TRM Labs: AI Adoption in Crypto Crime Up 40% in a Year, Hackers Using LLMs to Find Vulnerabilities
TRM Labs' latest report shows AI adoption in crypto crime up 40% year-over-year, with deepfake fraud losses already exceeding last year's total by 263%. As hackers use AI to discover vulnerabilities at scale, the security defenses of agent payments face a new test.

Blockchain analytics firm TRM Labs released a report on August 21 revealing that AI adoption in crypto crime has risen 40% year-over-year over the past 12 months. The company's 2026 AI Crime Adoption Index places the overall level of AI use in crypto crime at 54 out of 100—a "nascent" stage—compared to roughly 28 in 2024. The report shows that fraud is the most mature area of AI application, while hacking and ransomware remain in the "emerging" stage, and drug and darknet markets are still at the earliest "horizon" phase.
Ari Redbord, TRM Labs' Head of Global Policy and Government Affairs, said in the report: "AI hasn't invented new types of crime—it has removed the limits of old ones. The skill barrier has collapsed, the scale ceiling has been raised, and fake identities have become industrialized. What used to require a team can now be done by one person with a subscription."
The report disclosed several key data points: since 2022, the share of crypto fraud reports involving AI (such as deepfakes or AI chatbots) has risen by as much as 13 times. Deepfake fraud losses reported so far in 2026 are already 263% higher than the full-year total for 2025, indicating accelerating adoption of AI in fraud operations.
In the hacking domain, TRM Labs specifically called out North Korean cyber actors, noting they are using deepfake IT employees for infiltration, AI-driven social engineering, and AI-assisted vulnerability discovery to target companies and protocols. Several security experts have also recently warned that AI could significantly lower the technical barrier to vulnerability discovery, enabling attackers to scan and exploit flaws in smart contracts at much greater speed.
For the agent payment ecosystem, this report provides an unavoidable backdrop: when attackers use AI to discover vulnerabilities at scale, the traditional security model that relies on code audits and post-hoc remediation is failing. The core characteristics of agent payments—machine-to-machine, high-frequency, low-latency—mean that every transaction requires identity verification and intent validation before settlement. If attackers use AI-generated deepfake identities to pass KYC checks, or exploit AI-discovered contract vulnerabilities to intervene in the transaction flow before settlement, the consequences would directly impact fund security.
TRM Labs' data reveals an asymmetric attack-defense landscape: defenders must cover all possible attack surfaces, while attackers only need to find one entry point. For teams building agent payment infrastructure, this means a "pre-settlement firewall" is no longer optional—mechanisms such as KYA (Know Your Agent) identity verification, payout whitelists, per-transaction limits, and daily cumulative caps need to be embedded at the protocol layer from the design stage, not added as an afterthought. The progress of machine payment protocols like x402 in standardizing authorization intent and non-repudiation is, in some sense, a response to this threat: ensuring that every machine-initiated payment has a clear authorization boundary and an auditable trail.
The report also noted that the mature application of AI in fraud means social engineering attacks are becoming more scalable and personalized. Traditional risk control processes that rely on manual review will face severe challenges when confronted with AI-generated conversations and videos that are nearly indistinguishable from real humans. For stablecoin issuers and payment service providers, incorporating AI-vs-AI detection methods into compliance screening is shifting from a technical option to a dual necessity driven by both regulation and business.
Source: The Block · https://www.theblock.co/news/web3/2026-08-21-ai-adoption-in-crypto-crime-trm-412297
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-08-21
- Last updated
- 2026-08-23
- Content type
- Original compilation
- Source material
- View original ↗


