
AI use in crypto crime jumped 40% in a year, TRM Labs finds
AI adoption in crypto crime rose 40% over the past year, driven mainly by scammers, according to a new report from TRM Labs. The firm's 2026 AI-in-Crime Adoption Index places overall AI use across crypto crime at an emerging level of 54 out of 100, up from about 28 in 2024.
TRM ranked the categories by maturity. Scams sit at the top, rated mature in their AI use. Hacking and ransomware remain at the emerging stage, and narcotics and darknet markets stay at the earliest horizon level, with AI use concentrated mostly in marketing. The share of crypto scam reports involving AI, deepfakes or AI chatbots among them, has risen as much as 13 times since 2022. Reported losses from deepfake scams in 2026 have already surpassed the full-year 2025 total by 263%.
AI has not invented new crimes. It removed the constraints on old ones. The skill floor collapsed, the scale ceiling lifted, and fake identity went industrial. What used to take a team of operators now takes one person with a subscription.
Hackers are picking up AI at a similar pace. TRM said North Korean cyber actors are using deepfake IT-worker infiltration, AI-run social engineering, and AI-assisted vulnerability discovery to target firms and protocols, a pattern that connects to the wider trend we've covered in how AI is changing vulnerability discovery. In June, security engineer Taylor Hornby used AI to find a critical vulnerability in Zcash's Orchard transaction pool, one that could have let an attacker mint an unlimited amount of counterfeit tokens inside the pool.
It used to be so hard to try to hack a person worth $20,000 because why would you spend all that time going after one person? Now I can have an agent that goes after everyone.
- AI-in-Crime Adoption Index: 54/100 in 2026, up from about 28 in 2024
- Digital asset hacks in H1 2026: 201, more than double the 2025 full-year figure
- North Korea-linked activity: about $600 million, 61% of H1 2026 losses
- No-code ransomware kits: sold for $400 to $1,200
- Deepfake scam losses in 2026: up 263% over the full-year 2025 total
The scale of hacking losses tells its own story. Digital asset hacks hit a record 201 incidents in the first half of 2026, more than double the 2025 full-year figure. Around 75% of losses came from only 4% of incidents, most of them infrastructure compromises involving stolen private keys or credentials, and North Korea-linked activity accounted for about $600 million, or 61% of H1 losses.
Ransomware crews are moving the fastest toward full automation. Most operations already use AI at the phishing and initial-access stages, and no-code ransomware kits sell for $400 to $1,200. Last month, researchers disclosed JadePuffer, the first fully agentic ransomware attack used in a real extortion operation. An AI agent handled reconnaissance, credential theft, lateral movement, privilege escalation, and encryption from start to finish, with no human involved at any stage.
This is the shape of attacks at scale against hospital systems and critical infrastructure, with no human required in the loop. That is the scale that makes this a civilization-level threat.
TRM said most of the criminal activity it tracks still moves value on public blockchains, which makes onchain data a workable proxy for how these patterns spread across the industry. TRM's full report lays out the maturity ratings for each crime category in more detail.
This piece is informational, not a recommendation to buy, sell, or hold any asset.

Comments (0)
No comments yet — be the first!
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
247AI





