The dangerous part of an AI-generated voice or video is not that it can fool someone for ten seconds. It is that it can be inserted into a repeatable fraud operation: a convincing first contact, a fabricated investment dashboard, a rushed authorization, and a cryptocurrency transfer that is difficult to reverse.
That operation is already expensive for its victims. Chainalysis estimates that crypto scams and fraud took $17 billion in 2025. Its analysis found that scams with on-chain links to AI vendors extracted $3.2 million per operation on average, compared with $719,000 for scams without those links: 4.5 times as much revenue per operation. The same report says impersonation-scam revenue grew 1,400% year over year. Chainalysis’s 2026 Crypto Crime Report is a useful warning, but its number is an association, not proof that an AI tool caused every extra dollar.
It is also worth being precise about the language. “4.5 times as much” means 350% higher than the comparison group, not 450% more. The operational conclusion is still serious: if a scam becomes more persuasive and easier to localize, a criminal group needs fewer successful victims to fund a much larger operation.
Start With the Evidence, Then Design for the Failure Mode
The defense should be based on what the numbers establish and what they do not. The following is the core control map for an exchange, wallet provider, OTC desk, protocol treasury, or any team that can authorize a consequential crypto transfer.
| Evidence | What it suggests | Control that does not rely on “spotting AI” | Accountable owner |
|---|---|---|---|
| AI-vendor-linked scams averaged $3.2M per operation vs. $719K for other scams | Better targeting and presentation may increase the value extracted from each operation | Treat new payees, new wallet destinations, and credential changes as high-risk events, even when the request looks authentic | Payments / treasury |
| AI can create voices, video, fake websites, and tailored messages | A familiar face or voice is no longer sufficient authorization evidence | Require an out-of-band callback and a second signer for material transfers | Security and finance leadership |
| AI-generated IDs and deepfake selfies can weaken basic onboarding checks | Identity proofing is a process, not a document upload | Use liveness, document and device checks, plus manual review for conflicts | Compliance / identity operations |
| Scam centers run fake investment sites and launder proceeds through a network | Blocking one domain or wallet late will not dismantle the full funnel | Screen destinations, pause suspicious flows, preserve evidence, and report quickly | Fraud operations / legal |
This is not a promise that any vendor or workflow can identify every synthetic artifact. It is a design choice: the decision to release money should remain safe even when an attacker’s media is convincing.
A Scam Center Is an Operation, Not a Clever Prompt
The term “AI scam” can make this sound like a lone person with a chatbot. Recent enforcement activity describes a more sobering structure.
In April 2026, the U.S. Department of Justice said its Scam Center Strike Force had charged alleged managers of a Burma-based cryptocurrency investment-fraud compound, seized 503 fraudulent investment domains, and restrained more than $701 million in cryptocurrency allegedly tied to laundering scam proceeds. Investigators described a hierarchy of operators, fraudulent sites and apps, recruitment through online channels, and victims who were shown fabricated investment returns. The same announcement says some compound workers were trafficked and compelled by violence, which matters: “industrialized” should never erase the human coercion behind the operation. DOJ’s case summary is about alleged conduct and enforcement actions, not a template for assuming every scam has the same geography or organization.
The basic funnel is nevertheless recognizable:
- A contact is created through a text, social post, dating app, employment offer, or impersonated executive.
- Trust is built with a conversation, social proof, a forged identity, or an apparently legitimate trading interface.
- The target is induced to buy or transfer crypto, often through a familiar exchange or kiosk.
- The destination and subsequent hops move the proceeds into a laundering network.
AI chiefly improves the first two stages. It can translate a script, sustain more simultaneous conversations, generate plausible images and websites, or imitate a voice in a meeting. Crypto supplies the payment rail at stage three. Treating the deepfake as the whole attack misses the people, controls, platforms, and wallet flows that make the attack profitable.
Four Places AI Changes the Attack Surface
The best response separates the artifact from the action it is trying to induce.
1. Executive or signer impersonation
A call that appears to come from a founder, CFO, multisig signer, or vendor is a request to bypass normal payment controls. Elliptic’s expert consultation rated deepfake executive scams as a growing concern, with a 5.3/7 average impact score; it also identifies real-time voice and video impersonation as a risk to virtual-asset providers. Elliptic’s VASP guidance does not make that score a loss forecast, but it usefully directs attention to authorization.
For a treasury, the rule should be mechanical: a voice or video request cannot change the approval path. Use a pre-registered callback channel, transaction simulation where applicable, a human-readable destination allow-list, and a quorum that includes someone independent of the requester. A deepfake can imitate a person; it cannot satisfy a control that requires multiple, separately authenticated people and a previously approved destination.
2. Synthetic identities at onboarding and account recovery
Synthetic IDs matter because they can create mule accounts, open accounts used to receive stolen funds, or take over an existing account before a withdrawal. FINRA warns that fraudsters can use social-media images to create deepfake selfies intended to defeat selfie-based verification. Its guidance on GenAI fraud reinforces a practical point: document capture alone is not identity assurance.
Layered proofing should combine document authenticity signals, liveness and presentation-attack checks, device and behavioral signals, and velocity rules. Conflicts deserve human escalation: a fresh device, changed recovery details, a high-value withdrawal, and a new destination wallet are each ordinary events; together they are a different risk class. These controls create friction, so the right threshold is not “challenge everyone.” It is “challenge combinations that change who can move money.”
3. Personalized relationship scams and fake investment fronts
AI lowers the cost of writing persuasive, localized messages and making sites look populated and credible. That is especially relevant to relationship-investment fraud, where a criminal builds trust before directing a victim to a fake platform. Federal investigators reported 61,559 cryptocurrency-fraud complaints and $7.228 billion in reported losses in 2025; people aged 60 and over accounted for $2.764 billion of those reported losses. The FBI IC3 2025 report shows the scale of reporting, while also undercounting people who never report.
Customer-facing defenses should interrupt the payment moment rather than attempt to classify every social message. Ask whether a recipient is an investment platform, display a plain-language warning before a first transfer to a risky destination, and add a cooling period or live review for unusually large first-time transfers. The warning has to say what the scam actually looks like: a person met online, an unfamiliar platform that shows gains, and an urgent instruction to move crypto. Generic “beware of fraud” banners are too easy to ignore.
4. Destination wallets and laundering paths
The final wallet is not automatically illicit, and blockchain analytics is not a license to freeze funds indiscriminately. But an organization can assess exposure to known scam infrastructure, sanctions risk, unusual routing, or a customer’s sudden transfer pattern. When the threshold is met, the workflow should be defined in advance: pause where law and product terms allow, gather the facts, notify the customer through a trusted channel, escalate to legal and compliance, and preserve the relevant records for a report or a law-enforcement request.
That last step is where speed has visible value. By March 2026, DOJ said Operation Level Up had notified 8,935 suspected cryptocurrency-investment-fraud victims; 77% had not known they were being scammed, and the program estimated $562.7 million in prevented additional losses. Those figures are an agency program estimate, not a controlled trial of any one detection product. They do show why a late but well-routed intervention can still matter. DOJ’s release provides the program’s methodology context.
A Five-Step Operating Playbook
For teams building controls now, the sequence is more useful than an “AI fraud” purchase order.
- Make payment authority hard to impersonate. Define the dollar and asset thresholds that require quorum approval, a known callback route, and a destination allow-list. Test it when the request is urgent and comes from an executive’s usual channel.
- Score event combinations, not isolated signals. Combine new device, changed recovery data, fresh beneficiary wallet, unusual amount, and unusual time. Escalate the combination to a reviewer with authority to delay a transfer.
- Add friction exactly at irreversible moments. Show specific scam education, confirmation prompts, or a cooling period before a first high-risk crypto transfer. Do not bury the warning in account setup.
- Connect payment operations to chain intelligence and reporting. Define who can place a hold, what evidence they record, when they contact the customer, and when legal files the appropriate report. Rehearse this across fraud, support, compliance, and security.
- Run a deepfake tabletop every quarter. Simulate an executive asking for a new-wallet payment and a customer being shepherded to a fake investment site. Measure whether the control held, not whether someone guessed that the media was generated.
There are real limits. A determined attacker may recruit a legitimate account holder, compromise an existing device, or persuade a customer to override several warnings. A false positive can block a legitimate urgent payment. The right outcome is therefore not zero friction or a magical detection rate. It is a documented decision process whose risk, customer impact, and escalation time can be audited.
Measure Prevention Instead of Buying an “AI” Label
The useful operating metrics are boring—and that is their strength. Track the share of high-risk transfers that received an independent callback, time from alert to hold, escalation accuracy, confirmed fraud prevented, customer abandonment after challenges, and the rate at which customers reverse or contest a transfer. Segment those results by event combination rather than demographic stereotype.
Review them with product, fraud, compliance, and security together. If a liveness check catches presentations but account recoveries remain weak, the answer is not necessarily another model. It may be a tighter recovery workflow. If warnings are displayed but customers continue transferring to fake platforms, change the copy, timing, and review path. The goal is to make the criminal’s scalable front end collide with a payment process that remains deliberately unscalable.
AI did not create relationship fraud, money mules, or fake investment platforms. It can make each stage cheaper to produce and more tailored to a target. That is why the durable defense is not a contest to detect every synthetic image. It is a set of independent identity, authorization, payment, and response controls that still require real evidence before real money moves.



