TRM Labs: AI Crypto Crime Up 40% YoY; Bitcoin Scams in Focus

TRM Labs' AI-in-Crime Adoption Index shows criminal AI use up 40% YoY, scams rated Mature, and deepfake losses up 263%.

(10:17 AM UTC)
4 min read
AI SummaryAI
  • TRM Labs' AI-in-Crime Adoption Index placed overall criminal AI adoption at 54 out of 100 in 2026, up from about 28 in 2024.
  • Scams are the only crime category rated Mature in TRM Labs' index, with AI used for target lists, deepfakes, and victim conversations.
  • The share of scam reports involving AI has grown about 13 times since 2022, and 17% of active crypto scam domains advertise AI products.
  • Reported deepfake scam losses for 2026 already exceed the entire 2025 total by 263%.
d2mv6ykl

Artificial intelligence has become a mainstream tool in crypto-enabled crime, with blockchain intelligence firm TRM Labs reporting a 40% year-on-year rise in criminal AI adoption in 2026. TRM's AI-in-Crime Adoption Index puts overall adoption at 54 out of 100, up from roughly 28 in 2024, and rates four crime categories on how commonly AI is used, how many stages it touches, and how advanced its role is. Scams top the ranking and are the only category rated Mature: AI now assembles target lists, builds lures, generates deepfakes, and personally runs conversations with victims. The share of scam reports involving AI has grown about 13 times since 2022, while 17% of active crypto scam domains advertise AI products, including AI trading bot platforms. Reported deepfake scam losses for 2026 already exceed the entire 2025 total by 263%. The report also places narcotics at the opposite end of the adoption spectrum, noting that darknet buyers warn each other away from markets they suspect were AI-generated. TRM built the index to measure not just how often AI appears in crime but how deeply it is embedded in each stage of an attack, a distinction that separates automated schemes from manually operated ones. The authors call this depth of integration the key difference between opportunistic crime and industrialized fraud. That distinction makes the Mature label on scams particularly significant. For Bitcoin holders, the findings are a reminder that fraudulent outreach is no longer limited to static phishing pages; automated systems can now imitate service providers, clone interfaces, and tailor lures in real time. TRM notes that AI gives investigators a harder problem but also better tools, since pattern-recognition models can be pointed at suspicious blockchain activity. That conclusion matters for the broader market because the same AI tools are cheap enough for small groups to deploy, making retail users the primary exposure point.

On the hacking side, volumes are climbing even faster than the adoption index suggests. TRM logged 201 breaches in the first half of 2026, against 83 in the same period a year earlier, but losses are heavily concentrated: just 4% of incidents produced 75% of all stolen value. North Korea-linked actors accounted for roughly $600 million, or 61% of the half-year total. Two April operations dominate that figure: the $285 million Drift Protocol breach and the $292 million KelpDAO exploit, both initiated through social engineering rather than novel code. TRM classes hacking and state-sponsored theft as Emerging rather than Mature, but the volume data tells a harsher story. The concentration of losses in 4% of incidents suggests attackers with AI support can now execute high-value operations more reliably. The two incidents ranked among the largest crypto thefts of the year and underscored how a single compromised credential can bypass audited code, making key management a core security control. Ransomware sits one step further along the automation curve. No-code ransomware kits now change hands for $400 to $1,200, removing the programming barrier for would-be extortionists. In July, security firm Sysdig documented JadePuffer, which it calls the first fully agentic ransomware; an AI agent handled reconnaissance, credential theft, lateral movement and encryption without human direction. The report notes that commercial AI tools are cheap and widely available, so the same capabilities are likely to spread quickly. TRM's broader finding is that AI touches every stage of the crime lifecycle, lowering the barrier to entry while increasing the scale and sophistication of attacks. For crypto teams, that shifts the battleground toward faster detection, stricter privileged-access controls, and closer monitoring of wallet activity. Security teams, in turn, are being asked to verify both machine and human actors before trusting any privileged action, a trend that is reshaping incident response.

Read together, the two strands of TRM Labs' report point to a single trend: AI is compressing the entire criminal workflow, from first contact to final settlement. The primary document, the AI-in-Crime Adoption Index, ties each finding to how deeply AI participates in each stage of an operation. Our read is that enforcement and compliance tooling must scale at the same pace, or the current equilibrium between attackers and defenders will tilt further. For Bitcoin and the broader altcoin market, the practical implication is that security is becoming an identity problem, not just a code problem. Whether the entry point is a phishing email, a fake airdrop, or a cloned exchange portal, the attack is now often automated from the first message. In that environment, even AI crypto wallet features are only as trustworthy as the user's ability to verify who is on the other side.

Emily Watson

Emily Watson

COINOTAG author

View all posts
AI-AssistedTrading Analyst·Emily Watson is a trading analyst specializing in short-term trading strategies and daily/weekly market analysis.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Price-Impacting News

More News Articles