North Korea is turning blockchains into malware infrastructure, and regulators are scrambling to catch up

A 420% spike in onchain malware is not a glitch in the data. It’s a strategy. According to a new Chainalysis report covered by Cointelegraph, state-linked hackers, primarily from North Korea and Iran, account for roughly two-thirds of new activity where attackers embed malware instructions or infrastructure details directly onto public blockchains. The method is deliberate. Unlike traditional servers or domains, blockchain entries cannot be taken down. The malware lives on, permanently accessible, even after every other piece of infrastructure has been seized or shut.

Chainalysis linked one North Korean group, UNC5342, to previously unattributed activity across Tron, Aptos, and BNB Smart Chain. North Korean hackers used a similar trick in 2025, a technique called EtherHiding, to plant crypto-stealing code inside smart contracts. This year’s surge suggests the tactic has matured and spread. For users, the implication is uncomfortable: the same public infrastructure that makes blockchains transparent also makes them a durable hosting service for hostile code.

The threat is not limited to malware on-chain. NBC has reported that North Korea is now recruiting remote workers from Iran and Lebanon to pass job interviews at US tech companies. Once hired, North Korean operatives take over the roles. The goal is to infiltrate US firms, extract money, and funnel it back to weapons programs. This is state espionage dressed in a Slack avatar, and the crypto industry is a known target.

Meanwhile, South Korean police referred 18 Polymarket users to prosecutors over illegal gambling charges, after identifying 26 participants by analyzing publicly available blockchain data. The users had collectively wagered around $12.7 million. Polymarket does not collect real names or verify identities, which is precisely what attracted users and precisely what made investigators’ jobs harder. South Korean law treats staking assets on uncertain outcomes as illegal gambling, full stop. That’s a legal interpretation that could have wide consequences for prediction markets operating without geo-blocking.

In Hong Kong, the fallout from Metaplanet’s controversial executive compensation plan continues. After proposing to hand up to 20% of fully diluted shares to executives, the company has now cut its Series 10 stock pool by 41%, reducing potential shares from 319 million to 188 million. The move wipes out more than $220 million in warrant value but reportedly increases Bitcoin per fully diluted share by about 8.8%. Shareholders and critics who pushed back on the original plan will see this as a partial win.

Also in Hong Kong, the failure of the US CLARITY Act vote is being framed locally as an opening. Industry insiders are urging policymakers to build cross-border infrastructure rather than wait for Washington to define the global market. Whether Hong Kong can credibly fill that gap remains to be seen, but the political appetite appears real. Adding to that story, CoinEx, the Hong Kong-founded exchange, announced it is shutting down after nine years, blaming falling volumes, a prolonged bear market, and rising compliance costs. Withdrawals stay open until December 22.

India is moving in a different direction, toward structure. The country’s securities regulator and central bank launched a tokenized corporate bond pilot, with three firms issuing a combined $107 million through a system that connects to the Reserve Bank of India’s wholesale CBDC. The Parliamentary Standing Committee on Finance also wrapped a year-long crypto policy review, with a government response expected next week. India’s Enforcement Directorate is separately building out its crypto crime tracking capabilities, aiming to close economic crime investigations within 18 months.

Across Southeast Asia, Vietnam is developing crypto monitoring mechanisms based on FATF recommendations, and Binance signed an agreement to help develop the Vietnam International Finance Center in Ho Chi Minh City. Singapore Exchange became the first major Asian traditional finance exchange to receive CFTC approval for Bitcoin and Ethereum perpetual futures for US institutions. Thailand’s SEC proposed a daily stablecoin transfer cap of around $151,000 per user. And in Malaysia, Fitch Ratings noted the country is among the more crypto-open Muslim-majority nations, with its Securities Commission declaring Bitcoin, Ethereum, Ripple, and Stellar sharia-compliant.

The through-line across all of this is that Asia is not one story. It’s a dozen regulatory experiments running in parallel, with state-level threat actors watching every gap.