Deepfake scams trick users into approving crypto transfers
TRM Labs reports 2026 deepfake crypto losses up 263% year over year as attackers use AI voice, video and chatbots to impersonate authorized users and prompt transfers.
TRM Labs reports that reported losses from deepfake crypto scams in 2026 have already exceeded the total for all of 2025 by 263%. The blockchain intelligence firm’s latest AI-in-Crime Adoption Index classifies scams as the only crypto-crime category where AI use has reached a “Mature” level.
TRM says reports of scammer-side use of AI — including deepfake video, voice cloning, chatbots and automated lures — have risen roughly 13-fold since 2022. The broader set of scam reports that mention AI has increased about 25-fold over the same period, a figure that also includes victims using consumer AI tools while investigating fraud.
The firm notes that these attacks shift the point of failure from code and keys to the moment before a transaction is authorized. An exchange account can be authenticated correctly, a hardware wallet can sign with the correct private key, and a smart contract can execute as written, yet funds may still be sent if a person controlling those systems is deceived into approving the transfer. TRM’s data for the first half of 2026 shows the largest losses came from infrastructure and operational compromises that rely on stolen credentials or human cooperation rather than exploitable smart-contract code.
Other datasets cited by analysts show similar trends. Chainalysis reports inflows to impersonation scams rose more than 1,400% year over year and that scam operations with visible on-chain links to AI service providers generated about 4.5 times more revenue on average than those without such links. The FBI’s 2025 Internet Crime Report recorded 22,364 complaints carrying an AI-related descriptor with $893.35 million in reported losses; complaints listing cryptocurrency descriptors totaled $11.37 billion in losses that year.
Attackers use synthetic video to strengthen false identities during remote verification, voice cloning to imitate executives or relatives, and multilingual chatbots to manage simultaneous conversations. AI-generated documents, profiles and cross-channel messages can make fraudulent requests look consistent and authoritative across platforms.
Regulatory guidance addresses specific warning signs for financial firms and crypto platforms during account recovery and treasury operations. The Treasury’s FinCEN has advised monitoring for mismatched identity information, unusual device or location changes, use of third-party webcam tools, resistance to multi-factor authentication, and very rapid transactions following account-recovery or authentication changes. A sequence such as a recovery-factor change, a new device, a new withdrawal address and an immediate transfer should trigger stronger verification before assets leave a platform.
For corporate treasuries and custodians, measures noted in industry guidance include requiring multiperson approval for large transfers, using pre-established confirmation channels outside the requestor’s communication channel, and imposing delays before newly added withdrawal addresses become active. For individuals, platforms can reduce risk by enforcing stronger identity checks and offering user education about impersonation tactics.
TRM’s findings underline a security gap that is not resolved by smart-contract audits or private-key protections alone. On-chain analytics remain useful for tracing stolen funds and supporting freezes when intermediaries can act, but they typically operate after a fraudulent transfer has been approved.








