NextFin News - Artificial intelligence has opened a new front in cryptocurrency cybercrime, with criminal adoption of AI tools surging 40% year on year and scams now classified at a "Mature" level of AI integration, according to a new industry report that traces the escalation to the mid-2025 release of powerful Chinese open-source AI models with no restrictions on generating malicious code.
The shift marks a structural break in the economics of crypto fraud: where sophisticated attacks once required skilled programming teams, generative AI and productized tooling now let a single operator run operations that previously demanded an organization. The question investors and regulators face is whether this is a temporary spike in criminal activity or a permanent ratcheting of the threat baseline that the industry must price in. The evidence — from the FBI's first-ever dedicated AI crime section to on-chain loss data that compounds faster than defensive spending — points to the latter.
The Numbers: A Crime Wave Measured in Billions
The scale of the problem is no longer anecdotal. TRM Labs' 2026 AI-in-Crime Adoption Index, published in August, puts overall AI adoption across crypto crime at 54 out of 100 — an "Emerging" level, up from 28 in 2024. The index scores each crime type on three components: prevalence of AI involvement, how many stages of the crime lifecycle show AI in use, and the sophistication of that use. Scams are the only crime type to reach "Mature," meaning AI now spans nearly the entire operation, from generating target lists and lures to running the conversations that sustain the fraud. Hacking and state-sponsored theft sit at "Emerging," climbing fast; narcotics trafficking remains at the earliest "Horizon" stage.
The financial toll is staggering. The FBI's 2025 Internet Crime Report, released in April 2026, found that cyber-enabled crimes defrauded Americans of nearly $21 billion in 2025, beating the previous record of $16.6 billion set in 2024 by 26%. Cryptocurrency complaints accounted for the largest single share: 181,565 complaints totaling more than $11 billion. For the first time in the report's nearly 25-year history, the Internet Crime Complaint Center added a dedicated section on artificial intelligence — 22,364 AI-related complaints costing Americans nearly $893 million. Total complaints topped 1 million for the first time, reaching 1,008,597, up from 859,532 the year before, meaning the system now processes nearly 3,000 complaints a day.
Chainalysis estimated that $17 billion was stolen in crypto scams and fraud in 2025, a record, with impersonation scams growing 1,400% year over year. AI-enabled scams are not just more numerous; they are materially more profitable. Scams with on-chain links to AI vendors extract an average of $3.2 million per operation compared with $719,000 for those without — 4.5 times more revenue per scam, according to a J.P. Morgan analysis published in July 2025. Those AI-linked operations also run with far greater efficiency: median daily revenue of $4,838 versus $518, and an average of 35.1 transfers per day versus 3.89, roughly nine times the transaction activity.
The average payment per scam rose to $2,764 in 2025 from $782 the year before, a 253% increase — evidence that AI is not only widening the net but deepening the take from each victim. And the velocity is accelerating: reported deepfake-scam losses in 2026 to date already exceed all of 2025 by 263%, and the share of scam reports where AI was demonstrably part of the scam — deepfakes, AI chatbots, AI-branded lures — has grown roughly 13 times since 2022.
Why Mid-2025 Was the Turning Point
The acceleration is traceable to a specific inflection: the middle of 2025, when powerful Chinese open-source AI models with no restrictions on generating malicious code became widely available. Before that release, criminals who wanted AI assistance faced guardrails — commercial models that refused to write malware, generate phishing copy, or help with credential theft. The open-source alternatives removed those constraints and, crucially, could be run locally, fine-tuned on criminal datasets, and embedded into automated tooling without an API provider monitoring usage.
TRM Labs frames the mechanism plainly:
"AI lowers the skill required to run sophisticated operations, allows a single operator to reach far more victims, automates tasks that once required large teams, and makes deception more convincing through synthetic media and large language models (LLMs)."
That sentence captures the entire threat in four clauses: lower skill floor, higher scale, cheaper labor, better lies.
The distribution channel for these tools is now frictionless. Chinese AI vendors selling face-swap software, deepfake technology, and large language models are reachable on Telegram, turning what was once custom-built attack infrastructure into an off-the-shelf purchase with customer support. This is the industrialization of fraud: the same productization that turned software development into a commodity has turned crime into one.
The speed of the underlying technology's diffusion explains why the crime wave arrived so abruptly. Generative AI reached 53% of the US population within three years of ChatGPT's launch — a faster path to that scale than either the personal computer or the internet managed at the same age, according to Stanford's 2026 AI Index. When a general-purpose capability diffuses that quickly and then escapes the guardrailed commercial layer into open-source, the criminal application follows with a lag measured in months, not years.
The Mechanism: Why This Is Structural, Not Cyclical
The critical judgment for investors is whether this crime wave is cyclical — a spike that will revert as defenses catch up — or structural, a regime shift that will not self-correct. Three lines of evidence point decisively to structural.
First, the driver is a general-purpose technology, not a patchable vulnerability. A cyclical crime wave has a short-term driver that exhausts itself: a single exploit family, a temporary liquidity window, a specific bridge weakness. The 2022 crypto hacks clustered around cross-chain bridge exploits and could be addressed by hardening bridge contracts. This wave has no such single point of failure. Its driver is a technology that has already reached majority penetration in the legitimate economy and cannot be recalled. Defenders can build better detection, but they cannot uninvent the model. Historical analogy is instructive: the personal computer and the internet each spawned decades of evolving cybercrime because the underlying capability was permanent. AI follows the same pattern, only the diffusion was compressed from two decades into three years.
Second, the economics have permanently shifted in the attacker's favor. The classic asymmetry of cybersecurity — defenders must be right every time, attackers only once — has been widened by AI. A single operator can now automate victim targeting, run thousands of simultaneous conversations, and deploy deepfakes that match human persuasion at a fraction of the cost. KnowBe4's 2025 Phishing Threat Trends Report found that 82.6% of phishing emails now contain AI-generated content, and AI-generated phishing achieves a 54% click-through rate compared with 12% for traditional human-written versions. IBM demonstrated in 2024 that AI can construct a complete phishing campaign in five minutes, a task that took human security experts 16 hours. When the cost of a convincing attack falls by orders of magnitude while the success rate rises, the equilibrium number of attacks rises with it — and stays there.
Third, the crime has productized. No-code ransomware kits sell for $400 to $1,200; "vibe-hacking" ransoms — AI-assisted, low-effort intrusions — run $75,000 to $500,000 or more in bitcoin. In July 2026, the first documented agentic ransomware attack, dubbed JadePuffer, showed autonomous systems moving beyond assistance into execution. When crime becomes a software product with customer support, the addressable market of offenders expands from skilled hackers to anyone with a credit card. This is the same force that turned blogging into a mass activity and day trading into a mass activity: tooling that removes the skill requirement expands the participant base permanently.
TRM Labs counted a record 201 crypto hacks in the first half of 2026, more than double the year-earlier period — yet just 4% of incidents drove 75% of the losses. The majority of those large incidents were infrastructure compromises involving private-key and credential theft, precisely the areas where AI-assisted social engineering and automated vulnerability discovery are most effective. DPRK-linked theft accounted for roughly 61% of first-half losses, around $600 million, with state actors using deepfake IT-worker infiltration and AI-run social engineering as operational tradecraft. CertiK's H1 2026 data corroborates the vector shift: wallet compromise was the most costly attack vector, with $444.5 million stolen across 33 incidents, while phishing ranked second at $366.3 million across 63 incidents — fewer attacks, higher value per breach.
The Counter-Thesis: AI Arms Defenders Too
The strongest argument against the structural-threat view is that AI is a dual-use technology, and the same tools empowering criminals are empowering investigators. TRM Labs notes that because much of this activity ultimately moves value on public blockchains, those changes can be observed and measured — and AI is improving the ability of investigators, financial institutions, and law enforcement to trace and disrupt illicit flows. Chainalysis and TRM Labs themselves are AI-native surveillance firms whose products are selling into the same trend. The FBI's Operation Level Up has already notified more than 8,000 victims and reduced losses by more than $500 million, and Operation Winter SHIELD launched in 2026 to harden organizational defenses.
Will Lyne, Head of Economic and Cybercrime at the Metropolitan Police, put the law-enforcement side of the equation directly:
"Fraud linked to cryptocurrency continues to grow in scale and sophistication, with organised crime groups increasingly using impersonation tactics, online infrastructure, and AI-enabled tools to target victims at pace and scale. However, we are also seeing a step change in law enforcement's ability to respond. Through specialist capabilities, international cooperation, and the effective use of financial and digital intelligence, we are better equipped to identify criminal networks, seize illicit assets, and disrupt activity that causes harm in our communities."
This is not a weak objection. Detection technology does improve, and the concentration of losses — 4% of incidents driving 75% of the damage — suggests that if regulators can force exchanges and custodians to close the specific infrastructure gaps that enable those few mega-incidents, the aggregate loss figure could fall even while the number of attempts keeps rising. The 40% year-on-year surge in AI adoption is a measure of criminal uptake, not criminal success; a rising adoption index is compatible with a falling success rate if defenses improve faster.
But this counter-thesis confuses containment with reversal. Better detection can reduce the success rate of individual attacks; it does not restore the pre-AI cost structure. The number of attempts is still rising, the skill floor is still falling, and the tooling is still getting cheaper and more capable. A defense that requires perpetual catching-up against an adversary whose capabilities compound with every model release is not a return to the old equilibrium — it is a new, more expensive steady state that the industry must fund indefinitely. The burden of proof sits with the cyclical view: it must show not just that defenses are improving, but that they are improving faster than the offense, and there is no evidence yet that they are.
Who Benefits, Who Is Exposed
The asymmetry creates clear winners and losers. The direct beneficiaries are the cybersecurity and blockchain-intelligence vendors — the firms selling the detection, tracing, and compliance tooling that exchanges, custodians, and financial institutions must now buy. Every dollar stolen is also a dollar of compliance budget justified, and the compliance budget is stickier than the loss figure: even if thefts fall, the tooling stays purchased. Regulatory pressure will only tighten: the FBI's decision to add a dedicated AI section to its annual report signals that AI-enabled fraud is now a first-order enforcement priority, not a niche concern.
The exposed parties are the platforms that hold customer assets. Infrastructure compromises — the category behind most of the largest 2026 losses — are a custodial risk, and each successful breach raises the cost of capital, insurance, and regulatory scrutiny for the entire sector. For crypto investors, the risk is not that AI will crash bitcoin or ether directly; cybercrime is a background constant, not a price-setting flow. The real risk is that repeated large-scale thefts erode trust in the intermediaries that make the asset class usable, slowing institutional adoption at the margin. Trust is the scarcest asset in crypto, and AI-enabled fraud is a tax on it.
There is also a second-order exposure that the market has not fully priced. As AI makes phishing and social engineering more convincing, the weakest link in crypto security shifts from code to credentials — from audited smart contracts to the humans who hold the keys. The industry has spent a decade and billions of dollars auditing code; the next vulnerability frontier is behavioral, and it is far harder to patch. Multi-signature custody, hardware keys, and transaction simulation become not just best practices but economic necessities, and platforms that treat them as optional will be the ones in the 4% of incidents that drive the losses.
What to Watch
The falsifying signal for the structural-threat thesis is specific: if the share of crypto crime attributable to AI falls for two consecutive quarters while the AI-in-Crime Adoption Index continues to rise, the link between AI diffusion and criminal success is weaker than it appears, and the wave may prove more cyclical than structural. Conversely, if deepfake-scam losses continue to compound at the current pace — already 263% ahead of the full prior year — the regime-shift call is confirmed.
Short term, watch the quarterly hack counts and phishing loss data from firms like CertiK and Chainalysis, plus the AI-adoption index from TRM Labs. Medium term, watch whether exchanges and custodians can reduce the concentration — the 4% of incidents that drive 75% of losses — through infrastructure hardening, and whether the average payment per scam ($2,764 in 2025) continues to rise. Long term, watch whether regulators force a structural change in how customer assets are held — mandatory proof-of-reserves, segregated custody, or real-time attestations — which would attack the theft mechanism rather than the symptom.
The uncomfortable conclusion is that crypto's cybercrime problem is no longer a bug to be patched but a cost of doing business to be managed — and AI has made that cost structurally higher. The industry can build better defenses, but it cannot go back to the world where a sophisticated attack required a sophisticated attacker. That world ended in mid-2025, when unconstrained open-source models put the capability in the hands of anyone who wanted it. The crime wave now being measured is simply the market catching up to that fact.
Explore more exclusive insights at nextfin.ai.
