Key Takeaways
- Crypto impersonation scams increased more than 1,400% in 2025, while average payments to associated clusters rose over 600%.
- AI-linked scam operations generated 4.5 times more revenue and about nine times more transaction activity than operations without observable AI links.
- Deepfake identity attacks are exposing weaknesses in conventional KYC checks, even as exchanges, stablecoin issuers, and law enforcement expand detection and recovery efforts.
Chainalysis reports that impersonation scams grew more than 1,400% in 2025, while average payments into those clusters climbed more than 600%. The average payment across all crypto scam categories also increased, rising from $782 to $2,764.
The underlying deception is familiar: fake customer-support representatives, fabricated investment advisers, romance approaches, and messages posing as government notifications. Coinbase, E-ZPass, and convincing exchange "support agents" have all appeared as impersonation lures. What has changed is the cost of running those campaigns at scale.
Previously, fraud networks needed people who could maintain conversations, adapt scripts, translate messages, and keep multiple victims engaged for weeks. Generative AI can now perform much of that work through chatbots, synthetic voices, translated content, and rapidly generated websites. One operator can manage far more conversations without adding a comparable number of employees.
The financial results are visible on-chain. Chainalysis found that scam operations with observable links to AI tooling vendors extracted an average of $3.2 million, compared with $719,000 for operations without those links. AI-connected operations generated 35.1 transfers per day, versus 3.89 for the comparison group. That amounts to roughly 4.5 times the revenue and nine times the activity.
TRM Labs separately reported close to a 500% increase in AI-enabled scam activity over the past year. Outside crypto, the pattern is similar. Consumers lost $2.95 billion to impersonation scams in 2024, according to FTC figures, while the Identity Theft Resource Center recorded a 148% increase in such scams from April 2024 through March 2025.
Better language generation is only part of the threat. Synthetic identities and deepfake video are also challenging know-your-customer (KYC) systems built to detect printed photographs, recorded clips, and relatively basic physical spoofs.
Bypassing parts of that verification stack costs roughly $20 and takes about 30 minutes. Injection attacks, which feed synthetic video directly into a verification interface rather than presenting it through a camera, defeated standard liveness checks 58% of the time. Blinking or turning a head is no longer a persuasive signal when software can reproduce both.
Binance Research reports that crypto represents 88% of detected deepfake fraud globally. North American losses connected to deepfakes exceeded $410 million in the first half of 2025, and around 80% of attacks targeting Binance involve some degree of KYC fraud.
That shifts the security burden. The chief security officer at Binance noted that code is no longer necessarily the weakest link in Web3 as attackers focus on people, credentials, and governance. Binance Security, for example, helped prevent a $1.2 million governance attack on BrainTrust. Stronger smart contracts offer limited protection if a forged identity obtains administrative authority.
Detection is improving, but recovery remains a separate challenge. Binance Research reports efficiency gains of up to 100 times from using AI in KYC processing, including face-attack detection and liveness models retrained against new spoofing methods. Yet faster screening does not create certainty. It mainly lets security teams inspect more activity.
There is some advantage after funds move. Public enforcement data puts frozen Tether at more than $4.4 billion as of April 2026. The T3 Financial Crime Unit, a collaboration involving Tether, TRON, and TRM Labs, froze more than $300 million during its first year, including $19 million associated with the Bybit hack.
Law enforcement has expanded its response as well. INTERPOL's Operation First Light 2026 involved 97 countries, produced nearly 5,800 arrests, and intercepted $293 million. Europol's Operation Endgame froze about $47 million, disabled 326 servers and 142 domains, and recovered 27 million stolen credentials.
Still, what happens before the payment? For crypto businesses, identity assurance increasingly involves layered behavioral checks, transaction monitoring, privileged-access controls, and independent verification for sensitive actions. The crucial metric may be the widening gap between the low cost of creating a convincing identity and the much higher cost of proving that identity is real.
⬇️