How is Chinese state-affiliated hacking volume doubling through AI tools like DeepSeek?

Chinese state-linked hacking groups have doubled their attack frequency by integrating AI models like DeepSeek to automate repetitive cyber-offensive tasks. This surge, documented by threat intelligence firm TeamT5, marks a significant escalation in the efficiency of state-sponsored digital threats targeting global infrastructure.
How is Chinese state-affiliated hacking volume doubling through AI tools like DeepSeek?

Chinese state-affiliated hackers have significantly increased their operational output, doubling the volume of their attacks after integrating artificial intelligence into their daily workflows. According to a recent report by the Taiwanese threat intelligence firm TeamT5, these actors are utilizing AI models like DeepSeek and various open-source systems to automate mundane, repetitive tasks that previously required manual labor. This shift allows state-linked groups to scale their operations rapidly, maintaining a high volume of intrusions while focusing human expertise on more complex exploitation strategies.

The TeamT5 report highlights that while precise attribution for every individual intrusion remains difficult, the trend toward AI adoption among Chinese threat actors is undeniable. DeepSeek, a Chinese-developed high-performance AI, has emerged as a favored tool for these groups. By leveraging these models for tasks such as code generation, vulnerability research, and phishing content creation, hackers can launch more concurrent campaigns than ever before, overwhelming traditional defensive perimeters.

This development introduces a new layer of risk for the U.S. cryptocurrency and financial sectors. As state-sponsored actors become more efficient, the frequency of attempts to breach digital asset exchanges and decentralized protocols is expected to rise. U.S. agencies, including CISA and the FBI, have previously warned that geopolitical tensions often manifest in increased cyber activity targeting critical economic infrastructure, with the crypto industry being a prime target for both espionage and potential asset theft.

For investors and platform operators, this report signals a maturing threat landscape where defensive measures must also evolve through AI integration. The market may see increased volatility if high-profile breaches occur as a result of these automated campaigns. Moving forward, the industry should watch for updated cybersecurity mandates from U.S. regulators and a potential increase in AI-driven defensive spending by major crypto institutions to counter the rising tide of automated state-sponsored attacks.