Three dark server towers with glowing orange
AI

TRM Labs says AI adoption in crypto crime rose 40% over the past year

The 2026-08-21 disclosure offers a directional security signal, but no methodology or category breakdown.

By Elliot Marsh4 min read

TRM Labs says AI adoption in crypto-related crime increased 40% year-over-year in the 12 months leading up to 2026-08-21. The figure points to faster-scaling scam and fraud operations, but the packet includes no definitions or measurement details to size the risk.

TRM Labs Flags a 40% Jump in AI Use Across Crypto Crime

TRM Labs, a blockchain intelligence firm that tracks illicit activity involving crypto, said AI adoption in crypto crime rose 40% over the past year. The claim was published on 2026-08-21 and is framed as a year-over-year change rather than an absolute count.

Mechanically, “AI adoption” in this context means criminals using AI tools to create, automate, or improve illicit operations that touch crypto rails, whether that is social engineering, fraud workflows, or other abuse patterns. A 40% increase is not a loss figure on its own. It is a throughput claim, implying that the same set of bad actors can run more attempts per unit time, iterate faster, and target more venues.

The catch is that the packet excerpt stops at the headline-level number. It does not include TRM’s definitions for what qualifies as “AI adoption” or “crypto crime,” the dataset used, the baseline for the year-over-year comparison, or any examples that would let traders map the increase to specific chains, venues, or attack types.

What the 40% Figure Signals for Venue and Counterparty Risk—And What’s Still Unverified

For traders, the most direct read-through is operational risk, not macro. If criminals are getting a tooling upgrade, the first-order impact tends to be more convincing inbound lures, more automated account takeover attempts, and higher-volume fraud against exchange users, OTC desks, and protocol front ends. That can translate into more frequent withdrawal freezes, longer support queues, stricter deposit and withdrawal heuristics, and higher false positives in compliance controls, especially during volatility when venues are already load-tested.

On the counterparty side, faster-scaling fraud can also change how quickly “clean” liquidity becomes “tainted” liquidity. If scam proceeds move through more hops and more addresses with better automation, counterparties that rely on basic screening can end up taking more operational risk than their policies assume, even if their onchain exposure looks unchanged.

What remains unverified is the shape of the increase. Without a breakdown, it is unclear whether the 40% is driven by scams versus laundering, whether it is concentrated on centralized exchanges versus DeFi venues, or whether it is mostly about content generation and impersonation rather than onchain automation. The excerpt also provides no way to tell whether TRM is counting unique incidents, observed tool usage, or some other proxy that could move materially based on detection improvements rather than attacker behavior.

The next leg of this story depends on whether TRM publishes the primitives behind the number: definitions for “AI adoption” and “crypto crime,” the measurement approach, and the baseline period used to compute the year-over-year change. Traders should also look for follow-up data that splits the increase by crime type and venue, because “more AI” means very different things if it is mostly phishing copy versus automated laundering pipelines.

A second confirmation path is whether exchanges and major protocols start explicitly citing AI-driven social engineering or automated fraud as the driver for new controls, such as tighter withdrawal policies, new device and session checks, or more aggressive address screening. Independent datasets that corroborate or contradict the magnitude of the year-over-year increase would also determine whether this is a broad regime shift or a single-firm measurement artifact.

My Read: Treat It as a Risk-Management Headline Until TRM Publishes the Breakdown

The threshold that matters here is whether the 40% figure survives contact with definitions. If “AI adoption” is measured tightly, the number is an early warning that scam and fraud operations are scaling faster than most venue controls were designed for.

Until TRM publishes the methodology and a category breakdown, I treat this as a risk-management headline, not a quantified forecast of losses by chain or venue. It matters in practical terms only if the underlying data ties the increase to specific, repeatable attack paths that force exchanges and protocols to change how users deposit, withdraw, and authenticate.

Sources