Crypto-linked fraud losses reached $11.4 billion in the United States alone in 2025, according to the FBI's Internet Crime Complaint Center (IC3), accounting for more than half of total U.S. internet crime losses. Globally, on-chain scam revenue hit at least $14 billion and is expected to surpass...
"AI is no longer augmenting fraud — it is automating it. We are seeing entire extortion campaigns run end-to-end by language models." — Sysdig Threat Research Team, July 2026
Crypto-linked fraud losses reached $11.4 billion in the United States alone in 2025, according to the FBI's Internet Crime Complaint Center (IC3), accounting for more than half of total U.S. internet crime losses. Globally, on-chain scam revenue hit at least $14 billion and is expected to surpass $17 billion once wallet attribution is complete, per Chainalysis. The primary accelerant: artificial intelligence.
TRM Labs' 2026 AI-in-Crime Adoption Index, published August 17, places AI adoption across crypto crime at 54 out of 100 — up from 28 in 2024 — with scams the only crime type to reach the "Mature" classification. Reported deepfake-scam losses in the first half of 2026 already exceed all of 2025 by 263%. The crypto industry's response is a mirror image: Binance alone has deployed over 100 AI models that blocked $10.53 billion in risky funds over 15 months. The result is a quantifiable arms race between AI-powered offense and AI-powered defense, with billions of dollars moving between each side of the ledger every quarter.
The FBI's 2025 IC3 annual report, released in April 2026, documents the worst year on record for cyber-enabled fraud in the United States: $20.9 billion in total reported losses across 1,008,597 complaints, a 26% increase over 2024. Cryptocurrency-linked complaints totaled 181,565 — a 21% year-over-year increase — with $11.37 billion in losses and an average reported loss of $62,604 per complaint.
Crypto investment fraud was the single largest loss category at $7.2 billion. Recovery scams — where fraudsters pose as law firms, government officials, or the IC3 itself to extract additional funds from prior victims — generated 10,516 complaints and $1.4 billion in losses. Americans aged 60 and older filed 44,555 crypto complaints and reported $4.4 billion in losses, the largest share of any age bracket.
Globally, Chainalysis estimates at least $14 billion in on-chain scam revenue for 2025, with the figure expected to surpass $17 billion as investigators attribute additional wallets. Impersonation fraud — a category dominated by AI-generated content — surged 1,400%, with average victim payments rising from $782 in 2024 to $2,764 in 2025, a 253% increase. Scam operations with on-chain links to AI vendors generated 4.5 times more revenue per operation than those without, averaging $3.2 million each.
TRM Labs' 2026 AI-in-Crime Adoption Index quantifies the shift. The composite index climbed from 28 in 2024 to 54 in 2026, with the steepest gains in scams and hacking. The share of scam reports where AI played a documented role — deepfakes, AI chatbots, AI-branded lures — has grown roughly 13 times since 2022.
The operational economics are stark. No-code ransomware kits sell for $400–$1,200. AI-generated phishing emails and deepfake video calls cost fractions of a cent per target. The FBI broke out AI-enabled fraud as a standalone IC3 category for the first time in its 2025 report: 22,364 complaints carrying an AI descriptor, with $893.3 million in adjusted losses for calendar year 2025 alone.
Deepfake losses are accelerating. A study from security firm Surfshark puts documented global losses from deepfake-enabled fraud at $3.7 billion, with approximately 89% recorded in 2025 and the first half of 2026. The most prevalent tactic remains the fake celebrity endorsement video — often a fabricated livestream or paid advertisement — promising to double any cryptocurrency sent to a specific wallet address. Deepfake Elon Musk videos remain a persistent vector, according to multiple fraud tracking services.
Crypto hacks hit a record 201 in H1 2026, more than double the year-over-year rate. However, concentration risk is high: just 4% of incidents drove 75% of losses, according to TRM Labs.
Pig butchering — long-duration romance and investment scams — remains the single costliest fraud category tracked by the FBI. The IC3 recorded $7.2 billion in crypto investment fraud losses in 2025, dominated by pig butchering operations.
The operational model is evolving. In 2024, pig butchering relied on human-operated text messaging at scale, typically from forced-labor compounds in Southeast Asia. In 2026, operations increasingly deploy AI-generated deepfake video calls, allowing scammers to conduct live video interactions as entirely fabricated persons. This eliminates the language barriers and script inconsistencies that previously allowed victims to identify fraud.
The scale is industrial. Chainalysis identified compound operations in Myanmar, Cambodia, and Laos processing thousands of concurrent victim relationships. The U.S. government transferred $225 million in USDT seized from a single pig-butchering operation directly to Tether in January 2026.
July 2026 marked a technical milestone. Sysdig's Threat Research Team disclosed JADEPUFFER, described as the first documented case of agentic ransomware — a complete extortion operation driven end-to-end by a large language model.
The attack chain: the AI agent exploited CVE-2025-3248 in internet-exposed Langflow instances, harvested cloud and cryptocurrency credentials, dumped a PostgreSQL database, pivoted into a production MySQL server running Alibaba Nacos, forged JSON web tokens using known default signing keys, encrypted 1,342 configuration items using MySQL's AES functions, and left a ransom table demanding payment in Bitcoin.
When the agent's initial attempt to insert a backdoor administrator account failed, it diagnosed the cause and deployed a corrected payload within 31 seconds. From reconnaissance through credential theft, lateral movement, privilege escalation, and encryption, the entire operation ran autonomously.
The economic implications are significant. TRM Labs reports that "vibe-hacking" ransoms — operations run primarily by AI agents — range from $75,000 to $500,000 or more in BTC. The barrier to entry for sophisticated ransomware operations has collapsed from requiring a skilled development team to requiring a prompt and a $400–$1,200 no-code kit.
The exchange sector's response mirrors the attack surface. Binance, the largest exchange by trading volume, disclosed deploying more than 100 AI models across 24 AI-powered security programs. From Q1 2025 through Q1 2026 — a 15-month window — these systems blocked $10.53 billion in risky funds and intercepted 22.9 million scam and phishing attempts, protecting 5.4 million users.
In Q1 2026 alone, Binance intercepted $1.98 billion in risky transactions. The exchange reported that its AI systems slashed phishing success rates eightfold, cut illicit fund exposure by 96%, and increased KYC processing throughput by 100 times. AI now powers 57% of Binance's fraud detection systems.
Binance's Wallet Security Center, a more targeted tool, prevented approximately $540 million in potential losses in H1 2026, filtering 206 million spam transfers across 19 chains, flagging 4.93 million high-risk transactions, and detecting 996,000 malicious approvals.
OKX adopted Chainalysis Alterya, an AI-powered fraud prevention solution that detects scam infrastructure at inception across the web and enables real-time prevention of transfers to active scam accounts. OKX reported protecting more than $1.1 billion in customer assets during H1 2026, with AI-powered fraud detection preventing $26.3 million in scam-related losses specifically.
Coinbase partnered with Chainalysis on March 15, 2026, integrating advanced blockchain analytics tools for fraud detection. Kraken introduced biometric verification and enhanced identity checks on March 26, 2026.
The industry-wide shift toward AI-powered identity verification is measurable. According to aggregated industry data: 92% of centralized crypto exchanges now enforce full KYC compliance. 87% of KYC solutions use machine learning to identify fraudulent documents in real-time. Biometric authentication adoption has grown 65% year-over-year. Liveness detection technologies are standard in 72% of KYC platforms, reducing deepfake attacks during onboarding by 39%.
The results are visible in onboarding data. Biometric authentication cut fake account registrations by 76% on leading platforms. KYC compliance on exchanges rose 47%, blocking anonymous fund movements by scammers.
However, the arms race continues. AI-generated synthetic identities contributed to roughly one-third of new fintech fraud cases in 2025. Facial deepfake fraud attempts increased by more than 300% during digital onboarding processes. The defense layer is improving, but the attack surface is expanding at a comparable rate.
More than 65% of compliance leaders increased spending on AI-based fraud detection tools in 2026 budgets, according to industry surveys. AI monitoring systems flagged 88% of suspicious activities prior to major financial damage, suggesting that the detection rate is high but that prevention — stopping the funds from moving — remains the harder problem.
International law enforcement has escalated crypto fraud operations. The FBI's Operation Level Up, launched in January 2024, had alerted nearly 9,000 victims and prevented an estimated $562 million in losses as of April 2026.
A coordinated international crackdown resulted in 276 arrests, the shutdown of nine scam centers, and the freezing of more than $701 million in cryptocurrency linked to money laundering. The U.S. government's January 2026 transfer of $225 million in seized USDT directly to Tether represented a novel recovery mechanism — returning stablecoin to the issuer rather than liquidating through traditional channels.
Binance reported recovering $12.8 million directly and assisting authorities in confiscating $131 million in illicit funds during 2025. These figures, while meaningful in individual cases, represent a fraction of total losses — suggesting that the enforcement apparatus remains substantially behind the operational scale of AI-powered fraud networks.
The data describes an industry in which AI has become the primary variable on both sides of the fraud equation. Attackers deploy deepfakes, AI chatbots, and autonomous agents to industrialize scam operations at declining marginal cost. Defenders deploy AI models, biometric systems, and real-time blockchain analytics to intercept funds before they leave the platform.
The scale mismatch remains. Binance's $10.53 billion in blocked funds over 15 months is substantial, but it represents funds that reached the platform — not the universe of fraud that never touched a centralized exchange. The FBI's $562 million in prevented losses through Operation Level Up represents fewer than 9,000 victims out of 181,565 complaints filed in 2025 alone.
The JadePuffer incident signals a structural shift. When an AI agent can autonomously execute a complete ransomware chain — from initial exploit to Bitcoin ransom demand — in seconds, the cost curve for sophisticated attacks has fundamentally changed. The question for the industry is whether defense-side AI investment can maintain pace with offense-side capabilities that are now available as commodity tools for under $1,200.
The economic value at stake is not speculative. It is $11.4 billion in documented U.S. losses, $17 billion in estimated global on-chain theft, and an attack surface that grows with every new AI model release. The arms race is quantifiable, and for now, the attackers hold the cost advantage.