Hook
The number is almost too clean to be true. In 2025, cryptocurrency scams extracted approximately $17 billion from victims worldwide. But the number that should stop you cold is the multiplier: AI-enabled scams average $3.2 million per extraction — 4.5 times more than traditional attacks without AI assistance.
We didn't need another report telling us crime exists on-chain. We've known that since the first exchange hack. What Chainalysis's 2026 Crypto Crime Report reveals is something far more structural: criminals have industrialised artificial intelligence while the institutions tasked with stopping them operate under rules written before machine learning was a courtroom exhibit.
Every line of code writes a history of power. The question is whose code is winning.
Context
The asymmetry is stark. On one side, criminals use AI to clone voices, generate deepfakes, and automate phishing campaigns at scale. On the other side, law enforcement agencies face an entirely different constraint: many jurisdictions still prohibit investigators from using AI tools. Not because the tools don't exist. Because the policies don't.
This isn't a technology problem. It's a governance problem.
The blockchain industry has spent years building increasingly sophisticated surveillance and analytics infrastructure. Chainalysis, Elliptic, and a growing cohort of tracing firms can follow funds across chains, bridges, and even mixers with high confidence. Sol Cinosi, a former Buenos Aires prosecutor now working with Recoveris, argues that the technology has largely stopped being the bottleneck in investigations. The bottleneck is human — policy restrictions, training gaps, and a quiet psychological resistance among investigators who fear using tools they believe they lack authority to employ.
Nick Pailthorpe, who spent two decades in UK policing before joining Kodex, puts it bluntly: cryptocurrency adoption is growing faster than the number of experts who understand it. The gap isn't closing. It's widening.
Core
Let me be precise about what's actually happening, because the popular narrative misses the structural shift.
First, the crime data. Chainalysis's 2026 report shows that AI-enabled scams are not just more frequent — they're dramatically more effective. A $3.2 million average extraction per AI-assisted attack, versus roughly $700,000 for traditional scams, suggests something beyond simple automation. AI allows criminals to personalise attacks at scale, adapt in real time, and maintain multiple fraudulent operations simultaneously. The economics of crime have changed because the marginal cost of deploying a sophisticated attack has collapsed.
Second, the enforcement asymmetry. Recoveris claims to trace funds across chains, bridges, and mixers with high confidence. That's a technical capability that didn't exist three years ago. But Cinosi identifies the real obstacle: some jurisdictions ban AI use in investigations entirely. Others have no clear policy, leaving investigators uncertain about what they're permitted to do. And critically, many investigators simply fear using AI tools — they believe they lack permission to exercise powers they already possess.
This is where my own experience in governance architecture becomes relevant. Based on my work designing DAO frameworks and auditing smart contracts, I've learned that institutional resistance to new tools rarely stems from technical limitations. It stems from unclear rules of accountability. When no one has defined who is responsible for an AI-assisted investigative decision, no one wants to make that decision. The tool sits unused. The crime goes unresolved.
Third, the training deficit. Pailthorpe's point about expert scarcity is understated. The number of people who understand both blockchain forensics and legal procedure is vanishingly small. Kodex's model — providing educational materials to exchanges so they can bridge the gap with law enforcement — is a pragmatic response, but it's a bandage on a structural wound. You cannot train your way out of a problem that compounds daily.
Here's what the industry doesn't want to confront: the same technological forces that make decentralised finance revolutionary also make it an ideal environment for AI-driven crime. Pseudonymity, composability, and global liquidity are features that criminals exploit more efficiently than legitimate users because criminals have no compliance overhead. They don't need to reconcile transactions with regulatory frameworks. They need speed and scale. AI gives them both.
Contrarian
Now for the uncomfortable part. The enforcement gap isn't just a problem for law enforcement. It's a problem for the blockchain industry's legitimacy narrative.
We've spent years arguing that on-chain transparency is inherently superior to traditional finance's opacity. Every transaction is recorded. Every address is traceable. The blockchain is the ultimate audit trail. But if criminals can deploy AI to obfuscate, automate, and scale their operations faster than investigators can adapt, that narrative weakens.
Truth emerges from transparency, not from silence. Yet transparency without analytical capacity is just public data. And public data without interpretation is noise.
Consider the policy question more carefully. Some jurisdictions ban AI use in investigations because of legitimate concerns: algorithmic bias, due process, evidentiary standards. These aren't frivolous worries. An AI tool that flags suspicious transactions with 99% accuracy still produces false positives, and a false positive in a criminal investigation has real human consequences. But the alternative — refusing to use AI entirely while criminals automate — is not neutrality. It's unilateral disarmament.
The deeper problem is that regulatory frameworks move at legislative speed while AI crime moves at network speed. By the time a jurisdiction formally approves an AI investigative tool, the criminals have already adapted their techniques. This isn't a solvable problem in the traditional sense. It's a perpetual arms race with no terminal point.
There's also a structural issue that the blockchain industry itself has created. The proliferation of Layer 2 solutions and cross-chain bridges — which I've previously argued is fragmenting liquidity rather than scaling usage — has also fragmented the investigative surface. Each new chain, bridge, or interoperability protocol creates new obfuscation opportunities. Recoveris's cross-chain tracing capability is impressive, but it's always chasing the next architectural innovation.
Takeaway
The $17 billion in scam losses isn't just a crime statistic. It's a governance failure measured in financial terms.
We didn't build decentralised systems to make crime easier. But we also didn't build the governance infrastructure to handle the consequences of our own success. The tools exist to close the gap — Recoveris, Kodex, and others are proof that the technical capability is real. What's missing is the institutional will to deploy them effectively.
Governance isn't a smart contract. It's a living system of accountability, training, and adaptation. Until law enforcement agencies treat AI adoption with the same urgency that criminals treat AI deployment, the gap will continue to widen.
The next major crypto crime wave won't be a hack. It will be a coordinated, AI-driven fraud campaign that exploits the enforcement gap we've allowed to persist. The question isn't whether it's coming. It's whether we'll have closed the gap before it arrives.