TL;DR
Chainalysis reports impersonation scams grew over 1,400% in 2025, with AI-linked operations generating 4.5x the revenue at 9x the activity of non-AI operations. Deepfake KYC bypasses now cost about $20 and 30 minutes, defeating standard liveness checks 58% of the time. Crypto accounts for 88% of all detected deepfake fraud globally. Enforcement has responded with $4.4B in frozen Tether and nearly 5,800 arrests across 97 countries, but none of that stops a forged identity clearing a check.
Impersonation scams grew more than 1,400% year over year in 2025, according to Chainalysis, with the average payment into those clusters rising more than 600%. Across all scam categories the average crypto payment climbed from $782 to $2,764.
An attack class does not scale like that because more people are running it. It scales because fewer people are running it with better tools.
Fraud Used to Have a Headcount Problem
An investment scam or a romance approach had to be staffed. Someone trained had to hold the conversation, in the victim’s language and across weeks. Those requirements set a ceiling on how many people a network could work at once, and for years the ceiling held.
Generative tooling removed it without changing the underlying deception. The con is the same one the industry has seen since the first fake exchange support agent. What changed is that the expensive part of running it stopped being expensive.
The economics are visible on-chain. Chainalysis found that operations with observable links to AI tooling vendors extracted an average of $3.2 million against $719,000 for those without, while generating 35.1 transfers a day against 3.89. That works out to roughly 4.5 times the revenue on about nine times the activity: the same operation reaching more people and converting more of them. TRM Labs separately observed close to a 500% increase in AI-enabled scam activity over the past year.

“Code is no longer necessarily the weakest link in Web3,” says Jimmy Su, Chief Security Officer at Binance. “As smart contract security improves, attackers are shifting their attention to the people, credentials and governance systems surrounding protocols. We saw this firsthand when Binance Security helped prevent a $1.2 million governance attack on BrainTrust. Protecting a protocol today means securing not just its code, but also who can control it, how that control is exercised, and the infrastructure and people behind it.”
The Verification Stack Was Built for a Different Attack
Identity checks were designed against a threat model of printed photographs, recorded video and low-grade physical spoofs. That is why liveness prompts still ask a user to blink or turn their head. The threat model moved and the prompt did not.
Vendor research from Socure puts the current cost of defeating that stack at roughly $20 and about 30 minutes, and finds that injection attacks, which feed a synthetic video stream straight to the verification interface rather than through a camera, defeat standard liveness checks about 58% of the time. Socure and Zyphe, whose figures it cites, both sell detection products in this category.






