible. Chainalysis said defenders can map operator wallets, resolver contracts, funding relationships, and update histories, potentially linking campaigns that would appear unrelated when viewed only through their domains or servers.
Organizations can also monitor outbound JSON-RPC requests, the calls software uses to query blockchain nodes, for signs that infected machines are contacting suspicious contracts or addresses. Centralized API providers and RPC gateways remain potential intervention points even when the underlying blockchain cannot be taken offline.
Protocol developers have limited options to remove the underlying capability without restricting legitimate blockchain use. Chainalysis said preventing arbitrary data from being written on-chain would require changes with consequences that could outweigh the security benefit.
That leaves exchanges, infrastructure providers and cybersecurity firms with a growing monitoring problem. As more malware treats public chains as persistent coordination layers, defenders will need to follow activity across wallets, contracts and multiple networks while preserving access for legitimate users.
The next pressure point is likely to fall on RPC and API providers sitting between infected devices and blockchains. Their ability to identify and block malicious queries without disrupting ordinary applications could determine how much of the attackers' new resilience survives once the technique becomes more widely tracked.
Source: CryptoSlate