TRM Labs published its 2026 AI-in-Crime Adoption Index on August 21, scoring overall AI adoption across crypto crime at 54 out of 100 — up from 28 in 2024, a 40% year-over-year increase. The index classifies AI use in scams as "mature," the only crime category to reach that designation. Hacking a...
"AI has not invented new crimes. It removed the constraints on old ones. The skill floor collapsed, the scale ceiling lifted, and fake identity went industrial — what used to take a team of operators now takes one person with a subscription." — Ari Redbord, Global Head of Policy, TRM Labs
TRM Labs published its 2026 AI-in-Crime Adoption Index on August 21, scoring overall AI adoption across crypto crime at 54 out of 100 — up from 28 in 2024, a 40% year-over-year increase. The index classifies AI use in scams as "mature," the only crime category to reach that designation. Hacking and ransomware remain at "emerging" levels, while narcotics and darknet markets sit at the earliest "horizon" stage.
The numbers are stark. Reported deepfake-scam losses in 2026 year-to-date already exceed the full-year 2025 total by 263%. The share of scam reports involving AI — deepfakes, chatbots, AI-branded lures — has grown approximately 13x since 2022. Across all crypto crime vectors, H1 2026 recorded 201-212 hacking incidents (depending on the source) with total losses exceeding $1 billion, the most-hacked half-year on record. DPRK-linked actors accounted for roughly $600 million, or 61% of H1 2026 stolen funds.
This report examines TRM's index methodology, the specific crime categories where AI has achieved operational scale, the emergence of agentic ransomware, and the countermeasures being deployed.
TRM Labs' AI-in-Crime Adoption Index assigns a composite score to track how deeply AI tools have penetrated crypto-adjacent criminal operations. The methodology spans five crime categories — scams, hacking, ransomware, CSAM, and narcotics — rated across adoption breadth, sophistication, and operational impact.
The headline number: 54 out of 100, classified as "emerging." Two years ago, the same index read 28. The increase reflects not a single breakthrough but a broad, incremental integration of commercially available AI tools into existing criminal playbooks.
Critically, the index does not measure AI as a cause of new crime types. It measures AI as a force multiplier for existing operations. The distinction matters: the crimes are not novel; the economics of executing them have changed.
| Crime Category | Maturity Level | Trend | |---|---|---| | Scams & Fraud | Mature | AI spans full operational chain | | Hacking / State-Sponsored Theft | Emerging | AI-assisted recon and social engineering | | Ransomware | Emerging | First agentic attack documented | | CSAM | Emerging | Detection evasion improving | | Narcotics / Darknet | Horizon | Adoption limited and skeptical |
Scams are the first and only crypto crime type where AI adoption has reached TRM's "mature" classification. The data underpinning this designation is unambiguous.
Scale of losses. TRM identified $35 billion in crypto scam activity during 2025. The FBI's IC3 report recorded $11.37 billion in American crypto scam losses in 2025 alone, a 22% increase over 2024. Investment fraud — the category covering pig butchering — accounted for $7.2 billion of that figure.
AI integration across the kill chain. AI now participates in nearly every stage of a crypto scam operation:
Deepfake acceleration. Deepfake-scam losses in 2026 year-to-date have already surpassed the full 2025 total by 263%. AI-scam losses jumped approximately 400x from Q1 to Q2 2026, according to TRM data. Pig butchering operations specifically grew 164% over the past year.
The economic logic is straightforward: AI collapses the labor cost of sustained deception. A pig butchering operation that previously required dozens of human operators to maintain weeks-long relationships with victims can now scale the same operation with a fraction of the headcount.
H1 2026 set records for hack incident count while exhibiting a familiar concentration pattern in losses.
Incident volume. TRM recorded 201 hacking incidents in H1 2026, more than double the 83 incidents in H1 2025. CertiK's Hack3D report tallied 344 on-chain incidents with $1.32 billion in losses. Blockaid's count stands at 212 incidents exceeding $1.1 billion. The variance reflects differing methodologies, but all sources agree: this was the most-hacked first half on record.
Concentration. TRM found that 4% of incidents drove 75% of losses. Two attacks dominated: the Drift Protocol breach (~$285 million) and the KelpDAO exploit (~$292 million), both occurring in April 2026. Both were attributed to DPRK-linked threat actors.
AI's role in hacking remains supplementary. Unlike scams, AI has not yet transformed the hacking kill chain. Its primary contributions are in reconnaissance automation, credential harvesting efficiency, and — most significantly — social engineering at the initial access stage. Smart contract exploitation still relies predominantly on human expertise, though the Zcash case (discussed below) demonstrates AI's potential in vulnerability discovery.
July 2026 produced a milestone: JadePuffer, documented by Sysdig researchers as the first fully agentic ransomware attack.
Attack mechanics. JadePuffer exploited a Langflow vulnerability (CVE-2025-3248) for initial access. From that entry point, an LLM agent autonomously executed the full attack chain: reconnaissance, credential theft via Nacos, lateral movement, privilege escalation, and encryption. The agent encrypted 1,342 configuration items, dropped original tables, and planted a ransom note — all without human intervention after initial deployment.
Adaptive behavior. Sysdig observed the agent correcting its own approach. After an initial backdoor creation attempt returned unexpected results, the agent generated a corrective payload within 31 seconds. This adaptive loop — attempt, evaluate, adjust — represents a qualitative shift from scripted malware.
Economics of no-code ransomware. TRM documents no-code ransomware kits selling for $400-$1,200 on criminal marketplaces. "Vibe-hacking" extortion demands range from $75,000 to $500,000+ in BTC. The cost structure implies that ransomware, traditionally requiring skilled operators, is approaching a price point accessible to low-sophistication actors.
The implications for crypto infrastructure are direct. DeFi protocols, DAOs, and custodial services represent high-value targets with potentially exploitable configuration surfaces. Agentic malware that can discover and adapt to novel configurations raises the baseline security requirement for any on-chain service.
North Korea's crypto theft operations represent the most sophisticated state-level integration of AI into crypto crime. The data is specific.
Financial scale. DPRK-linked actors stole approximately $600 million in H1 2026, representing 61% of all crypto hack losses in the period. In 2025, DPRK-linked theft totaled $2.02 billion. Cumulative theft from 2016 through H1 2026 stands at approximately $6.75 billion across 263 logged incidents, according to Chainalysis.
IT worker infiltration. On August 2, 2026, eleven nations issued a joint advisory warning that North Korean IT workers now use real-time deepfake video to defeat live hiring screens. The operation has evolved from individual operatives applying for remote positions to orchestrated fake hiring processes, where DPRK actors pose as recruiters for Web3 and AI companies to harvest credentials, source code, and VPN access.
Social engineering as primary vector. According to TRM, social engineering powered by AI-generated deepfakes has become the primary attack vector for DPRK operations, outpacing smart contract exploits for the first time. BlueNoroff, a Lazarus Group sub-unit, has deployed AI-generated deepfake pipelines to create convincing fake meeting participants using exfiltrated webcam footage.
Sanctions response. On March 12, 2026, OFAC designated new sanctions targets tied to the DPRK IT worker program. The enforcement action acknowledged the program's evolution from opportunistic remote work fraud to systematized intelligence collection infrastructure.
The TRM report documents AI's defensive applications alongside its offensive uses.
FBI Operation Level Up. As of April 2026, the FBI's proactive victim-notification initiative has contacted nearly 9,000 individuals and estimates it has interrupted approximately $562 million in losses. The program, which began in January 2024, uses analytical techniques (likely including AI) to identify active scam victims before their losses compound.
AI-assisted vulnerability discovery. In May 2026, security researcher Taylor Hornby used Anthropic's Claude to discover a critical soundness vulnerability in Zcash's Orchard zero-knowledge proof circuit. The flaw, present since Orchard's activation in May 2022, could have permitted unlimited undetectable counterfeit ZEC creation. Hornby produced a working exploit in a local test environment. Developers pushed an emergency soft fork on June 2 and deployed a hard fork on June 3 to patch the circuit.
The Zcash case illustrates a dual-use dynamic: the same AI capabilities that enable offensive operations can accelerate defensive auditing. The vulnerability had survived four years and multiple human audits before AI-assisted analysis identified it.
Industry investment. TRM Labs itself reached a $1 billion valuation in March 2026 after raising a $70 million Series C, reflecting institutional demand for AI-powered compliance and crime detection infrastructure.
The TRM Labs 2026 AI-in-Crime Adoption Index quantifies what the incident data already showed: AI has reached operational maturity in crypto scam operations and is advancing rapidly in hacking and ransomware. The transformation is economic, not conceptual. Criminal operations that required teams now require subscriptions. Identity fabrication that required expertise now requires $500. Ransomware that required skilled operators now requires a $400 kit and an LLM.
The implications for crypto infrastructure are structural. Protocols, custodians, and DAOs face an adversary population that is growing not because more people have the skills, but because the skill requirement has dropped. The security baseline required to operate crypto infrastructure must account for AI-augmented threats that adapt in real time, scale without proportional labor costs, and operate at speeds measured in seconds rather than hours.
The defensive applications — AI-assisted auditing, proactive victim identification, real-time deepfake detection — are real and growing. But the offensive adoption curve, as measured by TRM's index, is steeper. The gap between the two curves defines the risk environment for the next 12 months.