AI Use in Crypto Crime Jumped 40% in a Year, TRM Labs Reports. The Consequences Are Already Global.
Blockchain intelligence firm TRM Labs released its 2026 Crypto Crime Report finding that the active use of artificial intelligence across criminal operations in crypto rose 40% year-on-year.
Blockchain intelligence firm TRM Labs released its 2026 Crypto Crime Report finding that the active use of artificial intelligence across criminal operations in crypto rose 40% year-on-year. The firm's AI-in-Crime Adoption Index now scores overall AI tool integration at 54 out of 100, up from roughly 28 in 2024. That composite index score increased by approximately 93%; the separate 40% figure tracks active AI adoption specifically across criminal typologies, a distinct metric. Scam operators, state-linked hackers, and darknet actors are moving at different speeds toward the same destination: full AI integration across criminal operations. TRM Labs, valued at approximately $1 billion, is among the leading blockchain intelligence firms whose findings shape regulatory and law-enforcement strategy worldwide.
The numbers behind the report underscore how urgent the shift is. Total illicit on-chain flows reached $158 billion in 2025, a 145% increase from $64.5 billion the prior year and the highest five-year figure on record. Illicit volume as a share of total on-chain activity did fall slightly, from 1.3% to 1.2%, indicating that legitimate crypto use is growing faster than criminal activity. Crypto hacks alone generated $2.87 billion in losses across approximately 150 incidents. The single largest breach, the $1.46 billion Bybit hack in February 2025, accounted for just over half (51%) of the annual total on its own.
The Skill Floor Collapsed
TRM's head of global policy, Ari Redbord, summarized the structural shift plainly: "AI has not invented new crimes. It removed the constraints on old ones. The skill floor collapsed, the scale ceiling lifted, and fake identity went industrial; what used to take a team of operators now takes one person with a subscription."
Scam operations have reached what TRM classifies as a "mature" level of AI adoption. The share of crypto scam reports involving deepfakes or AI-generated chatbots has grown up to 13 times over since 2022. Deepfake scam losses recorded so far in 2026 have already exceeded the entire 2025 total by 263%. Hacking and ransomware groups sit at an "emerging" classification, while darknet markets remain at the earliest, or "horizon," stage of AI integration.
North Korea Sets the Benchmark
North Korea's state-linked hacking groups represent the most advanced example of AI being folded into an active criminal and geopolitical programme. DPRK-affiliated actors stole $1.92 billion in 2025 and another $643 million in the first half of 2026 alone. That H1 2026 figure represents 66% of all global crypto hack losses during that period, which totaled $972 million across 207 incidents.
The Kimsuky group, tied to North Korea's Reconnaissance General Bureau, has been observed using tools including Ollama, GPT4All, Msty, and Cursor AI, alongside local retrieval-augmented generation systems, to produce convincing phishing emails, obfuscate malicious code, and run real-time deepfake video calls to pass live job interview screens at technology companies. A joint advisory issued in August 2026 and signed by eleven nations, including the United States, France, Germany, Italy, and the Netherlands, confirmed that DPRK IT workers are now defeating video hiring checks using real-time AI deepfakes, then funneling their wages back to Pyongyang's weapons program.
Regional Exposure: Africa and South Asia
The threat is not evenly distributed, and two regions with fast-growing crypto user bases are absorbing a disproportionate share of the damage.
In South Africa, AI-assisted scam campaigns generate an average of R54 million per operation, compared to R12 million for non-AI operations, according to data from the Financial Sector Conduct Authority (FSCA). That 4.5 times profitability gap is driving rapid adoption among criminal networks. Impersonation scams grew 1,400% year-on-year in the country. Tactics include AI-generated celebrity endorsement videos (including documented deepfakes mimicking Elon Musk), WhatsApp-based phishing, and fake investment platforms that redirect deposits to unrecoverable wallets.
Sub-Saharan Africa is the third-fastest-growing crypto region globally, according to Chainalysis, and received roughly $186 billion in on-chain value between July 2024 and June 2025, a 52% expansion. That growth in legitimate activity expands the attack surface in parallel. A specific detection challenge compounds the problem: Tether (USDT) accounts for approximately 95% of sanctioned inflows in the region, yet USDT is simultaneously the primary vehicle for legitimate peer-to-peer dollar access across many emerging markets. That dual-use reality makes enforcement calibration difficult without disrupting ordinary financial activity.
India is a similarly exposed market. In the first week of May 2026, crypto scam losses in the country surpassed 3 crore rupees. A documented case from March 2026 involved AI-generated deepfake videos mimicking legitimate trading platforms, with proceeds routed through layered wallet chains. Voice cloning in regional languages has become an increasingly common vector, used to impersonate bank officials and exchange representatives. The country's large developer community also faces a specific supply-chain threat: campaigns distributing malicious npm and PyPI packages designed to exfiltrate SSH keys, GitHub tokens, cloud credentials, and browser-stored wallet data.
Southeast Asia: The Upstream Risk
Southeast Asia represents a critical upstream risk for South Asia and for the broader global picture. The United Nations issued a warning in July 2026 that cryptocurrency is now fuelling a $114 billion criminal economy across the region. Romance scams and pig-butchering operations, increasingly conducted in South Asian regional languages, have seen average individual scam payments rise 253% as operators deploy AI to personalise outreach at scale.
The Infrastructure Gap and What Comes Next
Infrastructure failures now account for 76% of hack losses, totaling $2.2 billion in 2025. Smart contract exploits, the dominant concern in earlier years, have been overtaken as attackers focus on key management failures and operational security gaps.
The emergence of AI agents as a new attack surface adds another layer of risk. In May 2026, an attacker exploited Bankr, an AI-powered trading assistant built on the X platform, in what TRM Labs identified as the first confirmed AI-agent exploit in crypto. CertiK CEO Ron Zhao stated: "Mass deployment of AI agents is a disaster waiting to happen," pointing specifically to execution environments that lack isolation and tool-calling permissions that remain unsandboxed.
The regulatory framework has not kept pace. Redbord has testified before the US House Financial Services Subcommittee that existing anti-money-laundering rules "were built for a world where suspicious transactions took weeks to trace, not one where illicit funds hop across blockchain networks in 24 to 48 hours." Without AI-native investigative capacity at agencies including FinCEN and the FBI, the gap between criminal capability and enforcement response will continue to widen.
For developers and financial institutions, the implications are concrete. npm and PyPI supply chains are active exfiltration vectors targeting credentials and wallet data. AI agent execution environments require sandboxing that most current deployments do not provide. And the Bank Secrecy Act framework was not built to operate at the speed at which funds now move across blockchain networks. The 2026 picture is not one of a new criminal ecosystem. It is the industrialisation of an old one, accelerated by tools that are cheap, accessible, and increasingly autonomous.