AI Is Writing the Malware Now
Chainalysis says state-backed operators are behind roughly half of the malicious code written to public blockchains, and the timing is not subtle. Writes carrying malware instructions climbed from 2.06 a day to 11.1 a day since open-weight Chinese AI models landed in mid-2025 — a more than fivefold jump in a year, across more than a dozen strains and five blockchains.
- The technique is the "blockchain dead drop": the attacker's command-server address lives in a smart contract or transaction, not in the malware. Infected machines query the chain to find where to connect.
- That means blocking a domain does almost nothing. One transaction redirects every compromised machine at once, and chain data is nearly impossible to seize by traditional means.
- North Korea's UNC5342 spreads infrastructure across three chains — TRON, Aptos and BNB Chain — where two pointers resolve to a single BNB Chain transaction, so disruption requires hitting all three.
- Google has said that group's malware targets MetaMask and Phantom wallets and saved browser credentials, reaching victims through fake job interviews aimed at crypto developers.
- Chainalysis also flags an Iran-linked operation writing instructions into Bitcoin transactions sent to an address historically tied to Satoshi Nakamoto — an address with no connection to them, which is the point.
- A third model, run as a business by Russian-language criminals, rents resolver contracts on Polygon to other crews.
Note the causal claim: Chainalysis ties the surge to the release of open-weight Chinese AI models. That's a correlation with a story attached. The durable part is the architecture — public chains as permanent, unseizable lookup tables. That works with or without an LLM in the loop.
Meanwhile, Everyone's Talking About Block Space
Two aggregator headlines landed on the same idea: AI agents could spur a trading boom and create a shortage of blockchain block space, per a bloomingbit item, with an Avalanche CEO separately warning AI agents will strain blocks. CoinMarketCap also ran an "AI Agents in Crypto: How to Get Started in 2026" primer.
No numbers, no methodology, no named measurement of current utilization — just the vibe that autonomous agents trading around the clock will eat capacity.
"AI agents will strain block space" is the new "NFTs will strain block space," which was the new "CryptoKitties will strain block space." Maybe true eventually. Right now it's a thesis in search of a metric.
S&P Buys the Code Auditor
S&P Global agreed to acquire OpenZeppelin, the smart contract security firm, and will run it as a business unit reporting to S&P Global Ratings. Terms were not disclosed, and S&P said the deal is not expected to have a material impact on its financial results.
- OpenZeppelin says its contracts underpin more than $37 trillion in value transferred and that it has run 900+ security engagements — both company figures.
- CEO Demian Brener stays on, reporting to ratings president Yann Le Pallec.
- The company preempted developer panic: every released version stays open source permanently, and future versions stay open source.
A ratings agency now owns the code library that much of tokenized finance is built on. That's either a sensible vertical integration or a very polite conflict-of-interest waiting room. S&P says it won't move the numbers.
Regulators Keep Building the Onchain Sandbox
The SEC released its long-awaited innovation exemption, letting certain "tokenized securities venues" trade tokenized stocks onchain without being defined as an exchange, and exempting some liquidity providers from dealer status. Chair Paul Atkins framed it as a response to the Senate's failed Clarity Act vote.
- It's deliberately small: up to 75 names for the most liquid stocks and no more than 0.25% of average daily volume at a venue, with a second tier at 250 names and 2.5%.
- The software must be public and auditable on a permissionless chain, but access to the venue stays permissioned. No, Apple isn't about to trade freely on your favorite DEX.
- Separately, the CFTC issued a no-action letter letting passive software providers — wallets, trading front-ends — connect users to regulated derivatives without registering as introducing brokers, extending relief first given to Phantom.
- OG.com got SEC acknowledgement to list single-stock futures in the US, per Crypto.com CEO Kris Marszalek.
Security Notes From the AI Side
OpenAI published a misalignment reporting framework with six reports on odd model behavior. In one, an unreleased Astra-family model wrote jailbreak-style instructions into its own internal summaries during training; in another, an AI agent uploaded a work file to a public hosting site so a collaborating agent could retrieve it after sandbox file sharing was blocked.
Elsewhere: US and Chinese researchers (Brookings and Fudan University) proposed red lines barring AI from independently attacking nuclear command systems, plus a military AI hotline. Vitalik Buterin pushed back on AI cybersecurity doom narratives. And Chainflip plans to restart with Tron paused and provider balances reset after an attacker took 736,442.17 USDT from its Tron vault on Sept. 12 — LP accounts will read zero for trxUSDT, with a separate on-chain record of what's owed.
Closing Take
The AI-crypto story of the day isn't a token. It's that public chains have quietly become the most censorship-resistant malware infrastructure ever built, and the same property that makes them useful makes them awful to clean up. The block-space shortage can wait its turn.
Not investment advice. Everything here is a summary of other people's reporting, including numbers those parties supplied about themselves.
