AI-powered crypto scams surge: $17b lost, defenses scramble

The gist
AI-powered cybercrime has hijacked the cryptocurrency world, fueling $17 billion in losses by mid-2026 as deepfakes, synthetic identities, and autonomous attacks outpace traditional defenses.
What to know
- By mid-2026, AI-driven crypto scams and deepfake fraud have cost the sector $17 billion, exploiting fragmented defenses and cross-chain laundering.
- Tech giants like Microsoft, Cisco, and Fortinet are racing to build AI-native security, with platforms adopting advanced defenses saving an average of $1.9 million.
- Despite rapid AI adoption in cybersecurity, only 27% of organizations have mature AI defense, leaving critical gaps as attack timelines shrink from days to hours.
AI Becomes the Attacker
AI now autonomously orchestrates large-scale cyber intrusions and exploits vulnerabilities within hours, erasing the technical barriers that once limited sophisticated attacks.
By mid-2026, AI has transcended its initial role as a mere assistant in cyberattacks to become the autonomous operator of complex intrusion workflows, executing thousands of commands across multiple sessions with minimal human oversight. Check Point Research documented cases where AI systems like Claude Code and GPT-4.1 orchestrated breaches exposing hundreds of millions of records, highlighting a fundamental shift in attacker capabilities. This evolution compresses attack timelines dramatically, with AI turning fresh vulnerability disclosures into working exploits within hours, forcing regulatory bodies to mandate remediation windows as short as 12 hours for critical systems.
The rise of AI as an active cyberattack operator has lowered the technical barrier to entry, enabling individuals without deep expertise to conduct sophisticated attacks at machine speed and scale. As Lotem Finkelstein from Check Point notes, 'The expertise barrier that separated capable attackers from the rest is disappearing,' with AI effectively serving as an autonomous engineering team that rebuilds attacker infrastructure and maintains operational continuity. This democratization of cyber offense expands the threat landscape beyond traditional organized groups to include AI-augmented individuals capable of rapid, adaptive operations.
AI itself has become a novel attack surface, with a fivefold surge in detections of malicious prompt-injection payloads between March and May 2026 signaling that indirect prompt injection is now a routine operational risk. Attackers exploit AI trust in configuration files to create persistent compromises, while campaigns like Bissa Scanner have stolen and resold AI service credentials—known as LLMjacking—to mask malicious activity under legitimate usage. This dual threat of AI-powered offense and AI-targeted exploitation complicates defense strategies, necessitating enhanced governance and detection tailored to AI-specific vulnerabilities.
The integration of AI into every phase of cyberattacks—from reconnaissance and vulnerability exploitation to autonomous ransomware operations—has accelerated attack lifecycles from days to mere hours. Reports from Unit 42 and Sysdig reveal AI-driven ransomware agents capable of independent credential harvesting and adaptive attack strategies, outpacing defenders whose detection and patching cycles lag behind attacker development. Consequently, cybersecurity professionals must pivot from reactive to proactive defense models, incorporating AI-native detection methods and operational processes designed around rapid, AI-accelerated threat dynamics.
Crypto’s Defenses Fracture
Fragmented security and rapid AI evolution are fueling a wave of cross-chain crypto scams, turning even amateurs into formidable financial criminals.
By mid-2026, AI-powered fraud and deepfake scams have inflicted staggering financial damage on the cryptocurrency sector, with losses reaching $17 billion, underscoring the urgent need for robust defenses. Varun Choudhary of ORO advocates for programmable smart accounts, dual approvals, and rigorous controls as critical tools to counter these sophisticated AI-driven attacks that exploit the sector’s unique vulnerabilities.
The cryptocurrency market’s fragmented defense landscape—where cybersecurity, fraud prevention, AML, and AI risk teams operate in silos—creates exploitable gaps that enable complex, multi-stage scams involving cross-chain laundering and synthetic identities. This fragmentation, combined with AI’s ability to lower barriers to entry and enable near real-time adaptation of fraud techniques, transforms even amateur attackers into sophisticated operators, escalating both the scale and complexity of crypto-related fraud.
The broader financial ecosystem’s expanding digital payment attack surface, exemplified by card-not-present fraud accounting for 71% of US card fraud losses, amplifies risks for crypto platforms as transactions increasingly occur in unverifiable digital channels. This shift highlights the critical necessity for enhanced controls and programmable smart accounts in cryptocurrency, aiming to unify fragmented defenses and close gaps between traditional financial crime, cybersecurity, and fraud prevention functions to combat the rapidly evolving AI-driven threat landscape.
Tech Giants Lead AI Security Race
Microsoft, Cisco, and Fortinet are redefining defense with adaptive AI-native platforms, saving millions as the battle escalates between AI attackers and defenders.
Major technology and cybersecurity firms such as Microsoft, Fortinet, and Cisco are spearheading the development of AI-native security platforms to counter the surge in sophisticated AI-driven cyber threats, particularly those targeting the cryptocurrency sector which has suffered losses exceeding $17 billion from AI-powered fraud and deepfakes. These companies are not only innovating defensive tools but also demonstrating the financial benefits of AI integration, with crypto platforms employing advanced AI security measures saving an average of $1.9 million compared to those without such protections.
The cybersecurity landscape is entrenched in an 'AI vs. AI arms race,' where approximately 73% of global organizations have already embedded AI into their defenses, and nearly all intend to increase investment through 2025. This rapid adoption is driven by the need to protect AI infrastructure and digital assets from adversarial machine learning and data poisoning attacks, a challenge underscored by government mandates such as the June 2026 directive from CISA requiring US agencies to bolster defenses against AI-enabled hacking threats.
Security firms like Cisco are pioneering adaptive incident response frameworks to address the dynamic nature of AI-driven attacks, with experts such as Reza Maleksadeh emphasizing innovations like Network Admission Control that evolve alongside emerging threats. Meanwhile, startups like Kevla are harnessing AI not only for detection but to enhance operational response capabilities, tackling the critical issue of alert fatigue by enabling security teams to efficiently investigate and respond to incidents in real time.
Despite widespread AI adoption in cybersecurity, maturity levels remain low, with only 27% of organizations reporting mature AI implementations, which limits the effectiveness of defenses against increasingly sophisticated AI-powered attacks. This gap necessitates stronger governance, faster vulnerability remediation, and enhanced human oversight, as nearly two-thirds of respondents highlight significant shortcomings in threat detection and response. The accelerating pace of AI-driven exploits demands a paradigm shift from traditional patching cycles to near real-time vulnerability management to keep pace with adversaries.
Adaptive Defense Is Survival
Only organizations that unify rapid detection, automation, and skilled human oversight can withstand AI-driven threats that outpace traditional cybersecurity models.
By early 2026, cybersecurity defense strategies have pivoted from traditional prevention to an adaptive model emphasizing rapid detection, validation, and response to keep pace with AI-accelerated threats. As attackers leverage AI to automate and compress operational timelines—exemplified by a Russian threat actor using Google’s Gemini AI to rebuild command-and-control infrastructure in minutes—security teams across identity, infrastructure, and endpoint domains must adopt unified, adaptive incident response frameworks that break down organizational silos and enable coordinated defense.
Effective AI-native defense hinges on integrating triage, automation, and human-in-the-loop decision-making to counter the speed and complexity of AI-powered attacks. Security leaders like Jason Kikta, CTO of Automox, emphasize that attackers’ ability to pivot techniques in near real-time demands incident response mechanisms that are equally agile, supported by zero trust, least privilege, and data classification frameworks to mitigate AI-enabled social engineering and reconnaissance at scale.
Beyond advanced tooling, the resilience of AI-powered defenses depends critically on proper staffing, tuning, and continuous upskilling to build a security culture capable of managing overwhelming alert volumes and complex attack surfaces. Innovations like Kevla—developed by Ahmed Ashak and Hamsa Sayyah—demonstrate how AI can shift cybersecurity from mere detection to adaptive incident response, addressing operational bottlenecks and enabling security teams to respond effectively in a landscape where AI plays dual roles offensively and defensively.
To combat the multifaceted nature of AI-enabled fraud, especially in financial services and cryptocurrency sectors, organizations must implement unified command structures that integrate defenses across cybersecurity, fraud, AML, and AI risk teams. This holistic approach counters attackers who exploit fragmented defenses by treating endpoint management, transaction monitoring, and synthetic media detection as a single attack surface, requiring seamless coordination and AI-powered adaptive response to close exploitable gaps.


