Catenaa, Sunday, August 30, 2026- Artificial intelligence use in cryptocurrency crime increased 40% over the past year as scammers, hackers and ransomware groups adopted automated tools, blockchain intelligence firm TRM Labs said.
TRM placed overall AI adoption across crypto-related crime at 54 on a 100-point scale in its 2026 AI-in-Crime Adoption Index.
That compares with a score of about 28 in 2024.
Scams showed the highest level of AI adoption, reaching what TRM classified as a mature stage.
Hacking and ransomware remained at an emerging stage, while darknet markets and narcotics trafficking showed much lower adoption.
The findings suggest AI is changing the economics of existing criminal activity rather than creating entirely new forms of crime.
Scammers have been among the quickest to adopt generative AI.
TRM said the share of reported crypto scams involving deepfakes, AI-generated communications or automated chatbots has increased as much as 13-fold since 2022.
Losses linked to reported deepfake scams during 2026 have already exceeded the total recorded throughout 2025 by 263%, according to the firm.
AI lowers several barriers that previously limited fraud operations.
A scammer can generate convincing messages, fake identities, cloned voices or fabricated video without employing a large group of specialists.
Automated systems can also communicate with many potential victims simultaneously.
That allows criminals to test approaches across thousands of targets while spending little additional time on each one.
The technology can also improve language quality, making scams harder to detect through spelling errors or awkward phrasing.
Fake identities are becoming another concern.
AI-generated photographs and videos can be combined with stolen personal information to create convincing digital personas.
Deepfake technology can imitate executives, colleagues, relatives or public figures.
For financial companies, those tools create problems beyond consumer scams.
Attackers can use synthetic identities during recruitment, customer verification or internal communications.
Crypto companies are particularly exposed because employees may have access to private keys, wallet infrastructure and systems capable of moving digital assets quickly.
A successful impersonation can therefore lead directly to financial loss.
TRM said hackers are also increasing their use of AI.
North Korea-linked cyber groups have used deepfake technology in efforts to place fraudulent information technology workers inside companies.
Security researchers have also documented AI-assisted social engineering and vulnerability discovery.
AI systems can analyze software, search for coding weaknesses and help attackers identify targets more efficiently.
That does not mean autonomous AI can reliably defeat every security system.
It does mean attackers can automate work that previously required substantial human effort.
The economics are important.
Targeting an individual wallet holding a modest amount of cryptocurrency may have been uneconomic when an attacker needed hours of manual research.
An automated agent can attempt similar attacks against many users at once.
TRM said digital asset hacks reached a record 201 incidents during the first half of 2026.
That was more than double the number recorded during the comparable period in 2025.
Losses were highly concentrated.
About 75% of stolen value came from roughly 4% of incidents, according to TRM.
Many of those attacks involved infrastructure rather than flaws in individual DeFi applications.
Private-key compromises and stolen credentials accounted for much of the damage.
North Korea-linked activity represented about $600 million, or 61% of losses during the first half, TRM said.
That concentration shows why exchanges, custodians and blockchain firms increasingly focus on operational security alongside smart-contract auditing.
AI is not only helping attackers.
Security researchers are using the same technology to find vulnerabilities before criminals can exploit them.
One prominent example came from Zcash.
Security engineer Taylor Hornby used AI-assisted analysis in June to identify a critical weakness affecting Zcash’s Orchard shielded pool.
The vulnerability could have allowed counterfeit ZEC to be created inside the affected pool.
Developers disclosed the issue and later deployed protections.
The episode demonstrated AI’s ability to accelerate legitimate security research while highlighting what could happen if similar tools are used first by attackers.
The advantage may increasingly depend on which side discovers a weakness earlier.
Ransomware groups are also adopting AI at the earliest stages of attacks.
TRM said AI is already common in phishing and initial-access operations.
No-code ransomware kits are available for hundreds of dollars, reducing the technical knowledge required to launch an attack.
The development lowers the entry barrier for criminals who previously lacked programming skills.
More advanced operations are moving toward greater automation.
Researchers disclosed JadePuffer last month, which TRM described as the first fully agentic ransomware attack used in an extortion operation.
An AI agent reportedly handled reconnaissance, credential theft, movement across the victim’s network, privilege escalation and encryption.
That model could allow attacks to operate with less direct human involvement.
Traditional ransomware campaigns often require operators to make decisions throughout an intrusion.
Autonomous systems could change that.
An AI agent can potentially scan networks continuously, identify vulnerable machines and adjust its behavior as defenses respond.
That could allow a single operator to oversee far more attacks.
Critical infrastructure could become particularly exposed because hospitals, utilities and other large organizations often operate complex networks containing older systems.
Automation also increases the speed of attacks.
Human defenders may have less time to respond if software moves from initial access to asset theft or encryption in minutes.
AI adoption is not occurring evenly across criminal markets.
TRM said narcotics trafficking and darknet markets remain at an early stage.
Current use is concentrated mainly in marketing and communications.
Those operations often depend on physical supply chains, logistics and delivery.
AI can improve advertising or customer interaction, but it cannot replace the physical movement of illegal goods.
Crypto scams are different.
They can operate almost entirely online, making them far more compatible with automated tools.
That helps explain why scams have moved ahead of other criminal sectors in AI adoption.
Cryptocurrency also creates an unusual source of intelligence for researchers.
Transactions on public blockchains leave permanent records.
Criminals may hide identities or move funds through several addresses, but transfers can often still be traced across blockchain networks.
TRM said much of the criminal activity measured in its report eventually moves value through public blockchains.
That allows analysts to use onchain activity as one indicator of wider criminal trends.
AI may make scams easier to create, but it does not automatically make the resulting financial transactions invisible.
The report points toward an escalating contest between automated attackers and automated defenders.
AI can improve fraud detection, identify unusual wallet behavior and search software for vulnerabilities.
The same technology can generate convincing impersonations, automate phishing and help criminals find weaknesses.
That shifts the security problem from whether AI will be used to which side uses it more effectively.
The largest immediate change may be scale.
Crypto crime has always attracted attackers because transactions can move quickly and often cross national boundaries.
AI gives criminals the ability to target more victims at lower cost.
TRM’s findings suggest that transition is already well underway.
The technology may not have created new crimes.
It has made existing ones faster, cheaper and easier to reproduce.
