AI-driven impersonation scams are overtaking code exploits as a core crypto security threat
Impersonation and AI-assisted fraud are becoming one of the most serious security problems in crypto, shifting attention away from code bugs alone and toward identity, access control, and accountability. Chainalysis said at least $14 billion in on-chain funds flowed into crypto scams in 2025, though not all of that activity was tied to AI. Within a subset of cases linked on-chain to AI vendors, the average scam operation was about $3.2 million, compared with roughly $719,000 for scams without those links, a correlation the company did not describe as causal. Executives interviewed across the sector pointed to a broad change in attack methods. Binance Chief Security Officer Jimmy Su said smart-contract security has improved enough that attackers now focus more on people around protocols, credentials, and governance systems, citing Binance security team assistance in stopping a $1.2 million governance attack on BrainTrust. Binance Research also said access control failures accounted for about two-thirds of the $621 million lost to DeFi exploits in April 2026 alone. The report also highlights unresolved attribution issues, mixer-related tracing gaps, and a new frontier in AI agents that can pay, register for services, and potentially transact on users’ behalf. Several executives argued that the missing layer is not transaction verification itself, but trustworthy identity and responsibility behind those actions.

