Deepfake-related losses reported so far in 2026 have already overshot the full-year 2025 total by 263%. The figure comes from TRM Labs, and it hints at an awkward shift in crypto crime: criminals have largely stopped attacking the software. They go after whoever is holding the keys.
In the blockchain intelligence firm’s newly published AI-in-Crime Adoption Index, scams sit alone at the top. Of every crypto-crime category TRM assessed, it is the only one where the firm grades artificial intelligence adoption as “Mature.”
The 13-fold number matters more than the 25-fold one
According to TRM, reports that involve scammers themselves deploying AI — deepfakes, chatbots, AI-powered lures — are up roughly 13-fold since 2022. Circulating alongside it in the same research is a flashier statistic: a 25-fold jump in all scam reports that mention AI since 2022.
Set that one aside. It sweeps in incidents where the victims were the ones using consumer AI tools to look into suspected fraud, which reveals nothing about what attackers can actually do. The tighter 13-fold series filters for reports where the scammer used AI. That is the number to follow.
The index scores how common AI is inside each crime type, how widely it shows up across stages like targeting and deception, and how advanced the tooling has become. That 263% deepfake loss number covers 2026 up to the window captured in TRM’s Aug. 17 report, benchmarked against the reported total for all of 2025.
Your hardware wallet did its job. You didn’t.
This is where the mental model most of the industry has leaned on for a decade falls apart. An exchange login can be authenticated properly. A hardware wallet can produce a valid signature. A smart contract can run precisely as written. And the funds still arrive in an attacker’s address — because a deepfake talked the person operating all three into approving the transfer.
No component of the stack malfunctioned. That is precisely the issue.
Responsibility shifts to the instant before authorization: the moment an exchange judges whether an account-recovery request is real, the moment a treasury signer green-lights a transfer, the moment you act on payment instructions from a face or voice you are certain you know.
Other datasets say the same thing
Chainalysis reported that funds flowing into impersonation scams climbed by more than 1,400% year over year. The firm also determined that scam operations showing on-chain connections to AI service providers pulled in 4.5 times more revenue on average than those without such links.
Treat that second data point with care. Chainalysis notes the totals rest on the addresses it has managed to identify and may shift as attribution gets sharper. Multiples that hinge on attribution tend to move around.
Meanwhile, the FBI’s 2025 Internet Crime Report recorded 22,364 complaints tagged with an AI-related descriptor, tied to $893.35 million in reported losses. Complaints flagged with cryptocurrency descriptors, tallied on their own, accounted for $11.37 billion in losses.

Why AI is so good at this specific crime
Impersonation always carried a minimum price. It required a human on the call, fluent in the right language, armed with a believable narrative, for however long the con demanded. AI has knocked that floor out entirely.
One operator can now run parallel conversations with victims across several languages. Synthetic video can sustain a fabricated identity through remote verification checks. Cloned audio can mimic a company executive or a relative. Documents, profiles and messages generated by AI can keep a bogus request looking coherent across multiple channels simultaneously — the very consistency a cautious person looks for.
Crypto compounds the damage, since transactions are difficult to unwind after they are authorized.
The exchange account-recovery path
A separate TRM analysis of first-half crypto hacks found that smart-contract flaws are still widespread, though the heaviest losses concentrated in infrastructure and operational breaches — stolen credentials, private keys and other access that lets an intruder submit instructions the blockchain treats as valid.
Deepfakes push that further, letting attackers obtain cooperation rather than merely seizing access.
Picture the sequence at an exchange. The attacker poses as a customer during account recovery, swaps out the authentication factors and registers a fresh withdrawal destination. Everything that follows the opening move appears legitimate, because the identity check that governs the rest of the chain had already been subverted.
FinCEN has spelled out the post-onboarding warning signs for financial institutions: identity details that don’t line up, unusual device or location shifts, third-party webcam software, pushback against multifactor authentication, and transactions executed quickly after account changes. A recovery-factor change, followed by a new device, then a new withdrawal address, then an immediate transfer, is a pattern that ought to force tougher verification before any funds leave the platform.
What a hardware wallet can’t tell you
Corporate treasuries face the identical risk from a different angle. A cloned voice or a synthetic video of a senior executive leans on staff to sign off on a transfer, replace a signer or register a payment address.
A hardware wallet will verify that the right private key signed the transaction. It cannot detect whether the person wielding that key was deceived.
The remedies here are procedural rather than cryptographic: approvals requiring multiple people, confirmation channels settled on ahead of time, cooling-off periods before freshly added withdrawal addresses become active. Each achieves the same end — relocating the decisive moment away from the channel the attacker is running.
The FBI has separately cautioned that North Korean IT workers have relied on fake identities, doctored video, AI tools and remote-access infrastructure to secure jobs granting them privileged entry to corporate systems and cryptocurrency.

For individuals, it’s simpler and worse
There is no takeover to execute. A persuasive video call, voice note or profile convinces you to make the payment with your own hands. On-chain monitoring only kicks in once the security failure that actually counted is behind you.
Blockchain tooling still pays for itself. It flags suspicious movement, follows stolen funds and enables freezes wherever a centralized intermediary can intervene. What it struggles with is a transfer that looks entirely above board because the authorized signer chose to approve it.
What TRM’s figures expose is a gap that lives well outside the smart contract.
Hold on to the contract audits, the private-key hygiene, the wallet simulation and the transaction monitoring — none of those are negotiable. But if you are weighing where the next security dollar should go, spend it on the control that interrogates who is issuing the instruction, before someone signs something that cannot be reversed.



















STAY ALWAYS UP TO DATE