NewsCryptoTRM Labs: AI Use in Crypto Crime Rose 40% Over the Past Year

TRM Labs: AI Use in Crypto Crime Rose 40% Over the Past Year

Author: AI Crypto Core·

Key Takeaways

  • TRM Labs reported a 40% year-over-year increase in the share of crypto crime involving AI tooling.
  • The firm said attackers are using AI for phishing lures, fake identities, automated social engineering, and other deceptive workflows.
  • AI-assisted crime can lower attack costs and make threat detection more difficult for exchanges and compliance teams.
  • Synthetic identities and fabricated documents can put added pressure on KYC and transaction-monitoring systems under FATF and EU MiCA rules.
  • The article says defenders should watch whether AI-linked illicit activity continues to rise in future TRM reports and how EU AI Act transparency rules are enforced.
TRM Labs: AI Use in Crypto Crime Rose 40% Over the Past Year

Blockchain intelligence firm TRM Labs says the use of artificial intelligence in crypto crime rose 40% over the past year — a data point that pushes AI-blockchain convergence out of the compute-market narrative and into the threat-modeling column for exchanges and compliance teams.

What TRM Labs Reported

TRM Labs is one of the established names in blockchain analytics — alongside firms such as Chainalysis and Elliptic — supplying wallet screening, transaction monitoring, and forensic tracing to exchanges, financial institutions, and law enforcement. According to TRM Labs' 2026 crypto crime research, the share of crypto-related criminal activity involving AI tooling increased 40% year over year. The firm frames the increase specifically as crime enablement rather than as general AI adoption across the sector. The trend was also covered in reporting on TRM's findings.

In practical terms, "AI use in crypto crime" refers to threat actors folding machine-learning tooling into existing attack workflows: generative models for phishing lures and fake identities, automated social engineering, and scripted deception aimed at both retail users and protocol operators.

Why the Increase Matters for Crypto Security

The reported jump is newsworthy because it quantifies a shift many security teams have described anecdotally: adversaries are now automating steps that previously required manual effort, lowering the cost per attack. That operational change directly complicates threat detection for exchanges and compliance desks that rely on pattern recognition.

For compliance teams, AI-assisted attacks mean synthetic identities and fabricated documentation become cheaper to produce at scale, raising the bar for KYC and transaction-monitoring systems. Those burdens sit inside an already hardened rulebook — FATF's Travel Rule and the EU's MiCA regime extend banking-style KYC and monitoring duties to crypto-asset service providers — which makes AI-forged identities a regulatory exposure, not just a fraud loss. The pressure lands during a period when crypto security losses topped $1 billion in the first half of 2026, according to separate Blockaid data.

At the user level, the clearest near-term risk is more convincing scams: AI-generated messages, voices, and personas that are harder to distinguish from legitimate outreach. Deepfake-enabled fraud is documented well beyond crypto: in a widely reported 2024 case in Hong Kong, an employee at engineering firm Arup transferred roughly US$25 million after a video call in which every other participant turned out to be a deepfake. The same dynamic has already surfaced in the documented shift toward physical coercion seen in so-called crypto wrench attacks and rising security spending.

The convergence angle cuts both ways. The same generative and inference capabilities powering AI infrastructure crypto projects are the tooling TRM Labs identifies on the offensive side, and machine learning is already standard on the defensive side too — TRM Labs applies it to its own wallet risk-scoring — putting detection models on a collision course with automated abuse built on similar stacks.

TRM Labs' figure is a trend signal rather than a full threat map, and the underlying report is the grounding for any conclusion drawn from it. The concrete takeaway is narrow: defenders now have to assume attacker tooling is scaling with the same AI stack the industry is building on. The markers to watch are similarly concrete: whether AI-linked activity keeps rising as a share of overall illicit volume in TRM's subsequent reports, and how the EU AI Act's transparency rules — deepfake-disclosure obligations that begin applying in August 2026 — are enforced against AI-generated impersonation.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.