Key conclusions
- The use of AI technology in cryptocurrency crime has jumped 40% year-on-year, and fraud remains the main driver of this growth.
- Criminals are increasingly willing to implement AI to automate hacker attacks, social engineering and create fully autonomous ransomware.
- Losses generated by deepfake fraud in 2026 have already exceeded the entire balance from the previous year by 263%.
AI is making crypto crime way worse. TRM Labs says AI use in crypto crime jumped 40%, deepfake scams are exploding, and hacks already hit a record 201 cases in the first half of 2026. Scammers are getting dangerously good at this.

The use of AI in cryptocrime according to the TRM Labs index
The fraud category itself has already reached “mature” status. Hacking crime and ransomware attacks are at an emerging stage. In turn, the trade in illegal substances and illegal markets on the darknet remain in the earliest stages of development.
Artificial intelligence has not created new categories of crimes, but has removed existing enforcement barriers. The threshold for required technical skills has decreased, while the scalability of attacks has increased. The implementation of fake identities has become industrial. Tasks that previously required an entire team of people are now performed by a single operator with a paid subscription.
The number of incident reports in which fraudsters used chatbots or deepfake technology has increased 13-fold since 2022. This indicates the immediate commercialization of new solutions by criminal groups. Losses caused by deepfake materials in 2026 so far have exceeded the total result for 2025 by 263%.
Hacking and ransomware attacks based on AI agents
The second area with high implementation dynamics is digital hacking. Cybercriminals linked to North Korea widely use deepfakes to infiltrate companies as fictitious IT employees. They also use models to automatically detect protocol vulnerabilities.
The real threat comes from automated AI agents. An example is the variant detected by researchers called JadePuffer. This is the first fully autonomous ransomware (a malicious program that encrypts the victim’s data and demands a ransom to recover it) used in an extortion operation. The AI agent independently conducted reconnaissance, stole access data, took control of subsequent computers in the internal network, increased its own privileges and encrypted files without any human intervention.
The costs of tools to facilitate such operations remain low. No-code ransomware kits can be purchased on the black market for amounts ranging from $400 to $1,200.
The scale of losses and the role of AI tools in security breaches
Expert statements made during the Wyoming Blockchain Symposium 2026 confirm this direction. AI agents can crack Wi-Fi security, passwords and wallet keys on a massive scale, which was previously financially unfeasible.
In the first half of 2026, there were a record 201 hack attacks on digital assets. This result is more than twice as high as in the corresponding period of 2025. As much as 75% of total financial losses were generated by just 4% of all incidents. Most of them involved taking over infrastructure by stealing private keys. Groups linked to North Korea transferred approximately $600 million in this way, which translated into 61% of the losses in the first half of the year.
Tracking these flows is possible because most measured criminal activity ultimately transfers value through public networks. This means that analyzing data directly from the blockchain is an accurate reflection of actual criminal patterns.