Crypto impersonation scams grew 1,400% as AI supercharged fraud


Crypto impersonation scams grew 1,400% as AI supercharged fraud

TL;DR

Chainalysis reports impersonation scams grew over 1,400% in 2025, with AI-linked operations generating 4.5x the revenue at 9x the activity of non-AI operations. Deepfake KYC bypasses now cost about $20 and 30 minutes, defeating standard liveness checks 58% of the time. Crypto accounts for 88% of all detected deepfake fraud globally. Enforcement has responded with $4.4B in frozen Tether and nearly 5,800 arrests across 97 countries, but none of that stops a forged identity clearing a check.

Impersonation scams grew more than 1,400% year over year in 2025, according to Chainalysis, with the average payment into those clusters rising more than 600%. Across all scam categories the average crypto payment climbed from $782 to $2,764.

An attack class does not scale like that because more people are running it. It scales because fewer people are running it with better tools.

Fraud Used to Have a Headcount Problem

An investment scam or a romance approach had to be staffed. Someone trained had to hold the conversation, in the victim’s language and across weeks. Those requirements set a ceiling on how many people a network could work at once, and for years the ceiling held.

Generative tooling removed it without changing the underlying deception. The con is the same one the industry has seen since the first fake exchange support agent. What changed is that the expensive part of running it stopped being expensive.

The economics are visible on-chain. Chainalysis found that operations with observable links to AI tooling vendors extracted an average of $3.2 million against $719,000 for those without, while generating 35.1 transfers a day against 3.89. That works out to roughly 4.5 times the revenue on about nine times the activity: the same operation reaching more people and converting more of them. TRM Labs separately observed close to a 500% increase in AI-enabled scam activity over the past year.

Chainalysis
Credit: Chainalysis

Code is no longer necessarily the weakest link in Web3,” says Jimmy Su, Chief Security Officer at Binance. “As smart contract security improves, attackers are shifting their attention to the people, credentials and governance systems surrounding protocols. We saw this firsthand when Binance Security helped prevent a $1.2 million governance attack on BrainTrust. Protecting a protocol today means securing not just its code, but also who can control it, how that control is exercised, and the infrastructure and people behind it.

The Verification Stack Was Built for a Different Attack

Identity checks were designed against a threat model of printed photographs, recorded video and low-grade physical spoofs. That is why liveness prompts still ask a user to blink or turn their head. The threat model moved and the prompt did not.

Vendor research from Socure puts the current cost of defeating that stack at roughly $20 and about 30 minutes, and finds that injection attacks, which feed a synthetic video stream straight to the verification interface rather than through a camera, defeat standard liveness checks about 58% of the time. Socure and Zyphe, whose figures it cites, both sell detection products in this category.

Across the crypto industry, impersonation scams are increasing and becoming more sophisticated,says Lior Aizik, co-founder and COO of XBO. “Scammers have impersonated me by name, using fake profiles to contact people in the industry and request money while pretending to represent XBO. These attacks rely on urgency and trust, not technology.

The volume lands disproportionately on this sector. Binance Research reports that crypto accounts for 88% of all detected deepfake fraud cases globally, that North American deepfake-related losses exceeded $410 million in the first half of 2025, and that around 80% of attacks against the exchange involve some level of KYC fraud.

Binance Research

Detection Is Automated. Recovery Is Not.

Two things are working against this volume, and only one of them is a model.

Automated screening is the first, and it mostly buys throughput rather than certainty: Binance Research reports up to a 100x efficiency gain from applying AI to KYC processing, with face-attack and liveness models retrained against each new generation of spoofing technique.

The other effective response is considerably older: coordinated enforcement and the ability to freeze funds after the fact. Binance Research puts Tether’s total frozen at more than $4.4 billion as of April 2026, and the T3 Financial Crime Unit, a joint venture with TRON and TRM Labs, at more than $300 million in its first year, including $19 million tied to the Bybit hack. Both figures come from the exchange’s research arm rather than from the issuers themselves.

Conventional law enforcement has scaled alongside it. INTERPOL’s Operation First Light 2026 spanned 97 countries as well as produced nearly 5,800 arrests and intercepted $293 million. Europol’s Operation Endgame froze about $47 million while taking down 326 servers and 142 domains and recovering 27 million stolen credentials.

None of that stops a forged identity clearing a check. It does mean the money can sometimes be stopped after it moves, which is something a wire transfer cannot offer and something the sector rarely bothers to argue in its own defense.

The Deception Is Old. The Price Is New.

The cons here are the ones fraud has always used. What changed is the cost of producing them, which makes the defensive question less about detecting novel attacks than about matching the rate at which familiar ones are now generated.

Reporting in this category remains incomplete, so every scam figure above should be read as a lower bound. The gap between what it costs to forge an identity and what it costs to check one is the number worth tracking, because everything else in this category follows it.

Get the TNW newsletter

Get the most important tech news in your inbox each week.