Home › Knowledge Hub › AI crypto scams
AI crypto scams: deepfakes, voice clones and fake support
Artificial intelligence has not invented new crypto scams. It has made existing ones cheaper to run, faster to personalise and harder to spot by instinct. The FBI's 2025 Internet Crime Report logged 22,364 complaints with an AI element and nearly $893 million in losses, the first time in the centre's 25-year history the report carried a dedicated AI section. The defence has not changed: verify through a channel other than the one the request arrived on.
Who this is for
You have seen a video, heard a voice message, or received something that felt convincing and now feels wrong. Or you want to know what to trust before that happens.
This page avoids both the reassurance that AI changes nothing and the panic that it changes everything.
What the data says
The FBI's 2025 Internet Crime Report recorded 22,364 complaints with an artificial intelligence element, and nearly $893 million in losses. It was the first year in the IC3's nearly 25-year history that the report included a dedicated section on AI. The report describes scammers deploying fake social profiles, voice clones, identification documents, and believable videos depicting public figures or loved ones.
For context on the wider picture in the same report: cryptocurrency complaints reported the highest losses of any category, 181,565 complaints totalling more than $11 billion. Cryptocurrency investment fraud, commonly called pig butchering, accounted for $7.228 billion across 61,559 complaints, a 48% increase in complaint volume from 2024.
One caveat worth carrying through this whole article. The AI figure reflects only what victims reported and recognised as involving AI. Someone deceived by a synthetic voice they believed was real has no reason to report it that way. The true figure is unknowable and higher.
What AI changed
Three things, and none of them is a new category of scam.
Volume. Personalised phishing used to cost the attacker time. Writing a convincing message in fluent English, referencing a recipient's employer and role, once took effort that limited how many targets were worth pursuing. That constraint has gone.
Quality. The traditional advice to look for spelling errors and awkward phrasing is now close to useless. Bad grammar was never the tell; it was a side effect of who was writing. Well-written no longer means legitimate.
Believability of identity. A voice that sounds like someone you know, or a video of a public figure making a recommendation, defeats the instinct most people rely on. That instinct was doing real work, and it has been devalued.
What has not changed is the structure. AI-enabled scams still end with a request to send cryptocurrency, approve a transaction, share a recovery phrase, or install something. The ask is the constant. Everything before it is presentation.
Voice cloning
Short samples of recorded speech are now enough to produce convincing synthetic audio. Sources are ordinary: social media videos, voicemail greetings, podcast appearances, conference recordings.
In May 2025 the FBI warned that malicious actors were impersonating senior US officials using AI-generated voice messages, and advised recipients not to assume authenticity based on how the message sounded.
Common forms in a crypto context: a voice message from a family member describing an emergency and asking for a transfer; a call from someone presenting as exchange security; a message from a colleague approving an unusual payment.
Why it works. Recognising a voice is automatic and feels like knowledge rather than inference. When the voice matches, most people stop evaluating.
The defence is boring and effective. Hang up and call back on a number you already have. Not the number that called, not one provided in the message. If the request is real, the person answers and confirms it. If it is not, the call reveals that in seconds.
Agreeing a spoken code word with family for unusual financial requests costs nothing and defeats voice cloning outright. It feels excessive until the day it does not.
Deepfake video
Video of public figures endorsing investment platforms is now routine, and the production quality varies from obvious to convincing.
Common forms: a livestream replaying old footage with a wallet address overlaid; a well-known figure appearing to announce a giveaway; a fabricated interview; a video call where the other party is synthetic.
Signals that sometimes help: unnatural blinking, mismatched lip movement, lighting that does not match the background, audio that is too clean or too flat, and hands or accessories that distort during movement.
Do not rely on any of those. They are getting less reliable with each model release, and a person under time pressure will not be examining blink rates. Treat visual inspection as a weak secondary check, never as verification.
The reliable test is structural, not visual. No genuine investment opportunity requires you to send cryptocurrency to an address shown on a video. No legitimate giveaway asks you to send funds first. Those rules hold regardless of who appears to be speaking.
AI-written phishing
Messages are now fluent, contextually accurate, and personalised at scale. An attacker can reference your employer, your recent activity, your city, and the specific platform you use.
What to check instead of the writing quality:
- Did they contact you first? Unsolicited contact about your wallet or funds is the single most consistent signal, and AI does nothing to change it.
- What is the actual ask? Follow it to the end. Sending crypto, approving a transaction, entering a phrase, installing software, granting remote access. The wrapper varies; the ask does not.
- Does the domain match exactly? Character by character. Look-alike domains are cheap and AI does not make them harder to check.
- Is there urgency? Manufactured time pressure exists to prevent verification. Nothing legitimate collapses because you took ten minutes.
Fake support agents
The most common AI-assisted attack aimed at individual crypto holders, and the least discussed.
You post publicly about a wallet or exchange problem. Within minutes, accounts respond that appear to be official support, using correct terminology, appropriate branding and a plausible tone. AI makes producing that convincingly trivial.
Then comes the ask: your recovery phrase for "verification", remote access to "diagnose", a small transaction to "confirm ownership", or your credentials.
Real support never needs any of those. No exception exists.
A habit that removes the entire category: never discuss an account problem in a private message initiated by someone who approached you. Open a ticket through the company's own website, reached by typing the address.
The verification habit
One rule covers voice clones, deepfakes, AI phishing and fake support alike.
Verify through a different channel than the one the request arrived on.
A voice message asking for a transfer is confirmed by calling the person back on a number you already had. An email from your exchange is confirmed by logging in yourself, typing the address. A video recommendation is confirmed by checking the project's official channels. A support agent is confirmed by opening your own ticket.
The reason this works is that an attacker controls one channel. Controlling two, simultaneously, for the same target, is a different order of difficulty.
"It sounded exactly like them" is not evidence. That is precisely the capability being sold.
Where this is heading
The newer category is AI that acts rather than persuades. In 2026 people began losing funds to AI agents connected to wallets, where the theft happened without a key being stolen at all.
What not to worry about
Proportion matters, and hype in this area is doing its own damage.
AI is not breaking cryptography. Your wallet is not at risk from a model guessing your private key.
AI is not autonomously hunting individual wallets. The reality is industrialised social engineering, not autonomous agents.
Most crypto theft still involves no AI at all. Approval phishing, fake platforms, seed phrase exposure and ordinary impersonation remain the bulk of it. AI makes the persuasion better. The mechanics underneath are the same ones our wallet drainer guide and impersonation guide describe.
Being frightened of the wrong thing leaves you unprotected against the likely thing.
Red flags
- Unsolicited contact about your wallet, funds or an investment
- A voice message asking for a transfer, however familiar the voice
- A video endorsing a platform where you send crypto to an address
- Support responding to your public post with a private message
- Any request for a recovery phrase, remote access or a verification payment
- Urgency attached to a financial decision
- A request you cannot verify through an independent channel
What not to do
- Do not judge legitimacy by writing quality
- Do not act on a voice message without calling back independently
- Do not trust a verified badge as evidence of anything
- Do not continue a support conversation in a DM you did not start
- Do not send crypto to an address shown in a video
- Do not rely on spotting visual artefacts in a deepfake
Checklist: before acting on any request involving money
- [ ] Did they contact me first?
- [ ] Have I verified through a different channel?
- [ ] Am I being rushed?
- [ ] Does the ask involve sending crypto, approving a transaction, or sharing a phrase?
- [ ] Did I reach this site by typing the address?
- [ ] Have I told one other person what I am about to do?
That last one defeats more scams than any technical control. Describing it aloud to someone outside the situation is often the moment it becomes visible.
What this guide cannot do
Detection advice ages quickly here. The artefacts that reveal synthetic media today may not exist in six months, which is why this article leans on structural verification rather than visual tells. Nothing here guarantees you will not be deceived, and no honest guide would claim otherwise.
This is general information, not legal, tax or financial advice.
If you have already sent funds
Stop paying, whatever justification follows. Preserve the messages, the video, the profile and the transaction details before anything disappears. Our evidence checklist covers what matters and the country guides explain where to report.
Expect a second approach. People who lose money to AI-assisted fraud are targeted again, often by someone offering recovery. Read how to spot a crypto recovery scam before replying.
Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.
Sources
FBI, Cryptocurrency and AI Scams Bilk Americans of Billions, April 2026. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
FBI Internet Crime Complaint Center, 2025 Internet Crime Report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
CNBC, FBI warns of AI voice messages impersonating US officials, May 2025. https://www.cnbc.com/2025/05/15/fbi-ai-us-officials-deepfake.html
The IC3 AI figure reflects complaints where a victim identified and reported an AI element. It is a floor, not a total.
Frequently asked questions
How can I tell if a video is a deepfake?
Visual signals such as unnatural blinking, mismatched lip movement or distorted hands sometimes help, and they are becoming less reliable with each model release. Do not rely on them. Verify structurally instead: no genuine opportunity requires sending cryptocurrency to an address shown in a video.
Someone called with my family member's voice asking for money. What should I do?
Hang up and call them back on a number you already have. Do not call the number that rang you. Voice cloning needs only a short sample of recorded speech, and a matching voice is not evidence. Agreeing a spoken code word with family for unusual requests defeats this entirely.
Does AI mean crypto scams are unstoppable now?
No. AI has made persuasion cheaper and better, not the underlying mechanics different. Every scam still ends with a request to send crypto, approve a transaction, or share a phrase. Verifying through an independent channel works regardless of how convincing the approach was.
Are AI-written scam emails detectable?
Not by writing quality. Spelling errors and awkward phrasing were never the actual tell; they were a side effect of who was writing. Check whether they contacted you first, what the ask is, whether the domain matches exactly, and whether you are being rushed.
Can AI break my wallet's encryption?
No. That is not what any of this is about. AI-enabled fraud is social engineering at scale, aimed at persuading you to authorise something. The cryptography is not the target, and treating it as the threat distracts from the real one.
How much crypto fraud involves AI?
The FBI logged 22,364 AI-related complaints in 2025 with nearly $893 million in losses, against more than $11 billion in total cryptocurrency losses. But the AI figure only counts cases where a victim recognised and reported an AI element, so it is a floor rather than a total.
Is a verified account on social media trustworthy?
No. Verified accounts are compromised regularly, and on some platforms verification can be bought. Treat a badge as no evidence at all where money or credentials are involved.
What is the single most useful habit against AI-enabled scams?
Verify through a different channel than the one the request arrived on. An attacker controls one channel. Controlling two at once, for the same target, is a much harder problem.
If you have already sent funds
Ten questions showing which documentation and reporting steps are available in your case.
Recovery pathway assessment