The interesting part of an AI assistant in a crypto investigation is not that it can draw a graph faster. It is whether a person can later show why the graph led to a decision—before stolen funds reach a cash-out point, and after a regulator, prosecutor, or court asks how the conclusion was reached.
That is the line TRM Labs is trying to draw with Co-Case Agent, announced on March 25 and embedded in its TRM Forensics product. The company says the assistant can turn natural-language requests into tracing actions, audit an investigation graph, propose next steps, and record the interaction history. Those are meaningful workflow claims. They are not a claim that an agent can determine guilt, file a Suspicious Activity Report (SAR), or compel an exchange to freeze funds.
The distinction matters more as crypto-enabled fraud becomes faster and more industrialized. Here is what that boundary looks like in a representative case.
The answer in one case: accelerate the work, preserve the decision
Imagine a compliance analyst receives an alert after a customer sends USDC to an address connected to an impersonation scam. The alert is a lead, not a conclusion. A useful investigation assistant can reduce the mechanical time between that lead and a reviewed case file—but each handoff still has an owner and a constraint.
| Case step | What an assistant can accelerate | What the analyst must verify and decide | Evidence to retain | Dependency or failure condition |
|---|---|---|---|---|
| Triage | Summarize transfers, known labels, asset, chain, and timeline | Confirm the customer, transaction, and risk signal are in scope | Original alert, transaction hashes, data-source version | Labels can be incomplete or wrong; permissions may limit data access |
| Trace | Map forward and backward hops; flag bridges, swaps, and possible service endpoints | Check transaction logic, clustering assumptions, and whether paths actually connect | Reproducible graph, transaction IDs, attribution citations | False positives and cross-chain heuristics need human review |
| Graph review | Surface gaps, unusual patterns, or a possible next query | Accept, reject, or narrow the suggested path | Version history, rejected suggestions, analyst notes | A fluent explanation is not evidence; changing labels may alter the picture |
| Preservation request | Identify a likely custodial exit point and prepare a request package | Decide whether legal and policy thresholds are met; send the request through authorized channels | Request, legal basis, timestamps, contact record | The exchange may not hold funds, respond in time, or sit in another jurisdiction |
| SAR or case escalation | Organize chronology and supporting facts | Write and approve the narrative; characterize the activity; make the filing decision | Final narrative, reviewed exhibits, approvals | AI cannot supply missing facts, establish intent, or substitute for a legal duty |
This is the core value proposition—and its ceiling. Faster tracing can give an analyst more time to assess a lead, preserve evidence, and contact a service provider. It cannot turn an uncertain attribution into a fact, bypass an organization’s approval rules, or make a cross-border preservation request effective.
TRM’s product description is unusually explicit on that point. It says the investigator retains control of actions and final judgment, while prompts, graph changes, and suggestions are captured in an exportable audit log. That is a better framing than “autonomous investigator.” In regulated work, an audit trail of what the model suggested, what data supported it, and what the analyst rejected may be more valuable than a fast but opaque answer.
What TRM actually shipped
Co-Case Agent is an AI investigation assistant inside TRM Forensics, not a separate general-purpose chatbot. According to TRM, it is available to existing Forensics customers across crypto businesses, financial institutions, law enforcement, regulatory agencies, and national-security agencies at no additional cost.
The announced functions are specific:
- Trace funds forward, backward, and across multiple hops from a natural-language request.
- Run graph reviews intended to catch tracing errors and improve investigation layout.
- Surface patterns and suggested next steps.
- Identify possible custodial exit points where account records or other evidence may exist.
- Keep a record of prompts, graph changes, and suggestions for later export.
Those functions occupy the labor-intensive middle of a blockchain investigation. Traditional graph tools require an analyst to select entities, follow transfers, inspect bridges or swaps, and document why a path matters. Co-Case Agent proposes to compress some of that navigation and documentation into a conversational workflow.
The launch announcement should still be read as a vendor description, not independent proof that case durations, recovery rates, or filing quality have improved. TRM has not published a controlled outcome study for Co-Case Agent. “Trace in seconds” describes a product capability, not the time required to validate a case or receive a response from an outside institution.
Why faster triage matters in an AI-enabled fraud environment
There is a real scale problem behind the product. Chainalysis estimates that crypto scams and fraud stole $17 billion in 2025, with AI-enabled scams 4.5 times more profitable per operation than traditional scams in its analysis. It also reported a 1,400% year-over-year increase in impersonation-scam revenue, although estimates can rise as more scam wallets are identified.
TRM reports a broader $158 billion estimate for illicit crypto volume in 2025 and says AI-enabled scam activity rose roughly 500% year over year. Its methodology describes that figure as a conservative floor based on attributed illicit addresses and crypto-native thefts, not a measurement of all criminal activity touching crypto. That caveat is important: attribution improves over time, and different analysts can legitimately report different totals because they measure different populations.
The operational takeaway is less controversial than a headline number. Scam proceeds can be divided, swapped, bridged, and sent toward cash-out services quickly. A team that spends hours manually constructing an initial graph has less time to decide whether it has sufficient grounds for outreach, escalation, or a report.
But speed is only one link in the response chain. The worked example above has at least five separate clocks: data availability, analyst review, internal approvals, the custodian’s response, and the relevant jurisdiction’s process. An AI assistant can shorten the first two. It does not own the other three. Any claim that “AI solves crypto crime” erases the legal and organizational steps that determine whether an actionable lead becomes a disrupted transaction.
Defensibility is the product constraint
For an investigation team, useful automation has to be reviewable at the level of a claim. A graph should identify the on-chain transaction, the data source behind a label, the inference used to connect the next hop, and the person who accepted or rejected that inference. A concise natural-language summary is helpful only if it can be traced back to those elements.
That standard is especially visible in suspicious-activity reporting. FinCEN’s guidance says a SAR narrative must accurately explain the nature and circumstances of suspicious activity; a narrative that merely repeats form fields does not explain why the behavior is suspicious. Its practical “who, what, when, where, why, and how” test cannot be satisfied by a polished model response that lacks source evidence or omits exculpatory context.
An auditable assistant can help in four concrete ways:
- Preserve the original prompt and the exact graph state the analyst saw.
- Tie each suggested action to transaction data and attribution evidence.
- Record analyst edits, rejections, and additions rather than silently overwriting the case.
- Make it possible to recreate the chronology after a label changes or new facts emerge.
It also needs operational guardrails. Organizations should define which roles can ask the agent to modify a graph, require a human review before external outreach or filing, retain source-data versions, and test how the system behaves when labels conflict or a path is only weakly supported. The risk is not merely hallucinated prose. A misplaced confidence cue can cause an analyst to stop checking a transaction path that is incomplete, falsely clustered, or outside the team’s legal authority.
A category shift, not a solved case
TRM is not alone in bringing AI to blockchain intelligence, but the products make different claims. Chainalysis has announced blockchain-intelligence agents and positions its investigation stack around plain-language triage followed by deeper graph analysis in Reactor. Elliptic’s AI API offers natural-language summaries, risk analysis, and forward/backward risk-graph traversal for compliance teams. These are comparable in direction—using AI to make complex blockchain data easier to investigate—not interchangeable evidence engines with identical coverage or controls.
The larger shift is from AI as a dashboard summarizer to AI as a participant in the case-preparation workflow. Co-Case Agent’s combination of tracing, graph review, next-step suggestions, and an audit log is an example of that change. Its success should be judged on whether analysts can correct it, reproduce it, and defend the result—not on how convincingly it narrates a graph.
Does this tilt the AI offense-versus-defense balance toward investigators? It can improve defensive throughput: more leads can be triaged and documented without asking every analyst to perform every repetitive graph operation by hand. Yet the acceleration is symmetrical. The same generative tools help fraud networks translate messages, impersonate victims’ trusted contacts, and operate campaigns at scale. Defense remains constrained by evidence quality, legal authority, exchange responsiveness, and cross-border coordination—constraints an attacker does not face in the same way.
That makes the near-term promise narrower and more useful. AI can give a trained investigator a faster, reviewable starting point. It cannot replace the investigator’s judgment or turn a suggested transaction path into an autonomous verdict.



