Crypto

AI-Enabled Scams Are Closing In On Crypto Hacks As A Security Threat


Impersonation and AI-driven scams are emerging as one of crypto’s biggest security threats, according to Chainalysis data, which puts on-chain inflows to crypto scams at a minimum of $14 billion in 2025. Not all of that is AI. Rime Salmi, founder and CEO of Fractl, told us in an interview, “There are a lot of people who are posing as investors and they’re absolutely not. They’re looking for investments or grifting actually.” Salmi said the technology itself blurs the line: “AI is a big buzzword, but we don’t know where the human fits in that anymore. Are we okay with one person company or are we still funding solid big teams?”

The Economics of AI-Enabled Fraud

Salmi said AI has stopped being a separate category at all: “It’s part of everything. So it’s not a thing on its own anymore.” Chainalysis put scams with on-chain links to AI vendors at $3.2 million per operation on average, against $719,000 for scams without them, a correlation it does not present as cause. She said the one defense that still holds is data nobody can copy: “If a startup has solid proprietary data, that’s something that would be very difficult to vibe code them out of because it would just take years to get really high quality in depth data.”

In that subset Chainalysis identifies deepfakes, face-swapping software and large language models used to build fake identities at scale. Erika Maslauskaite, CEO and co-founder of AlongID, told us in an interview, “With AI currently, you can fake everything. You can literally fake everything.” She put the problem as “how do we verify what is true and authentic and what is not.”

Hacks Are Changing Too

AI-enabled scams do not make conventional hacks obsolete. An attacker does not need to break a smart contract if they can compromise the person authorized to use it.

“Code is no longer necessarily the weakest link in Web3. As smart contract security improves, attackers are shifting their attention to the people, credentials and governance systems surrounding protocols,” said Binance Chief Security Officer Jimmy Su. “We saw this firsthand when Binance Security helped prevent a $1.2 million governance attack on BrainTrust. Protecting a protocol today means securing not just its code, but also who can control it, how that control is exercised, and the infrastructure and people behind it.”

In April 2026 alone, access-control failures accounted for roughly two-thirds of the $621 million lost to DeFi exploits, according to Binance Research. Nitya Subramanian, founder and CEO of Para, said on the On The Margin podcast, “Wallets are ultimately the authorization and control flow layer of anything that’s happening on chain. Every chain, every DeFi primitive, every action that you can take on chain needs to go through a wallet. And I feel like people still don’t fully get that.”

The Attribution Problem

Blockchain transparency remains one of crypto’s strongest forensic advantages, but attribution needs context outside the transaction. Dmitry Machikhin, founder and CEO of BitOK, told us in an interview that mixing remains a gap: “Even Chainalysis has no, like, 100% solution for the mixing.” He said seizure notices do not always translate into action: “There was a case where the Israel government seized some wallets in their official documents. So that means that those wallets should be literally blocked by any exchanges, by any entities dealing with crypto. But this didn’t happen.”

Machikhin was blunt about the limits: “We are not catching anybody. We are just showing … the path of money.” He put illicit volume at “less than 0.1% of all transactions,” then said the percentage understates it: “even 0.1% is huge. And it’s growing with the market.” He said crypto still dominates one channel: “Terrorism financing, I think fiat helps to finance such forbidden organizations much, much more efficiently. But crypto is still the number one priority way of transferring money in darknet.”

Law enforcement recovered more than 61,000 bitcoin in the United Kingdom in 2025 and secured a $15 billion forfeiture linked to the Prince Group, according to Chainalysis’ 2026 report.

The Next Target May Not Be the Human

Varun Kabra, chief growth officer at Concordium, said on the On The Margin podcast, “The next step, which is already starting, is that the AI agents start transacting on your behalf. So they pay for things, they sign up for services, they probably handle your financial transactions now.”

The gap, he said, sits on the receiving end: “the counterparty on the other side, the airline in this case, or the ticketing platform, whatever it is, they have no way to verify whether a real accountable human is behind the transaction. And that could open a door to fraud, bots acting as humans, agents operating with no accountability.”

Kabra put agent traffic “six to twelve months away” from overtaking human transactions, and called “human to agent accountability … the biggest problem I think the world needs to solve for.” Subramanian framed the same shift from the user’s side: “Agents are like fundamentally about outsourcing a purchase and anyone who has ever outsourced a purchase knows that this comes with trade-offs.”

Concordium’s Agent Registry gives agents an on-chain identity tied to a verified human owner, and held 1,131 agents and more than 15,663 on-chain transactions as of July 14, 2026, the company said in July. Kabra said that linkage is not the same as exposure: “I always think of privacy and anonymity as completely different things.” He described the mechanism as “selective disclosure, there is zero knowledge proof, nobody knows it is you.”

Atul Khekade, co-founder of XDC Network, told us in an interview that the rails are not there yet: “AI doesn’t have a transaction layer right now.” The compliance piece is missing too, he said: “AI platforms don’t have a monetization compliance layer that they can use for, like, real transactions to execute actions.” Counterparties will not close that gap quickly, and “for them to come up with that infrastructure overnight is not going to be possible.”

The Defense Is Being Automated Too

Chainalysis says its Alterya platform helps banks and crypto businesses spot known scam destinations before funds leave. Machikhin was short on it: “We can’t live without AI, right?” He said his own tracing runs on the same kind of tooling, “with the help of our intuitive AI product, which shows the path of blocks being labeled, we can track.”

Maslauskaite calls the gap the “missing trust layer on the internet.” The raw material is already loose: “our digital identity attributes are scattered everywhere. We do not have any control of them.” Crypto verifies the transaction, not the assumption someone made before authorizing it. For agents she draws the line Kabra does: “behind every agent you would need to verify who’s acting.”

What Comes Next

Khekade said demand is arriving ahead of the infrastructure, with the market growing “at the speed of light almost.” A criminal may not need a bug in the code at all. Maslauskaite said the rules are running behind too: “the technology develops way more quicker than the regulation as we know.”

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button