Crypto Impersonation Scams Skyrocket 1,400% with AI Assistance
Chainalysis reports a staggering 1,400% increase in impersonation scams in 2025, with AI-linked operations outperforming non-AI ones by a significant margin. Deepfake KYC (Know Your Customer) bypasses are now remarkably affordable and efficient, costing around $20 and taking approximately 30 minutes, successfully fooling standard liveness checks 58% of the time.
Impact of AI on Fraud:
- Revenue: AI-linked operations generate 4.5 times the revenue compared to non-AI operations.
- Activity: They are nearly nine times more active, reaching and converting more victims.
- Global Scams: Approximately 88% of all detected deepfake fraud globally involves crypto accounts.
Historical Context:
Historically, impersonation scams faced a headcount problem. Each scam required staffing, with someone trained handling conversations over weeks in various languages. This limited the number of simultaneous victims. However, generative tooling has removed this constraint, allowing for wider-reaching and more frequent attacks.
AI’s Role in Escalating Fraud:
- Economics: Chainalysis analysis reveals that AI-linked operations extracted an average of $3.2 million compared to $719,000 for non-AI operations, conducting 35.1 transfers daily versus 3.89.
- TRM Labs’ Observation: They independently noted a 500% surge in AI-enabled scam activity over the past year.
Expert Insights:
Jimmy Su, Chief Security Officer at Binance, emphasizes the evolving threat landscape:
"Code is no longer necessarily the weakest link in Web3… As smart contract security improves, attackers are shifting their focus to people, credentials, and governance systems surrounding protocols."
Lior Aizik, co-founder and COO of XBO, highlights the increasing sophistication of impersonation scams:
"Scammers have impersonated me by name, using fake profiles to contact industry contacts and request money under the guise of representing XBO. These attacks rely on urgency and the perceived legitimacy of a known figure."
Legacy Identity Checks vs. Modern Threats:
Identity checks were designed for printed photos, recorded videos, and basic physical spoofs. They often include liveness prompts like blinking or turning heads, which are ineffective against modern deepfake technology. Vendors like Socure and Zyphe offer detection products to combat these sophisticated injection attacks.