EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

AI助黑客在区块链上隐藏恶意软件,攻击激增440%

2026-09-20 21:33:37
Bookmark

公共区块链上的恶意指令实例激增440%,日均达11起

据Chainalysis周四发布的一份报告显示,隐藏在公共区块链上的恶意指令实例在不到一年的时间内激增了440%,平均每天出现11起案例。而在2025年中期之前,这一数字的平均值仅为每天两起。

Chainalysis是全球最大的区块链分析公司之一,为全球政府、执法机构和金融机构提供调查工具。区块链是一种共享的数字账本,永久记录网络上发生的每一笔交易。这一特性使其在追踪资金流向方面极具价值,但正如报告所示,它同样被用于在众目睽睽之下隐藏恶意代码。

什么是“区块链死投”?

Chainalysis所描述的这种技术类似于一种数字化的“死投”(Dead Drop)机制。攻击者将恶意指令——例如指示受感染计算机发送窃取数据的命令——直接写入区块链交易或智能合约中。

由于区块链具有永久性和公开可访问性,这些指令无法像传统服务器那样被下架或屏蔽。任何知道如何查找的受感染设备都可以读取这些指令,而攻击者无需维护独立的命令与控制服务器。

该报告将使用币安智能链(Binance Smart Chain)的此类技术称为“EtherHiding”,尽管类似的方法已在多个网络中被观察到。

开源AI成为加速剂

Chainalysis将此次440%的激增直接归因于2025年中期发布的强大开源人工智能模型。这些模型在生成恶意代码方面没有任何限制。

这些工具降低了技术门槛,使经验较少的黑客也能构建基于区块链的恶意软件基础设施,而这种设施此前需要专业知识才能建立。报告指出,除了受经济利益驱动的网络安全罪犯外,与朝鲜和伊朗国家相关的组织也是该技术的使用者。

特性转变为漏洞

正是使区块链具有价值的同一属性——不可篡改性(即数据一旦记录便无法更改或删除),也使其对攻击者充满吸引力。

传统的网络安全防御措施侧重于关闭恶意服务器或阻止已知的IP地址。然而,当指令存储在区块链上时,这些防御措施便不再适用。这些数据是永久的、公开可读的,并托管在全球数千个节点上。

Chainalysis表示,这一趋势代表了区块链相关网络犯罪的新前沿,需要超越传统下架方法的新型检测手段。

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP