
TRM Labs reports 13-fold rise in AI-powered scam reports since 2022. Chainalysis finds impersonation scams up 1,400%. The security gap now lies in identity verification, not smart contracts.
Reported losses from deepfake scams in 2026 have already exceeded last year's total by 263%, according to TRM Labs. The blockchain intelligence firm's new AI-in-Crime Adoption Index classifies scams as the only crypto-crime category where artificial intelligence has reached a "Mature" level of adoption. The trend is reshaping security priorities across the crypto market.
TRM said reports involving scammer-side use of AI, including deepfakes and AI-powered lures, have risen roughly 13-fold since 2022. The shift puts more of the security burden on the moment before authorization, when an exchange decides whether an account-recovery request is genuine or a treasury signer approves a transfer.
TRM's data shows that traditional smart-contract security does not address this weakness. An exchange account can be properly authenticated and a hardware wallet can sign correctly, yet funds can still reach an attacker if a deepfake convinces the person controlling those systems to approve the transaction.
Chainalysis said inflows to impersonation scams rose more than 1,400% year over year. It found that scam operations with visible on-chain links to AI service providers generated 4.5 times more revenue on average than those without such links. The company cautions that those figures are based on addresses it has identified and can change as attribution improves.
The FBI's 2025 Internet Crime Report recorded 22,364 complaints carrying an AI-related descriptor and $893.35 million in associated reported losses. Separately, complaints involving cryptocurrency descriptors totaled $11.37 billion in losses.
These datasets show why AI is increasingly useful to scammers. It can make impersonation cheaper and more convincing. A single attacker can maintain conversations with victims in multiple languages. Synthetic video can strengthen a false identity during remote verification. Voice cloning can imitate an executive or family member. AI-generated documents, profiles and communications can make a fraudulent request appear consistent across several channels.
The problem becomes more consequential in crypto because transactions are difficult to reverse once authorized. TRM's separate review of first-half crypto hacks showed that smart-contract vulnerabilities remained common. The largest losses were concentrated in infrastructure and operational compromises.
Deepfakes extend that problem by helping attackers obtain cooperation rather than merely stealing access, TRM's data shows. At an exchange, an attacker could impersonate a customer during account recovery and change authentication factors. Each subsequent step may appear valid because the attacker has already compromised the identity decision that controls access.
That makes post-onboarding identity checks increasingly important. FinCEN has warned financial institutions to watch for mismatched identity information, suspicious device or location changes, third-party webcam tools, resistance to multifactor authentication, and rapid transactions following account changes. A recovery-factor change followed by a new device and immediate transfer can require stronger verification before assets leave the platform.
Corporate treasuries face a similar risk. A synthetic voice or video of an executive can pressure an employee to approve a transfer or add a new payment address. Hardware wallets can confirm that the correct private key signed the transaction. They cannot determine whether the human controlling that key was deceived.
Multiperson approval and delays before newly added withdrawal addresses become active can move the critical decision outside the communication channel controlled by the attacker.
On-chain tools remain useful for detecting suspicious flows and tracing stolen assets. They are less effective at stopping a transaction that appears legitimate because the victim or authorized signer willingly approved it.
The FBI has warned that North Korean IT workers have used false identities, manipulated video, AI tools and remote-access infrastructure to gain positions that can provide privileged access to corporate systems and cryptocurrency.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.