Artificial intelligence is rapidly reshaping crypto-related crime, with the use of AI across illicit activities now scored at 54 out of 100 on TRM Labs’ 2026 AI-in-Crime Adoption Index. That places overall adoption in the “emerging” category, up from roughly 28 in 2024 and reflecting about a 40 percent increase over the past year. Scams are the only crime category where AI integration has reached a “mature” stage, while hacking, ransomware, narcotics and darknet activity remain in earlier phases.
Ari Redbord, Global Head of Policy and Government Affairs at TRM Labs, said AI has not created entirely new forms of crime but has eliminated previous limitations: technical barriers have dropped, the scale of operations has expanded, and false identities can now be industrialized. Tasks that once required a coordinated team can often be handled by a single individual using widely available AI subscriptions.
The fraud data is especially stark. The proportion of crypto scam reports involving scammer-side AI elements such as deepfakes, chatbots or AI-powered lures has risen roughly 13-fold since 2022. Reported losses tied to deepfake scams in 2026 have already exceeded the entire 2025 total by 263 percent. Chainalysis separately found that inflows to impersonation scams rose more than 1,400 percent year over year, while scam operations with visible on-chain links to AI service providers generated 4.5 times more revenue on average than those without such links. The FBI’s 2025 Internet Crime Report recorded 22,364 complaints carrying an AI-related descriptor and $893.35 million in associated losses.
Hacking is also becoming more AI-intensive. North Korean-linked actors used deepfake techniques to infiltrate organizations through fake IT worker profiles and AI-supported social engineering. Digital asset hacks hit a record 201 incidents in the first half of 2026, more than double the comparable period a year earlier, with about 61 percent of associated losses—around $600 million—tied to North Korea-linked activity. TRM Labs also highlighted JadePuffer, described as the first fully agentic ransomware attack, in which an AI system managed reconnaissance, credential theft, lateral movement and encryption without continuous human direction.
The shift exposes a security gap outside smart contracts: an exchange account can be properly authenticated and a hardware wallet can sign correctly, yet funds can still reach an attacker if a deepfake convinces the human controlling those systems to approve a transaction. FinCEN has warned financial institutions to watch for mismatched identity information, suspicious device or location changes, resistance to multifactor authentication, and rapid transactions after account changes. As AI makes impersonation cheaper and more convincing, the decisive security control increasingly becomes the moment before an irreversible transaction is signed.