Quick Take
- TRM Labs says reported deepfake-scam losses in 2026 have already exceeded 2025’s total by 263%.
- AI-driven impersonation targets recovery, signing, and payment decisions, bypassing protections that secure accounts, keys, and smart contracts.
- The remaining challenge is verifying human intent before authorized transfers become irreversible, especially after identity or withdrawal details change.
Reported losses from deepfake scams in 2026 have already exceeded last year's total by 263%, according to TRM Labs, highlighting a growing crypto security problem in which attackers increasingly manipulate authorized users rather than break blockchain code.
The blockchain intelligence firm’s new AI-in-Crime Adoption Index classifies scams as the only crypto-crime category where artificial intelligence has reached a “Mature” level of adoption.
TRM said reports involving scammer-side use of AI, including deepfakes, chatbots and AI-powered lures, have risen roughly 13-fold since 2022.
The shift exposes a weakness that traditional smart-contract security does not address. An exchange account can be properly authenticated, a hardware wallet can sign correctly, and a smart contract can execute exactly as programmed, yet funds can still reach an attacker if a deepfake convinces the person controlling those systems to approve the transaction.
That puts more of the security burden on the moment before authorization, when an exchange decides whether an account-recovery request is genuine, a treasury signer approves a transfer, or an individual accepts payment instructions from someone they believe they know.
AI scams reach maturity as impersonation scales
TRM’s index measures the prevalence of AI within different crime types, how broadly it is used across stages such as targeting and deception, and the sophistication of the tools involved.
The firm said its broader series covering all scam reports that mention AI has increased about 25-fold since 2022. That figure also includes cases where victims used consumer AI tools while investigating suspected fraud. The narrower 13-fold increase isolates reports where scammers themselves used AI.
TRM separately said reported losses tied to deepfake scams in 2026 through the period covered by its Aug. 17 report were 263% higher than the reported total for all of 2025.

Notably, other datasets nevertheless point in the same direction.
Chainalysis said inflows to impersonation scams rose more than 1,400% year over year and found that scam operations with visible on-chain links to AI service providers generated 4.5 times more revenue on average than those without such links.
The company cautions that those figures are based on addresses it has identified and can change as attribution improves.
The FBI’s 2025 Internet Crime Report recorded 22,364 complaints carrying an AI-related descriptor and $893.35 million in associated reported losses. Separately, complaints involving cryptocurrency descriptors totaled $11.37 billion in losses.
| Source | View of the problem | 2025 signal |
|---|---|---|
| TRM Labs | AI adoption across crime stages and report-based observations | Scams are the only Mature AI-adoption category; scammer-side AI report share is roughly 13 times its 2022 level |
| FBI IC3 | U.S. complaints and adjusted reported losses | 181,565 cryptocurrency-descriptor complaints carried $11.37 billion in losses; 22,364 AI-related-descriptor complaints carried $893.35 million |
| Chainalysis | Global flows attributed to identified on-chain scam addresses | At least $14 billion reached identified addresses, with a projection above $17 billion as attribution expanded |
Taken together, these datasets show why AI is increasingly useful to scammers: it can make impersonation cheaper, more convincing, and easier to operate at scale.
A single attacker can maintain conversations with victims in multiple languages. Synthetic video can strengthen a false identity during remote verification. Voice cloning can imitate an executive or family member. AI-generated documents, profiles and communications can make a fraudulent request appear consistent across several channels.
The breach increasingly happens before the signature
The problem becomes more consequential in crypto because transactions are difficult to reverse once authorized.
TRM’s separate review of first-half crypto hacks showed that smart-contract vulnerabilities remained common, but the largest losses were concentrated in infrastructure and operational compromises.
Such attacks can involve stolen credentials, private keys, or other forms of access that allow an attacker to issue instructions the underlying blockchain accepts as legitimate.
Deepfakes extend that problem by helping attackers obtain cooperation rather than merely stealing access.
At an exchange, an attacker could impersonate a customer during account recovery, change authentication factors, and add a new withdrawal destination. Each subsequent step may appear valid because the attacker has already compromised the identity decision that controls access.
That makes post-onboarding identity checks increasingly important. FinCEN has warned financial institutions to watch for mismatched identity information, suspicious device or location changes, third-party webcam tools, resistance to multifactor authentication, and rapid transactions following account changes.
A recovery-factor change followed by a new device, new withdrawal address, and immediate transfer can therefore require stronger verification before assets leave the platform.
Corporate treasuries also face a similar risk.
A synthetic voice or video of an executive can pressure an employee to approve a transfer, alter a signer or add a new payment address. Hardware wallets can confirm that the correct private key signed the transaction, but they cannot determine whether the human controlling that key was deceived.
Multiperson approval, pre-established confirmation channels and delays before newly added withdrawal addresses become active can move the critical decision outside the communication channel controlled by the attacker.
The FBI has also warned that North Korean IT workers have used false identities, manipulated video, AI tools and remote-access infrastructure to gain positions that can provide privileged access to corporate systems and cryptocurrency.
For individual holders, the attack can be even simpler. A convincing video call, voice message, or profile can persuade the victim to make the payment personally. In that case, blockchain monitoring begins only after the decisive security failure has occurred.
On-chain tools remain useful for detecting suspicious flows, tracing stolen assets, and supporting freezes where centralized intermediaries can intervene. However, they are less effective at stopping a transaction that appears legitimate because the victim or authorized signer willingly approved it.
TRM’s data therefore points to a security gap that sits outside the smart contract itself.
Crypto companies still need contract audits, private-key protection, wallet simulation, and transaction monitoring. But as AI makes impersonation more effective, the more consequential control may increasingly be the one that challenges who is giving the instruction before an irreversible transaction is signed.


