AI scam single transaction of 3.2 million dollars, the main battlefield of crypto security has shifted from "code" to "tricks."

CN
1 hour ago
On-chain scams reached 14 billion in a year: AI has raised the scale of single transactions to four times that of traditional scams.

Written by: Boaz Sobrado

Translation: AididiaoJP, Foresight News

Impersonation and AI-driven scams are becoming one of the biggest security threats in the crypto space. Data from Chainalysis shows that on-chain funds flowing into crypto scams reached at least 14 billion dollars by 2025. Of course, not all are related to AI. Rime Salmi, founder and CEO of Fractl, said in an interview, "Many people pose as investors, but they aren't. They are looking for investments, or are simply scamming." She believes that the technology itself is erasing boundaries: "AI is a buzzword, but we can no longer tell where people stand. If a company has only one person, can we still accept that? Or do we only invest in solid large teams?"

The economics of AI fraud

Salmi said that AI is no longer a standalone thing: "It is embedded in everything. So it itself is no longer an independent topic." Chainalysis statistics show that scams with on-chain associations to AI vendors have an average operation size of about 3.2 million dollars, while scams without such associations average about 719,000 dollars. The company did not express this correlation as a causal relationship. Salmi believes that the only defense that still stands is data that others cannot copy: "If a startup has solid proprietary data, others will find it hard to push it out with 'atmospheric programming' because truly high-quality, in-depth data takes years to accumulate."

In this subset identified by Chainalysis, deepfake, face-swapping software, and large language models are used to create false identities on a large scale. Erika Maslauskaite, CEO and co-founder of AlongID, said in an interview, "With today's AI, you can almost forge anything. Really, anything." She summed up the problem: "How do we verify what is real and what is fake?"

Hacking methods are also changing

AI scams have not rendered traditional hackers obsolete. Attackers do not need to breach smart contracts; it's sufficient to take down the people authorized to use the contracts.

Binance Chief Security Officer Jimmy Su stated, "Code is no longer necessarily the weakest link in Web3. With the enhancement of smart contract security, attackers are directing their attention to the people, credentials, and governance systems surrounding the protocols. We have personally experienced this: the Binance security team once helped thwart a 1.2 million dollar governance attack against BrainTrust. Protecting a protocol today is not just about safeguarding the code, but also about protecting who can control it, how control is exercised, and the underlying infrastructure and people."

In April 2026 alone, failures in access control accounted for about two-thirds of the 621 million dollars in DeFi vulnerability losses, according to data from Binance Research. Nitya Subramanian, founder and CEO of Para, said on the On The Margin podcast, "Wallets are essentially a layer of authorization and control over everything on-chain. Every chain, every DeFi primitive, every on-chain operation must go through a wallet. I think many people still do not fully understand this."

The attribution problem

Blockchain transparency remains one of the strongest evidential advantages in crypto, but attribution still requires context beyond the transactions. Dmitry Machikhin, founder and CEO of BitOK, pointed out in an interview that mixing coins is still a loophole: "Even Chainalysis does not have a 100% solution for coin mixing." He said that seizure notices do not always come to fruition: "There was a case where the Israeli government issued seizure notices for certain wallets in official documents. Logically, any exchange or any entity that interacts with crypto should block those wallets. But it did not happen."

Machikhin stated bluntly, "We have not caught anyone. We are just showing the flow of funds." He estimated the volume of illegal transactions to be "less than 0.1% of all transactions," and immediately added: this ratio underestimates the problem, "Even 0.1% is already quite large and continues to grow with the market." He also pointed out that crypto still dominates a specific channel: "In terms of terrorist financing, fiat currency is actually more efficient. But when it comes to transferring money on the dark web, crypto remains the number one priority path."

The Chainalysis 2026 report shows that UK law enforcement agencies recovered over 61,000 bitcoins in 2025 and seized 15 billion dollars linked to Prince Group.

The next target may not be people

Varun Kabra, Chief Growth Officer of Concordium, said on the On The Margin podcast, "The next step has already begun: AI agents are starting to trade for you. They pay, register services, and are likely already handling your financial transactions."

The gap lies at the receiving end: "Counterparties on the other side—such as airlines and ticketing platforms—cannot verify whether there is an accountable real person behind the transaction. This opens a door for fraud: robots impersonating humans, agents operating without any accountability."

Kabra predicts that in 6 to 12 months, agent traffic may exceed real human transactions, and believes, "The accountability between humans and agents is, in my view, the biggest problem this world needs to solve." Subramanian described the same change from the user side: "Agents essentially outsource the purchasing process. Anyone who has outsourced procurement knows that there will be trade-offs."

The Concordium Agent Registry provides agents with on-chain identities linked to verified real human owners. The company stated in July that as of July 14, 2026, there were 1,131 agents registered, with over 15,663 on-chain transactions. Kabra emphasized that this linkage does not equate to exposure: "I have always believed that privacy and anonymity are two different things." The mechanism he described is "selective disclosure, with zero-knowledge proof, where no one knows it is you."

Atul Khekade, co-founder of XDC Network, stated in an interview that the groundwork has not yet been laid: "AI does not currently have a transactional layer." The compliance layer is also lacking: "AI platforms lack a monetized compliance layer that can be used for real transactions and to execute actions." Counterparties will also not quickly fill this gap, "expecting them to build this infrastructure overnight is unrealistic."

Defense is also being automated

Chainalysis stated that its Alterya platform can help banks and crypto firms identify known scam addresses before funds leave. Machikhin was very straightforward about this: "We cannot survive without AI, right?" He said his tracking relies on similar tools, "With our intuitive AI products, which can outline the block paths, we can follow along."

Maslauskaite referred to the gap as "the missing trust layer on the internet." The raw materials are scattered everywhere: "Our digital identity attributes are all over the place, and we can't control them." Crypto can verify the transaction itself but cannot validate the assumptions made by the person who authorized it. Regarding agents, she drew the same line as Kabra: "Behind every agent, it must be verified who is acting."

What will happen next

Khekade said that demand has already outpaced infrastructure, and the market is "growing almost at the speed of light." Criminals may not even need coding vulnerabilities. Maslauskaite also believes that regulations are not keeping up: "The speed of technological development far exceeds the regulations we know."

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink