Losses from AI-driven deepfake scams have surged 263% in 2026, as attackers increasingly target users directly instead of exploiting blockchain code, exposing new vulnerabilities for exchanges, wallets, and individual crypto holders
Losses from deepfake scams in the cryptocurrency sector have soared in 2026, with reported incidents already up 263% over last year, according to TRM Labs. This sharp increase highlights a shift in crypto security threats: attackers are now focusing on manipulating authorized users through artificial intelligence rather than exploiting flaws in blockchain code or smart contracts.
AI Adoption in Crypto Scams
TRM Labs' new AI-in-Crime Adoption Index classifies scams as the only crypto-crime category where artificial intelligence has reached a "Mature" level of use. The firm reports that scammer-side deployment of AI-including deepfakes, chatbots, and AI-powered lures-has grown roughly 13 times since 2022. Broader scam reports mentioning AI have increased about 25-fold in the same period. These trends reveal a security gap: even when exchange accounts are properly authenticated and hardware wallets sign transactions correctly, funds can still be lost if a deepfake convinces the user to approve a fraudulent transfer.
Impersonation at Scale
Other data providers confirm the trend. Chainalysis found that inflows to impersonation scams rose more than 1,400% year over year, and scam operations with visible on-chain links to AI service providers generated 4.5 times more revenue on average than those without such links. The FBI's 2025 Internet Crime Report recorded 22,364 complaints with an AI-related descriptor, totaling $893.35 million in reported losses. Complaints involving cryptocurrency descriptors reached $11.37 billion in losses. AI tools make impersonation cheaper, more convincing, and easier to scale-enabling attackers to maintain conversations in multiple languages, generate synthetic video for remote verification, and clone voices to imitate executives or family members.
Security Risks Beyond Code
Unlike traditional hacks that exploit code vulnerabilities, deepfake scams target the human element. Once a user is deceived into authorizing a transaction, blockchain monitoring tools can only detect suspicious flows after the fact. At exchanges, attackers may use deepfakes to impersonate customers during account recovery, change authentication factors, and add new withdrawal destinations. This places greater importance on post-onboarding identity checks and monitoring for suspicious activity, such as mismatched identity information or rapid transactions following account changes. Corporate treasuries face similar risks, as synthetic voices or videos can pressure employees to approve transfers or alter payment addresses. Hardware wallets can confirm the correct private key signed a transaction, but cannot determine if the human controller was manipulated.
Operational and Infrastructure Weaknesses
TRM Labs' review of first-half 2026 crypto hacks shows that while smart-contract vulnerabilities remain common, the largest losses are now concentrated in infrastructure and operational compromises. These attacks often involve stolen credentials or private keys, but deepfakes extend the threat by enabling attackers to obtain cooperation from authorized users. The FBI has also warned that North Korean IT workers have used false identities, manipulated video, and AI tools to gain privileged access to corporate systems and cryptocurrency. For individual holders, a convincing video call or voice message can be enough to persuade a victim to send funds directly, bypassing technical safeguards.
In a related development, Ethereum researchers are working to address critical cryptographic proof gaps in zkEVM security, aiming to close vulnerabilities that could affect scaling and user protection. For more on these efforts, see EgonCoin's coverage of Ethereum's push to close the zkEVM security gap by December 2026.
According to TRM Labs, the number of scam reports involving AI tools has increased about 13-fold since 2022, while broader scam reports mentioning AI have risen 25-fold. Chainalysis data shows that impersonation scams with on-chain links to AI service providers generated 4.5 times more revenue than those without such links. The FBI's 2025 Internet Crime Report documented $893.35 million in AI-related losses and $11.37 billion in cryptocurrency-related losses, underscoring the scale of the threat.
As AI-powered scams become more sophisticated, the burden of crypto security is shifting from code-level protections to verifying the legitimacy of user actions before transactions are authorized. This evolution challenges exchanges, wallet providers, and individual users to strengthen identity verification, monitor for behavioral anomalies, and implement controls that can detect and prevent social engineering attacks before funds are irreversibly transferred.
Deepfake scams illustrate a fundamental limitation of blockchain security: while cryptographic protocols can ensure that only authorized keys sign transactions, they cannot guarantee that the person behind the key is acting with full awareness and intent. As attackers increasingly use AI to manipulate users, the most critical security decisions may occur before a transaction is ever signed. This dynamic places new pressure on exchanges, custodians, and users to adopt layered defenses that address both technical and human vulnerabilities in the crypto ecosystem.