Chinese State Hackers Doubled Their Attack Volume. Blame AI.
A new TeamT5 report says Chinese state-affiliated hackers now run twice as many attacks after handing routine work to DeepSeek and open-source AI. The real story isn't the tool, it's what happens when the time constraint on state hacking disappears.
What happens when state-backed hackers hand their dullest work to an AI? Apparently, they double their attack volume. That's the takeaway from a new report by TeamT5, a Taiwanese threat intelligence firm that's been tracking Chinese state-affiliated hackers for years.
The raw numbers
TeamT5 says Chinese state hackers are now running twice as many attacks as before they started using DeepSeek and open-source AI systems to handle routine tasks. Not every intrusion can be tied to a specific system, and the report admits attribution is imprecise. But DeepSeek, the report notes, has become a popular choice among the operators they monitor.
Doubling volume matters. Think about what it changes operationally. Instead of a human analyst spending hours scanning for vulnerabilities, mapping internal networks, or drafting convincing phishing lures, an AI model does the first pass in minutes. The hacker only steps in at the end, when a target is already compromised.
That's a fundamental shift in how state cyber operations scale.
Why this matters
Here's the thing: the constraint on state hacking was never raw talent. It was time. Chinese intelligence agencies have plenty of skilled operators. What they didn't have was enough hours in the day to run operations at scale. AI removes that bottleneck, and it doesn't take an expensive proprietary system to do it.
DeepSeek is open-source. So are a dozen other capable models. Anyone with a decent GPU and some technical skill can fine-tune one for malicious tasks, and the same forums where these hackers trade tools now include threads about prompt engineering and dataset preparation.
Granted, I'm not entirely convinced that double the attacks means double the successful breaches. Volume is one thing. Getting through a well-patched network is another. But it means defenders face twice as many probes, twice as much phishing, twice as much noise to sort through. That's a real cost, even if the success rate stays flat.
For crypto specifically, this isn't abstract. Exchange hot wallets, bridge contracts, governance protocols, all of these have been targeted by state-linked groups before. The attackers are now faster and cheaper to scale, and the infrastructure holding user funds just became a bigger target.
What the researchers are saying
TeamT5 is careful with its language. It can't tie every attack to a specific AI system, and it doesn't pretend otherwise. But the pattern matches what other threat intelligence firms have reported over the past year. State actors, not just Chinese ones, are adopting AI for the mundane parts of their work. Reconnaissance, payload generation, credential stuffing. The stuff that used to burn analyst hours.
The question worth asking: if this is the effect from commodity AI tools, what happens when these groups build custom models trained on their own intrusion data? We're already seeing hints of it. Fine-tuned models that write phishing emails with near-perfect grammar, or generate malware variants faster than defenders can patch the originals.
What to watch next
Three things are worth tracking. First, how quickly Western intelligence and defensive security firms roll out their own AI-driven countermeasures. Second, whether the doubled attack volume starts appearing in publicly disclosed breach data over the next two or three quarters. Third, whether model providers start building serious abuse controls, or keep shipping open weights with no guardrails.
Time will tell, though. History suggests the defense side usually catches up, but it takes a while, and the gap is where the damage happens.
Related Articles
Explore More
Key Terms Explained
A protocol that lets you move tokens between different blockchains.
Permanently removing tokens from circulation by sending them to an unusable wallet address.
A basic good used in commerce that's interchangeable with other goods of the same type.
A marketplace where cryptocurrencies are bought and sold.