In 2026, deepfake scams have become a significant threat in the crypto world, with reported losses exceeding last year’s total by 263%, according to TRM Labs. This highlights a growing issue in crypto security, where attackers are focusing on manipulating authorized users rather than breaking blockchain code.
TRM Labs’ AI-in-Crime Adoption Index classifies scams as the only category of crypto crime where artificial intelligence has reached a “Mature” level of adoption. The use of AI on the scammer-side, including deepfakes, chatbots, and AI-powered lures, has increased approximately 13-fold since 2022.
This shift exposes a vulnerability that traditional smart-contract security does not address. Even if an exchange account is properly authenticated, a hardware wallet signs correctly, or a smart contract executes as programmed, funds can still end up in the hands of an attacker if a deepfake convinces the user to approve a transaction.
This places more emphasis on security measures before authorization, such as verifying account-recovery requests, approving transfers, or accepting payment instructions from familiar sources. The moment before authorization becomes crucial in preventing deepfake scams.
TRM’s index measures the prevalence of AI in different types of crime, the stages at which it is used, and the sophistication of the tools involved. The use of AI in scams has increased significantly since 2022, with reported losses from deepfake scams in 2026 being 263% higher than in 2025.
Other datasets also support the trend of AI being used more frequently by scammers. Chainalysis reported a significant increase in inflows to impersonation scams, while the FBI’s Internet Crime Report recorded a high number of complaints related to AI and cryptocurrency descriptors.
The use of AI by scammers makes impersonation cheaper, more convincing, and easier to scale. Attackers can use AI to maintain conversations in multiple languages, create synthetic videos, clone voices, and generate fraudulent documents and communications.
In the crypto world, where transactions are irreversible once authorized, deepfake scams pose a significant risk. Smart-contract vulnerabilities remain common, but attacks focused on compromising infrastructure and operations have led to the largest losses. Deepfakes help attackers obtain cooperation rather than simply stealing access, making post-onboarding identity checks more critical.
Crypto companies need to implement stronger verification processes to prevent deepfake scams. This could include multiperson approval, pre-established confirmation channels, and delays before new withdrawal addresses become active. Blockchain monitoring tools can help detect suspicious activity, but the key lies in challenging the identity of the person giving instructions before a transaction is signed.
In conclusion, as AI continues to make impersonation more effective, the focus on verifying the authenticity of users before authorizing transactions becomes increasingly important in combating deepfake scams in the crypto space.
