Summary
- AI adoption across crypto crime increased 40%, with scammers leading usage as deepfake losses and automated fraud expand rapidly worldwide.
- Hackers are integrating AI into social engineering and vulnerability discovery, while North Korean actors target cryptocurrency infrastructure more aggressively globally.
- Ransomware groups increasingly automate attacks using AI, while JadePuffer demonstrates autonomous reconnaissance, credential theft, network movement, and encryption capabilities.
AI adoption across crypto crime has increased by 40% over the past year, with scammers becoming the technology’s most advanced criminal users. TRM Labs placed overall adoption at 54 out of 100 in its 2026 AI-in-Crime Adoption Index, compared with 28 in 2024.
Scammers have reached the mature category, while hacking and ransomware remain emerging areas despite growing reliance on automated tools. TRM executive Ari Redbord explained that AI has not created new crimes but has removed constraints surrounding established criminal operations.
Consequently, individuals can automate activities that previously required larger teams, specialized technical knowledge, substantial resources, and considerably more operational time. Reports involving AI-powered crypto scams have increased thirteenfold since 2022, including schemes using deepfake impersonations and automated chatbot conversations. Moreover, reported deepfake scam losses during 2026 have already surpassed the entire 2025 total by an estimated 263%.
Also Read: Bitcoin Rockets Past $77,000 as Binance Short Squeeze Hits Historic Extreme
AI-Assisted Hacks Expand Across Crypto
Hackers are integrating artificial intelligence into operations targeting cryptocurrency companies, protocols, employees, wallets, credentials, and other digital infrastructure. TRM identified North Korean cyber actors using deepfake workers, automated social engineering, and AI-assisted vulnerability discovery against cryptocurrency targets.
Additionally, autonomous agents could increase attacks targeting passwords, wallets, and wireless networks across significantly larger groups of potential victims. Security engineer Taylor Hornby used artificial intelligence to uncover a critical vulnerability within Zcash’s Orchard transaction pool during June.
TRM recorded 201 digital asset hacks during 2026’s first half, more than double the figure reported during 2025. Significantly, around 4% of incidents generated 75% of losses, with private-key and credential theft driving major infrastructure compromises. North Korea-linked activity accounted for approximately $600 million, representing about 61% of first-half losses tracked within TRM’s dataset.
Ransomware Operators Increase AI Automation
Ransomware groups are using AI for phishing and initial access, while no-code ransomware kits cost between $400 and $1,200. Researchers also disclosed JadePuffer, described as the first fully agentic ransomware attack deployed as part of an extortion operation.
Its AI agent handled reconnaissance, credential theft, lateral movement, privilege escalation, and encryption without requiring constant human involvement globally.
Also Read: Peter Brandt Rejects XRP, Says He Would Convert Holdings Into Bitcoin
