Loading article…
Crypto scams stole at least $14 billion in 2025, a surge driven by AI-powered phishing and social engineering. Learn the red flags and risks to watch.
Criminals stole at least USD 14 billion through cryptocurrency fraud in 2025, a figure that could climb to USD 17 billion as investigators identify more illicit addresses [1]. This surge in theft coincides with a shift toward sophisticated social engineering and AI-enhanced tactics that have significantly increased the profitability of illicit schemes [1].
| At a glance | |
|---|---|
| 2025 Scam Losses | At least USD 14 billion [1] |
| Potential Total | Up to USD 17 billion [1] |
| AI Scam Profitability | 4.5x higher than traditional schemes [1] |
| FBI Fraud Reports | Up nearly 50% in 2025 [2] |
The scale of crypto-related crime has expanded as bad actors leverage AI to create deepfake videos and cloned voices, making impersonation scams 1,400% more frequent in 2025 compared to the previous year [1]. These tools allow scammers to build trust over weeks before introducing fake investment opportunities, often masquerading as legitimate exchange representatives or support agents [1]. In one notable case, a network of young hackers used social engineering to steal over USD 240 million in bitcoin from a single investor, demonstrating the extreme financial impact of these targeted attacks [2].
Beyond impersonation, technical exploits remain a primary vector for theft. Web3 security losses reached USD 1.31 billion across 344 incidents in the first half of 2026, with wallet takeovers alone accounting for more than USD 444 million [1]. Attackers are increasingly using "approval phishing," where users are tricked into signing permissions that grant criminals access to drain tokens from their wallets [1]. Malware frameworks like Okobot have further exacerbated the threat, harvesting credentials and seed phrases across more than 25 countries [1].
The surge in fraud reports to the FBI comes as the U.S. regulatory environment for digital assets has shifted [2]. While the Justice Department recently disbanded a unit specifically dedicated to prosecuting crypto-related crimes, law enforcement continues to pursue individual high-profile cases, such as the arrest of 22-year-old Malone Lam for his role in a massive bitcoin theft [2]. Despite the crackdown on specific criminal networks, cybersecurity experts warn that the lack of ramped-up resources to combat these underground hacker subcultures may lead to further proliferation of these scams [2].
As scammers continue to refine their methods, the burden of security has shifted heavily toward the individual investor. The ability to distinguish between legitimate opportunities and AI-backed fraud remains the primary defense against the billions of dollars in assets currently at risk.
Coverage is mostly measured — 216 of 218 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Sep 8, 2026 · How we report
As of 14 September 2026, the Peru Ministry of Economy and Finance reported that its official X account was compromised by attackers who used the platform to promote a fraudulent token called $HYLO. The ministry confirmed the posts were unauthorized and stated that no financial losses were reported in connection with the incident.
The Revolut data disclosure, reported in September 2026, involved the release of customer full names, birth dates, occupations, postal addresses, email addresses, and telephone numbers. Additionally, the impersonator obtained copies of passports or driving licenses, verification selfies, IBANs, and complete Bitcoin transaction histories.
MetaMask utilizes AI-powered security partners like Blockaid to analyze websites, social feeds, and on-chain bytecode to identify phishing and malicious behavior in real time. The wallet also employs Added Protection, a feature that automatically reverts transactions that do not match their previews, and provides warnings for lookalike addresses and first-time recipients.
Scammers exploit government accounts because these platforms command high levels of public trust, which can be used to legitimize fraudulent schemes. By posting on official channels, perpetrators can more effectively use urgency—such as fake token launch dates—to bypass the critical thinking of potential victims.