Login
Sign Up
Woofun AI reports that the primary vector for cryptocurrency theft has shifted from technical wallet breaches to the manipulation of human authorization decisions, placing a heavier security burden on the moment before transaction approval. This structural change means that whether an exchange validates an account-recovery request, a treasury signer approves a transfer, or an individual follows payment instructions from a trusted contact, the critical failure point is no longer code but consent. TRM's index quantifies this evolution by measuring the prevalence of AI across crime types, its application in targeting and deception stages, and the sophistication of the tools employed by attackers.
The scale of this transformation is evident in the explosive growth of AI-related scam reports. TRM's broader series, which captures all scam reports mentioning AI, has increased approximately 25-fold since 2022. This aggregate figure encompasses cases where victims utilized consumer AI tools while investigating suspected fraud, reflecting the pervasive integration of these technologies into daily digital interactions.
However, when isolating reports where scammers themselves deployed AI, the increase remains substantial at 13-fold. This distinction highlights that while victim-side AI usage is rising, the offensive capability of fraudsters leveraging artificial intelligence is growing at a similarly alarming rate, fundamentally altering the threat landscape.
Woofun AI data shows that financial losses associated with these advanced impersonation tactics have surged dramatically. Reported losses tied to deepfake scams in 2026, through the period covered by TRM's Aug. 17 report, were 263% higher than the reported total for all of 2025. This steep increase underscores the escalating effectiveness of synthetic media in facilitating fraud. TRM cautions that these figures are based on addresses currently identified and may fluctuate as attribution methodologies improve. Nevertheless, the directionality of the data is clear: deepfake-enabled fraud is not only becoming more common but is also resulting in significantly higher financial damages, indicating a maturation of criminal sophistication.
The mechanisms driving this surge rely on AI's ability to make impersonation cheaper, more convincing, and scalable. A single attacker can now maintain simultaneous conversations with victims across multiple languages, removing linguistic barriers that previously limited fraud operations. Synthetic video strengthens false identities during remote verification processes, while voice cloning technology can accurately imitate executives or family members, adding a layer of auditory credibility to fraudulent requests.
Furthermore, AI-generated documents, profiles, and communications ensure that fraudulent requests appear consistent across several channels, making it increasingly difficult for targets to discern legitimacy.
In the cryptocurrency sector, these risks are amplified by the irreversible nature of transactions once authorized. TRM's separate review of first-half crypto hacks indicated that while smart-contract vulnerabilities remained common, the largest losses were concentrated in infrastructure and operational compromises. Deepfakes extend this problem by enabling attackers to obtain voluntary cooperation rather than merely stealing access. Consequently, a recovery-factor change followed by a new device, new withdrawal address, and immediate transfer requires stronger verification protocols before assets leave the platform, as traditional technical safeguards are insufficient against socially engineered consent.
Corporate treasuries face a parallel threat where synthetic voice or video of an executive can pressure employees to approve transfers, alter signers, or add new payment addresses. Hardware wallets can confirm that the correct private key signed the transaction, but they cannot determine whether the human controlling that key was deceived. To mitigate this, organizations must implement multiperson approval processes, pre-established confirmation channels, and delays before newly added withdrawal addresses become active. These controls move the critical decision outside the communication channel controlled by the attacker, reducing the impact of real-time social engineering.
For individual holders, the attack vector is often simpler, relying on a convincing video call, voice message, or profile to persuade the victim to make the payment personally. In such scenarios, blockchain monitoring begins only after the decisive security failure has occurred, limiting its preventive utility. On-chain tools remain valuable for detecting suspicious flows, tracing stolen assets, and supporting freezes where centralized intermediaries can intervene.
However, they are less effective at stopping transactions that appear legitimate because the victim or authorized signer willingly approved them, highlighting a gap in post-transaction security measures.
TRM's data points to a critical security gap that sits outside the smart contract itself, necessitating a reevaluation of existing defenses. Crypto companies still require contract audits, private-key protection, wallet simulation, and transaction monitoring to maintain baseline security. Yet, as AI makes impersonation more effective, the most consequential control may increasingly be the one that challenges who is giving the instruction before an irreversible transaction is signed.
This shift demands that security frameworks prioritize pre-transaction identity verification over purely technical safeguards.