Criminal Use of AI Surges 40% in 2026, Crypto Scams Lead Adoption
Blockchain intelligence firm TRM Labs reports criminals now deploy AI across every stage of scams, hacks, and ransomware operations.
Criminal AI Adoption Reaches New Peak
Criminals are integrating artificial intelligence into their operations at an accelerating pace, with adoption climbing 40% year-over-year in 2026, according to blockchain intelligence firm TRM Labs. The firm's newly released AI-in-Crime Adoption Index scored overall criminal AI use at 54 out of 100, nearly double the 28 recorded in 2024.
Scams have reached what TRM classifies as "Mature" adoption—the only crime category to achieve that designation. The data, first reported by BeInCrypto, reveals that AI now handles everything from generating victim target lists to conducting the conversations that extract money from marks.
Why it matters
The industrialization of cybercrime through AI fundamentally changes the risk calculus for businesses holding digital assets. When criminals can automate reconnaissance, social engineering, and execution at scale for as little as $400, traditional security perimeters built around human attackers become inadequate. Organizations need to match the pace of offensive AI tooling or face asymmetric exposure.
Scams Achieve Full Automation
TRM's index evaluates four crime types based on prevalence, operational integration, and technical sophistication. Scams dominate across all three dimensions. The share of scam reports involving AI has multiplied roughly 13-fold since 2022. Among active crypto scam domains, 17% now advertise AI-powered products as part of their lure.
Deepfake scams show particularly explosive growth. Reported losses from deepfake-enabled fraud in 2026 already exceed the entire 2025 total by 263%. The technology allows criminals to impersonate executives, family members, or trusted figures with sufficient fidelity to bypass human skepticism.
North Korea Dominates State-Sponsored Theft
Hacking and state-sponsored operations rank one tier below scams at "Emerging" maturity, but the financial impact tells a different story. TRM logged 201 hacks in the first half of 2026 compared to 83 in the same period of 2025. However, just 4% of those incidents accounted for 75% of stolen value.
North Korea alone extracted approximately $600 million—61% of the half-year total. Two April breaches drove that figure: a $285 million theft from Drift Protocol and a $292 million exploit of KelpDAO. Both attacks began with social engineering rather than sophisticated code exploits, demonstrating that human vulnerabilities remain the primary attack vector even as AI tools proliferate.
Ransomware Goes No-Code
Ransomware sits further along the maturity curve. No-code ransomware kits now sell for $400 to $1,200 on criminal markets, dramatically lowering barriers to entry. In July, security firm Sysdig documented JadePuffer, which it identified as the first fully autonomous ransomware. The AI agent independently handled reconnaissance, credential theft, lateral movement through networks, and encryption—all without human intervention.
TRM's broader assessment concludes that AI now touches every phase of the criminal lifecycle, from planning through execution to laundering proceeds. The firm warns that maintaining current parity between offensive and defensive capabilities depends on enforcement and compliance tools scaling at the same rate as criminal adoption.
The data was compiled by TRM Labs and reported by Kamina Bashir at BeInCrypto.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
