AI-driven impersonation scams are overtaking code exploits as a core crypto security threat

AI-driven impersonation scams are overtaking code exploits as a core crypto security threat

N
News Editor
2026-08-31 10:55:47
Impersonation and AI-assisted fraud are becoming one of the most serious security problems in crypto, shifting attention away from code bugs alone and toward identity, access control, and accountability. Chainalysis said at least $14 billion in on-chain funds flowed into crypto scams in 2025, though not all of that activity was tied to AI. Within a subset of cases linked on-chain to AI vendors, the average scam operation was about $3.2 million, compared with roughly $719,000 for scams without those links, a correlation the company did not describe as causal. Executives interviewed across the sector pointed to a broad change in attack methods. Binance Chief Security Officer Jimmy Su said smart-contract security has improved enough that attackers now focus more on people around protocols, credentials, and governance systems, citing Binance security team assistance in stopping a $1.2 million governance attack on BrainTrust. Binance Research also said access control failures accounted for about two-thirds of the $621 million lost to DeFi exploits in April 2026 alone. The report also highlights unresolved attribution issues, mixer-related tracing gaps, and a new frontier in AI agents that can pay, register for services, and potentially transact on users’ behalf. Several executives argued that the missing layer is not transaction verification itself, but trustworthy identity and responsibility behind those actions.

Impersonation and AI-assisted scams are emerging as one of the biggest security threats in crypto. Chainalysis said at least $14 billion in on-chain funds flowed into crypto scams in 2025, though not all of that activity was tied to AI.

Rime Salmi, founder and CEO of Fractl, said in an interview, 「Many people pretend to be investors, but they are not. They are trying to raise money, or they are just scamming.」 She said technology is blurring old boundaries: 「AI is a buzzword, but we can no longer tell where the human is. If a company has only one person, are we fine with that? Or do we still only back solid, larger teams?」

The economics of AI-enabled fraud

Salmi said AI is no longer a standalone category. In her view, it has been embedded across everything, which makes it less useful to treat it as a separate topic.

Chainalysis found that scams with on-chain links to AI vendors averaged about $3.2 million per operation, compared with about $719,000 for scams without those links. The company did not frame that relationship as proof of causation.

Salmi said one of the few defensible moats left is data that competitors cannot easily copy. If a startup holds strong proprietary data, she said, others will struggle to push it aside with 「vibe coding」 because high-quality, deep datasets can take years to build.

Within the subset identified by Chainalysis, deepfakes, face-swapping software, and large language models are being used at scale to create false identities. Erika Maslauskaite, co-founder and CEO of AlongID, said, 「With today’s AI, you can fake almost everything. Literally everything.」 For her, the central question is how to verify what is real and what is fake.

Attack methods are moving from code to control

The rise of AI scams has not made traditional hacking irrelevant. Attackers do not always need to break a smart contract if they can compromise the people authorized to use it.

Binance Chief Security Officer Jimmy Su said, 「Code is not necessarily the weakest link in Web3 anymore. As smart contract security improves, attackers are shifting their focus to the people around protocols, credentials, and governance systems. We have seen this firsthand: Binance’s security team helped stop a $1.2 million governance attack against BrainTrust. Protecting a protocol today is not just about protecting code. It is also about protecting who can control it, how that control is exercised, and the infrastructure and people behind it.」

Data from Binance Research showed that access control failures accounted for about two-thirds of the $621 million lost to DeFi vulnerabilities in April 2026 alone. Nitya Subramanian, founder and CEO of Para, said on the On The Margin podcast, 「A wallet is essentially the layer for all authorization and control flows on-chain. Every chain, every DeFi primitive, every on-chain action has to pass through the wallet. I do not think many people fully understand that yet.」

Transparency helps, but attribution remains hard

Blockchain transparency remains one of crypto’s strongest forensic advantages, but attribution still needs context beyond transaction records.

Dmitry Machikhin, founder and CEO of BitOK, said in an interview that mixers remain a major gap. 「Even Chainalysis does not have a one-hundred-percent solution for mixers.」 He also said seizure notices do not always translate into enforcement: 「There was one case where the Israeli government officially seized certain wallets in formal documents. In theory, any exchange or any entity touching crypto should have blocked those wallets. That did not happen.」

Machikhin put it bluntly: 「We have not caught anyone. We are only showing the money trail.」 He placed illicit transaction volume at 「less than 0.1% of all transactions,」 then added that the figure understates the problem because 「even 0.1% is already large, and it is growing with the market.」 He also said fiat is more efficient for terrorist financing, while crypto remains the first choice for moving money on the dark web.

Chainalysis’ 2026 report said UK law enforcement recovered more than 61,000 BTC in 2025 and secured a $15 billion forfeiture tied to Prince Group.

The next target may not be a human

Varun Kabra, chief growth officer at Concordium, said on the On The Margin podcast that the next phase has already begun: AI agents are starting to trade on users’ behalf. 「They pay, register for services, and by now they are very likely already handling your financial transactions.」

He said the gap is on the receiving side. Counterparties such as airlines and ticketing platforms cannot verify whether the entity behind a transaction is a real human who can be held accountable. That opens the door to fraud, with bots posing as people and agents operating without any accountability layer.

Kabra said agent traffic could exceed human trading within 6 to 12 months, adding that 「accountability between humans and agents is the biggest problem this world needs to solve.」 Subramanian described the same shift from the user side: 「An agent is basically outsourcing a purchase. Anyone who has ever outsourced procurement knows there are trade-offs.」

Concordium said in July that as of July 14, 2026, its Agent Registry had 1,131 agents and more than 15,663 on-chain transactions. The registry gives agents an on-chain identity linked to a verified human owner. Kabra said that link does not mean public exposure: 「I have always believed privacy and anonymity are two different things.」 He described the model as 「selective disclosure, with zero-knowledge proofs, and nobody knows it is you.」

Atul Khekade, co-founder of XDC Network, said the rails are still missing. 「AI does not have a transaction layer yet,」 he said. He added that AI platforms also lack a monetization and compliance layer that can support real transactions and execute actions, and that counterparties are unlikely to build that infrastructure overnight.

Defense is being automated too

Chainalysis said its Alterya platform can help banks and crypto firms identify known scam addresses before funds leave the system. Machikhin was direct about the role of automation: 「Without AI, we would not survive, right?」 He said his own tracing work also relies on similar tools that map block paths visually so investigators can continue following fund flows.

Maslauskaite described the current gap as 「the missing trust layer of the internet.」 In her view, digital identity attributes are scattered everywhere and people do not really control them. Crypto can verify the transaction itself, but not the assumption made before authorization that the person behind the action is genuine. On agents, she drew the same line as Kabra: every agent needs a verified answer to who is acting behind it.

Demand is outpacing infrastructure

Khekade said demand has already moved ahead of infrastructure and that the market is growing 「almost at the speed of light.」 In that environment, criminals may not even need code vulnerabilities. Maslauskaite also said rules are struggling to keep up: 「Technology is moving much faster than the regulation we know.」

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.