
TRM Labs' AI-in-Crime Index hit 54/100, up 40% from 2024. Deepfake scam losses already exceed 2025 by 263%. Hackers and ransomware are next.
The use of artificial intelligence in cryptocurrency crime is climbing fast, according to blockchain intelligence firm TRM Labs. Its 2026 AI-in-Crime Adoption Index scores AI integration across crypto crime at 54 out of 100, placing it in the "emerging" category. That is up from roughly 28 in 2024, a rise of about 40 percent.
TRM Labs classifies AI adoption into four stages: horizon, emerging, mature, and dominant. Scammers have reached the mature stage, while hacking and ransomware operations remain in the emerging phase. Activities linked to narcotics and darknet markets are still at the earliest horizon stage.
"AI has not created entirely new forms of crime," Ari Redbord, TRM Labs' global head of policy and government affairs, said. "It has eliminated previous limitations." The barrier of required technical skill has dropped dramatically, he said, and the potential scale of operations has expanded. False identity creation has become industrialized. Tasks that once required a coordinated team can now often be handled by a single person with AI subscriptions.
The index is based on TRM Labs' analysis of blockchain data and threat intelligence. The firm said the 40 percent year-over-year increase reflects a broad acceleration across multiple crime categories.
Scammers account for most of the growth, TRM Labs said. The proportion of cryptocurrency scam reports involving AI elements such as deepfakes or automated chatbots has increased by as much as thirteen times since 2022. AI allows scammers to generate personalized content at scale, TRM Labs said, using deepfakes to impersonate trusted figures and chatbots to interact with victims. Losses attributed to deepfake-related scams in 2026 so far have already exceeded the entire 2025 total by 263 percent.
Hackers are incorporating AI more aggressively, TRM Labs said. North Korean-linked cyber actors are using deepfake-assisted social engineering to infiltrate organizations through fake IT worker profiles, and using AI to identify software vulnerabilities. AI helps automate reconnaissance and vulnerability scanning, TRM Labs said, making it easier for attackers to find entry points. Digital asset hacks hit a record 201 incidents in the first half of 2026, more than double the figure from the comparable period the year before, TRM Labs said. Roughly 61 percent of the associated losses, about $600 million, were tied to North Korea-linked activity, the firm said. A large share of total losses stemmed from a small minority of incidents that typically involved compromises of private keys or credentials rather than purely code-based exploits, TRM Labs said.
TRM Labs also said it identified a development it called JadePuffer, described as the first fully agentic ransomware attack. In that case, an AI system managed the entire process from reconnaissance and credential theft through lateral movement and encryption without continuous human direction. The firm said the JadePuffer case shows a shift toward fully autonomous ransomware attacks, where AI handles the entire lifecycle without human intervention. TRM Labs also said that ready-made, no-code ransomware packages are now available for relatively low prices, further lowering entry barriers.
Because a significant portion of illicit proceeds eventually moves across public blockchains, on-chain patterns serve as a useful indicator of broader trends in AI-enabled crime, the firm said.
Deepfake scam losses in 2026 have already exceeded the 2025 total by 263 percent, TRM Labs said.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.