← AI-Powered Crypto Phishing Infrastructure 20261 decision on this page
Audit log
Every state-changing event for AI-Powered Crypto Phishing Infrastructure 2026: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-15 12:16:39ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
1FdvLYW3Z6rf…ULmcHb2hsha256 → base58
verifying row…canonical bytes (37985 B) ▸
{"actor":"system:backfill","investigation_id":"e458fdb1-9e2d-42a4-9b2a-a13e95f69e1d","kind":"publish","page_slug":"ai-powered-crypto-phishing-infrastructure-2026","published_at":"2026-08-15T12:16:38.855Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"AI-Powered Crypto Phishing Infrastructure 2026","sections":[{"content":"The 2025–2026 period marks what blockchain analytics firm Chainalysis describes as the transition of crypto fraud from opportunistic criminal activity to an industrialized, AI-assisted economy. According to Chainalysis's 2026 Crypto Crime Report, an estimated $17 billion was stolen through crypto scams and fraud in 2025 alone, a figure the firm characterizes as a record high. AI-enabled scam operations were found to generate approximately $3.2 million in revenue per operation, compared to $682,000 for operations without AI linkage — a 4.5x efficiency premium. The average payment made by victims to scammers rose 253% year-over-year, from $782 in 2024 to $2,764 in 2025. Impersonation scams specifically grew more than 1,400% year-over-year, according to the same report. CertiK, a blockchain security firm, separately reported that phishing attack losses in the crypto sector increased approximately 200% year-over-year in early 2026. These figures reflect a convergence of three forces: the commoditization of generative AI tools available to criminals, the emergence of phishing-as-a-service (PhaaS) platforms, and the continued migration of organized crime networks — particularly those operating from Southeast Asia — into AI-assisted fraud.","heading":"Overview and Threat Landscape","severity":"critical","sources":[{"credibility":2,"name":"Chainalysis 2026 Crypto Crime Report: Scams","type":"research","url":"https://www.chainalysis.com/blog/crypto-scams-2026/"},{"credibility":2,"name":"AI, Impersonations Drove Crypto Scam Losses to Record $17 Billion in 2025: Chainalysis — Decrypt","type":"news_article","url":"https://decrypt.co/354624/ai-impersonation-drove-crypto-scam-losses-record-17-billion-2025-chainalysis"},{"credibility":2,"name":"Phishing, Deepfakes to Dominate Crypto Hacks by 2026: CertiK — CoinMarketCap","type":"research","url":"https://coinmarketcap.com/academy/article/certik-flags-deepfakes-and-phishing-as-top-2026-crypto-threats"}]},{"content":"A dominant attack vector involves AI-generated video and audio impersonating high-profile public figures to promote fraudulent cryptocurrency investment platforms or fake token giveaways. Threat actors use face-swap software and generative video models to clone the likeness of figures such as Elon Musk, Brad Garlinghouse (Ripple CEO), and government officials, then distribute the resulting videos via YouTube livestreams, social media posts, and targeted ad placements. Engadget documented livestreams on YouTube featuring Musk deepfakes promoting crypto giveaway scams, with roughly 30,000 concurrent viewers at peak. During a SpaceX launch event, Cryptonews reported more than 35 deepfake videos of Musk operating simultaneously on the platform. In July 2025, Ripple's Chief Technology Officer publicly debunked an AI-generated video showing Garlinghouse endorsing an XRP reward scheme. Celebrity and government impersonation fraud accounts for approximately 52% of documented deepfake fraud losses according to incident-database data compiled through March 2026, representing roughly $1.13 billion of total deepfake fraud losses reported in that period. Chainalysis traced surges in government impersonation deepfakes specifically to Chinese-language vendors selling face-swap software and LLM subscriptions via Telegram channels, with on-chain payment records linking these vendors to organized scam networks.","heading":"Deepfake Celebrity and Government Impersonation","severity":"critical","sources":[{"credibility":2,"name":"Deepfakes of Elon Musk are pushing crypto giveaway scams on YouTube Live — Engadget","type":"news_article","url":"https://www.engadget.com/deepfakes-of-elon-musk-are-pushing-crypto-giveaway-scams-on-youtube-live-200700886.html"},{"credibility":2,"name":"YouTube Flooded with Over 35 Deepfake Videos of Elon Musk During SpaceX Launch — CryptoNews","type":"news_article","url":"https://cryptonews.com/news/over-35-deepfake-videos-of-elon-musk-during-spacex-launch/"},{"credibility":2,"name":"Elon Musk Deepfakes Are Fueling Crypto Scams — CloudSEK","type":"research","url":"https://www.cloudsek.com/knowledge-base/elon-musk-deepfakes-are-fueling-crypto-scams-a-dangerous-trend"},{"credibility":1,"name":"Chainalysis: Impersonation and AI scams are becoming crypto's biggest threat — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/01/14/chainalysis-report-reveals-impersonation-and-ai-crypto-scams-surpass-cyberattacks"}]},{"content":"Voice-cloning technology has significantly lowered the barrier for social engineering attacks targeting crypto users and exchanges. AI voice synthesis tools require as little as 3–10 seconds of source audio — obtainable from LinkedIn profiles, conference recordings, or public interviews — to produce a convincing facsimile of a target's voice. Group-IB's threat intelligence researchers documented the use of AI voice cloning in what the FBI characterized as a 312% rise in AI-fraud complaints from U.S. businesses between 2024 and 2026. A widely reported 2024 case in Hong Kong involved fraudsters impersonating a company's finance manager via WhatsApp using AI-generated voice cloning, resulting in a loss of HK$18.5 million. A separate Hong Kong incident involved real-time voice and video deepfaking during a video call, resulting in a reported $25 million wire transfer. These techniques have migrated into crypto-specific contexts: the FBI IC3 2025 Annual Report documented 22,364 complaints about AI-assisted crimes totaling $893 million in losses, with investment fraud — heavily overlapping with crypto — accounting for $632 million of that total. These methods are also available through 'Fraud-as-a-Service' platforms on the dark web and via Telegram bots.","heading":"AI Voice Cloning and Social Engineering","severity":"high","sources":[{"credibility":2,"name":"The Voice of Fraud: Deepfake Vishing and the New Age of Social Engineering — Group-IB","type":"research","url":"https://www.group-ib.com/resources/research-hub/voice-of-fraud/"},{"credibility":1,"name":"FBI IC3 2025 Annual Report","type":"regulatory","url":"https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf"},{"credibility":1,"name":"Cryptocurrency and AI Scams Bilk Americans of Billions — FBI Press Release","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions"},{"credibility":2,"name":"AI Social Engineering in 2026: Deepfakes and Voice Clones — CyberFortress","type":"research","url":"https://cyberfortress.com/blog/three-seconds-of-audio-one-25-million-wire-transfer/"}]},{"content":"Generative AI has been weaponized to produce phishing websites at machine scale. Netcraft researchers tracked a threat actor that deployed over 17,000 AI-written GitBook phishing and lure sites over a one-year period, targeting more than 30 major cryptocurrency brands including Coinbase, Crypto.com, MetaMask, and Trezor. The campaign used a multi-stage infrastructure: lure pages hosted on GitBook.io and Webflow.io directed victims through Traffic Distribution System (TDS) redirect URLs to phishing pages deployed on Microsoft Azure App Service, with TDS technology routing security researchers to legitimate pages while funneling victims to credential-harvesting infrastructure capable of capturing two-factor authentication codes. Netcraft separately documented a 3.95x increase in websites featuring AI-generated text between March and August 2024, with a 5.2x increase in a 30-day window in July 2024. Palo Alto Networks reported that LLMs have been prompted to generate approximately 2.1 million URLs resembling major brands, which criminals then register and deploy as malicious sites. The Proofpoint-documented 'Lovable' AI campaign abused an AI website-creation tool to produce fake cryptocurrency platform interfaces; one campaign in 2025 redirected nearly 10,000 emails to an Aave-impersonating application built with Lovable. Commoditized phishing kits are available for as little as $500 on cybercrime forums and include hosting, phishing pages, fake investment dashboards, and victim-tracking tools. Dark LLM subscriptions — services advertising uncensored, jailbroken model access — are available for $30–$200 per month, enabling operators with minimal technical background to generate large volumes of personalized phishing content.","heading":"LLM-Generated Phishing Sites and Automated Phishing Kits","severity":"critical","sources":[{"credibility":2,"name":"Sophisticated AI-generated GitBook lures phishing the crypto industry — Netcraft","type":"research","url":"https://www.netcraft.com/blog/ai-generated-gitbook-lures-phishing-the-crypto-industry"},{"credibility":2,"name":"Scam Sites at Scale: LLMs Fueling a GenAI Criminal Revolution — Netcraft","type":"research","url":"https://www.netcraft.com/blog/llms-fueling-gen-ai-criminal-revolution"},{"credibility":2,"name":"Cybercriminals Abuse AI Website Creation App For Phishing — Proofpoint","type":"research","url":"https://www.proofpoint.com/us/blog/threat-insight/cybercriminals-abuse-ai-website-creation-app-phishing"},{"credibility":2,"name":"$500 scam kit builds a fake $TSLA presale and screens wallets before draining them — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/kit-scam-tsla-presale-drains-crypto/"}]},{"content":"Pig butchering (sha zhu pan) — a long-form fraud technique in which operators cultivate trust with victims over weeks or months before defrauding them through fake cryptocurrency investment platforms — has been substantially amplified by AI automation. Criminal organizations now use large language model-assisted scripts and automated sentiment analysis to adjust tone based on victim responses in real time, allowing a single operation to manage thousands of concurrent victim relationships. In February 2026, OpenAI published findings from its own threat intelligence investigation identifying a Cambodia-based operation it designated 'Operation Date Bait,' a romance and task scam targeting men in Indonesia. OpenAI determined that ChatGPT had been used by this operation to generate advertising materials, design fake brand assets, and produce images of fake personas. On July 31, 2026, OpenAI published a broader report confirming the shutdown of a larger Cambodia-based criminal network that used ChatGPT for automated fraud, encompassing romance scams, fake cryptocurrency investment platforms, illegal online gambling, and law enforcement impersonation. Threat intelligence confirmed that frontline operators in these compounds were often victims of human trafficking, trapped in forced-labor arrangements. The FBI IC3 2025 report attributed over $11 billion in cryptocurrency-related fraud losses to investment and relationship-based schemes in 2025. Crystal Intelligence documented that in Northern California alone, romance scam losses rose from approximately $22 million in 2024 to more than $40 million in 2025. Chainalysis found $341 million in a single wallet tied to one pig-butchering laundering ring.","heading":"Pig Butchering and AI-Assisted Romance Scams","severity":"critical","sources":[{"credibility":1,"name":"Disrupting a Criminal Scam Operation — OpenAI","type":"official","url":"https://openai.com/index/disrupting-malicious-uses-of-ai-criminal-scam-operation/"},{"credibility":2,"name":"OpenAI Shuts Down ChatGPT Accounts Powering a Cambodia-Based Scam Factory — GBHackers","type":"news_article","url":"https://gbhackers.com/openai-shuts-down-chatgpt-2/amp/"},{"credibility":2,"name":"Crypto romance scams in 2026: How AI changed the threat — Crystal Intelligence","type":"research","url":"https://crystalintelligence.com/thought-leadership/crypto-romance-scams-in-2026-ai-and-the-new-threat/"},{"credibility":3,"name":"Scam or Not? OpenAI Disrupts Cambodia-Based AI Romance and Crypto Scam Ring — UnboxFuture","type":"news_article","url":"https://www.unboxfuture.com/2026/08/scam-or-not-openai-disrupts-cambodia.html"}]},{"content":"A distinct segment of the threat ecosystem consists of dedicated uncensored large language models sold to criminals as subscription services, primarily via Telegram channels and dark web marketplaces. FraudGPT, first documented in circulation from approximately July 22, 2023, was advertised as capable of generating phishing emails, scam pages, carding code, and vulnerability scanning scripts. It was sold on a subscription model at $200 per month or $1,700 per year. WormGPT, accessible via dark web platforms, was marketed for business email compromise (BEC) attacks and operated by bypassing mainstream model safety guardrails through jailbreaking techniques. GhostGPT, identified by Abnormal Security researchers in late 2024 and operating primarily through Telegram, uses a wrapper connecting to a jailbroken version of ChatGPT or an open-source LLM, making it accessible to less technical operators with no setup friction. Rapid7 researchers documented new WormGPT variants built on top of commercial LLMs including xAI's Grok and Mistral's Mixtral. These tools are built for a 'cybercrime-as-a-service' model: the operator handles model hosting and evasion while affiliates pay per month and handle deployment. All three tools have been specifically advertised for crypto-fraud use cases including fake exchange site generation and social engineering script drafting.","heading":"Dark LLM Infrastructure: FraudGPT, WormGPT, and GhostGPT","severity":"high","sources":[{"credibility":2,"name":"New GhostGPT AI Chatbot Facilitates Malware Creation and Phishing — Infosecurity Magazine","type":"news_article","url":"https://www.infosecurity-magazine.com/news/ghostgpt-ai-chatbot-malware/"},{"credibility":2,"name":"How LLMs Like WormGPT Are Reshaping Cybercrime in 2025 — Rapid7","type":"research","url":"https://www.rapid7.com/blog/post/ai-goes-on-offense-how-llms-are-redefining-the-cybercrime-landscape/"},{"credibility":3,"name":"FraudGPT, WormGPT, and Dark AI Models Fuel Surge in Cybercrime — Daily Security Review","type":"news_article","url":"https://dailysecurityreview.com/blog/fraudgpt-wormgpt-and-dark-ai-models-fuel-surge-in-cybercrime/"},{"credibility":2,"name":"Generative AI Fraud: FraudGPT, WormGPT, and Beyond — IronScales","type":"research","url":"https://ironscales.com/blog/generative-ai-fraud-fraudgpt-wormgpt-and-beyond"}]},{"content":"In April 2026, security researchers documented a large-scale fraud campaign named FEMITBOT, which abused Telegram's Mini App feature to deliver fake cryptocurrency platforms and Android malware. The campaign operated by routing users who interacted with Telegram bots to embedded Mini App WebView sessions displaying phishing pages impersonating major brands including Binance, NVIDIA, Bitget, Netflix, and BBC. Victims were shown fabricated dashboards displaying fictitious balances with countdown timers designed to create urgency, while chatbot-style 'customer support' agents kept victims engaged. FEMITBOT represents a convergence of several techniques: Telegram's trusted app environment provides a legitimacy shield, Mini Apps sidestep conventional browser-based phishing detection, and AI-generated content supports the branding and scripting of fake platforms. This is consistent with broader findings that fraud actors are shifting infrastructure toward platforms that offer technical features — such as in-app WebViews and bot APIs — that obscure the distinction between legitimate and malicious applications.","heading":"FEMITBOT and Telegram Mini App Exploitation","severity":"high","sources":[{"credibility":2,"name":"FEMITBOT Network Abuses Telegram Mini Apps for Crypto Scams and Android Malware — HackRead","type":"news_article","url":"https://hackread.com/femitbot-telegram-mini-apps-crypto-scam-android-malware/"},{"credibility":2,"name":"Telegram Mini Apps Abused In Large-scale Crypto Scam Campaign — Dataconomy","type":"news_article","url":"https://dataconomy.com/2026/05/04/telegram-mini-apps-abused-in-large-scale-crypto-scam-campaign/"},{"credibility":2,"name":"New FEMITBOT Network Uses Telegram Mini Apps to Push Crypto Fraud and Android Malware — CybersecurityNews","type":"news_article","url":"https://cybersecuritynews.com/new-femitbot-network-uses-telegram-mini-apps/"},{"credibility":2,"name":"Telegram Mini Apps Abused for Crypto Scams and Android Malware Delivery — Security Boulevard","type":"news_article","url":"https://securityboulevard.com/2026/05/telegram-mini-apps-abused-for-crypto-scams-android-malware-delivery/"}]},{"content":"Approval phishing is a technique in which victims are tricked into signing malicious smart contract transactions that grant a third-party address unlimited spending permissions over the victim's wallet. Unlike traditional credential phishing, approval phishing does not require capturing a password or seed phrase — a single signed transaction suffices for complete fund exfiltration. AI has made approval phishing more scalable by automating the generation of convincing fake DeFi interfaces and urgency-inducing alert messages. Operation Atlantic, a multinational law enforcement action co-led by the US Secret Service, UK National Crime Agency, Ontario Provincial Police, and Ontario Securities Commission in late March 2026, specifically targeted approval phishing infrastructure. The operation identified more than 20,000 victim wallet addresses across 30+ countries, froze over $12 million in stolen cryptocurrency, identified an additional $33 million under active investigation, and shut down more than 120 scam web domains. Total disrupted fraud exceeded $45 million. Separately, the Drainer-as-a-Service (DaaS) ecosystem — in which operators sell specialized phishing toolkits on an affiliate model offering approximately 80% commission to deploying affiliates — was documented in a 2025 ACM Internet Measurement Conference paper. The 'Inferno Drainer Reloaded' operation was reported to have siphoned over $9 million from more than 30,000 wallets in a six-month period in early 2025.","heading":"Approval Phishing and Wallet Drainers","severity":"critical","sources":[{"credibility":1,"name":"Multi-National Operation Atlantic Targets Approval Phishing, Identifies $12 Million in Stolen Cryptocurrency — US Secret Service","type":"regulatory","url":"https://www.secretservice.gov/newsroom/behind-the-shades/2026/04/multi-national-operation-atlantic-targets-approval-phishing"},{"credibility":1,"name":"Operation Atlantic: US, UK and Canada Disrupt Crypto Approval Phishing — The Block","type":"news_article","url":"https://www.theblock.co/post/393746/us-secret-service-uk-and-canada-launch-operation-atlantic-targeting-crypto-approval-phishing-scams"},{"credibility":1,"name":"Unmasking the Shadow Economy: Drainer-as-a-Service Phishing on Ethereum — ACM IMC 2025","type":"research","url":"https://dl.acm.org/doi/10.1145/3730567.3764476"},{"credibility":2,"name":"Inside Wallet Drainers and EIP-7702 Exploits — Three Sigma","type":"research","url":"https://threesigma.xyz/blog/opsec/ai-phishing-wallet-drainers-eip7702-part-2"}]},{"content":"Regulatory enforcement has begun to intersect with AI-enabled crypto fraud infrastructure, though agencies acknowledge the pace of tool proliferation outpaces current capacity to disrupt it. On April 23, 2026, the US Treasury's Office of Foreign Assets Control (OFAC) designated 29 individuals and entities tied to Cambodia's cyber-fraud and human-trafficking economy, targeting property owners, financial networks, and armed groups that facilitate scam compound operations generating AI-assisted pig butchering and romance fraud. On March 12, 2026, OFAC sanctioned six individuals and two entities connected to North Korea's IT-worker fraud scheme, in which North Korean agents used AI-enabled tools, stolen identities, and fraudulent online personas to obtain remote employment at US companies and funnel approximately $800 million to the regime in 2024. The FBI's IC3 2025 Annual Report, published in 2026, included for the first time a dedicated section on AI-assisted crime, reflecting the FBI's recognition of AI as a distinct fraud category requiring separate tracking. The FTC has pursued enforcement actions against AI-powered investment fraud schemes and is preparing to enforce a new law targeting AI-generated deepfakes and voice cloning used in scams.","heading":"Sanctions and Regulatory Enforcement Actions","severity":"high","sources":[{"credibility":1,"name":"OFAC Sanctions Cambodian Senator and Scam Center Network — TRM Labs","type":"regulatory","url":"https://www.trmlabs.com/resources/blog/ofac-sanctions-cambodian-senator-and-scam-center-network-targeting-americans-with-digital-asset-fraud"},{"credibility":1,"name":"Cryptocurrency and AI Scams Bilk Americans of Billions — FBI Press Release","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions"},{"credibility":1,"name":"FBI IC3 2025 Annual Report","type":"regulatory","url":"https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf"},{"credibility":2,"name":"AI and Cyber-Enabled Tools Are Changing Sanctions Compliance Risks — Holland and Knight","type":"other","url":"https://www.hklaw.com/en/insights/publications/2026/04/ai-and-cyber-enabled-tools-are-changing"}]},{"content":"Chainalysis's 2026 report traced a significant portion of AI-enabled crypto phishing activity to Chinese-language criminal infrastructure, particularly a phishing-as-a-service (PhaaS) vendor called Lighthouse. Lighthouse is described as a Chinese-language vendor offering phishing infrastructure including hundreds of fake website templates, domain setup automation, and evasion features. Chainalysis identified the underlying operator group as the 'Smishing Triad,' also known as 'Darcula,' which received over 7,000 cryptocurrency deposits and amassed more than $1.5 million over three years. The group's most prominent operation was a US-targeted campaign distributing fraudulent E-ZPass toll payment alerts, sending as many as 330,000 texts in a single day and, according to Chainalysis estimates, generating $1 billion in fraudulent proceeds over three years while affecting over one million victims. A separate entity, the Taihe Gong scamming group, was identified by Chainalysis as having purchased Lighthouse phishing kits and receiving payments from Chinese-language money laundering networks. Netcraft separately documented the Lucid PhaaS campaign operating alongside Lighthouse, with the two campaigns collectively associated with over 17,500 phishing domains targeting 316 global brands. Google filed a lawsuit to disrupt the Smishing Triad's infrastructure, citing the scale of its SMS-based phishing operations.","heading":"Lighthouse Phishing-as-a-Service and Chinese Criminal Infrastructure","severity":"critical","sources":[{"credibility":2,"name":"Chainalysis: AI drives impersonation scams up 1,400% — Cyber Magazine","type":"news_article","url":"https://cybermagazine.com/news/chainalysis-inside-lighthouse-phishing-as-a-service-scams"},{"credibility":2,"name":"Lighthouse and Lucid: Netcraft Exposes 17,500+ Phishing-as-a-Service Domains","type":"research","url":"https://www.netcraft.com/blog/inside-the-lighthouse-and-lucid-phaas-campaigns-targeting-316-global-brands"},{"credibility":2,"name":"Chainalysis 2026 Crypto Crime Report — Introduction","type":"research","url":"https://www.chainalysis.com/blog/2026-crypto-crime-report-introduction/"}]},{"content":"The AI-powered phishing ecosystem has developed several techniques specifically designed to evade automated detection. Traffic Distribution Systems (TDS) route known security researcher IP addresses to legitimate destination pages while routing all other traffic to phishing infrastructure. Phishing pages on Azure App Service, GitBook, and Webflow leverage the trusted reputation of major cloud providers to evade domain reputation blocklists. AI-generated phishing content passes content-based spam filters at higher rates than manually written copy, since LLMs generate grammatically correct, contextually appropriate text without the typographic errors that trained filters detect. Netcraft researchers found that 34% of hostnames provided by LLMs in response to natural language queries about major financial brands were not controlled by the brands at all — and as of mid-2026, malicious links were appearing in AI-generated 'overview' responses in major search engines, effectively automating distribution. The Drainer-as-a-Service ecosystem has developed wallet-screening capabilities in which phishing kits pre-screen connected wallets for balance before attempting a drain transaction, maximizing per-operation yield. EIP-7702 smart account delegation, introduced in the Ethereum Pectra upgrade, has been identified by security researchers as a new attack surface that wallet drainer kits are beginning to exploit. Human detection rates for high-quality deepfakes are reported to be at or near chance level in published behavioral studies.","heading":"Detection Evasion and Technical Capabilities","severity":"high","sources":[{"credibility":2,"name":"LLMs Are Recommending Phishing Sites — Netcraft","type":"research","url":"https://www.netcraft.com/blog/large-language-models-are-falling-for-phishing-scams"},{"credibility":2,"name":"AI-Crafted Crypto Wallet Drainer Bypasses Security Tools — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/ai-crafted-crypto-wallet-drainer-bypasses-security-tools-empties-balances-fast/"},{"credibility":2,"name":"Inside Wallet Drainers and EIP-7702 Exploits — Three Sigma","type":"research","url":"https://threesigma.xyz/blog/opsec/ai-phishing-wallet-drainers-eip7702-part-2"},{"credibility":2,"name":"LLM Slop Links Ignite a Surge In AI Cyberattacks — IEEE Spectrum","type":"news_article","url":"https://spectrum.ieee.org/ai-cyberattacks-llm-slop-squatting"}]}],"sources_used":[{"credibility":2,"name":"Chainalysis 2026 Crypto Crime Report: Scams","type":"research","url":"https://www.chainalysis.com/blog/crypto-scams-2026/"},{"credibility":2,"name":"AI, Impersonations Drove Crypto Scam Losses to Record $17 Billion in 2025 — Decrypt","type":"news_article","url":"https://decrypt.co/354624/ai-impersonation-drove-crypto-scam-losses-record-17-billion-2025-chainalysis"},{"credibility":1,"name":"Chainalysis: Impersonation and AI scams are becoming crypto's biggest threat — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/01/14/chainalysis-report-reveals-impersonation-and-ai-crypto-scams-surpass-cyberattacks"},{"credibility":1,"name":"FBI IC3 2025 Annual Report","type":"regulatory","url":"https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf"},{"credibility":1,"name":"Cryptocurrency and AI Scams Bilk Americans of Billions — FBI Press Release","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions"},{"credibility":1,"name":"Multi-National Operation Atlantic Targets Approval Phishing — US Secret Service","type":"regulatory","url":"https://www.secretservice.gov/newsroom/behind-the-shades/2026/04/multi-national-operation-atlantic-targets-approval-phishing"},{"credibility":1,"name":"Operation Atlantic — The Block","type":"news_article","url":"https://www.theblock.co/post/393746/us-secret-service-uk-and-canada-launch-operation-atlantic-targeting-crypto-approval-phishing-scams"},{"credibility":1,"name":"Disrupting a Criminal Scam Operation — OpenAI","type":"official","url":"https://openai.com/index/disrupting-malicious-uses-of-ai-criminal-scam-operation/"},{"credibility":1,"name":"OFAC Sanctions Cambodian Senator and Scam Center Network — TRM Labs","type":"regulatory","url":"https://www.trmlabs.com/resources/blog/ofac-sanctions-cambodian-senator-and-scam-center-network-targeting-americans-with-digital-asset-fraud"},{"credibility":2,"name":"Sophisticated AI-generated GitBook lures phishing the crypto industry — Netcraft","type":"research","url":"https://www.netcraft.com/blog/ai-generated-gitbook-lures-phishing-the-crypto-industry"},{"credibility":2,"name":"Scam Sites at Scale: LLMs Fueling a GenAI Criminal Revolution — Netcraft","type":"research","url":"https://www.netcraft.com/blog/llms-fueling-gen-ai-criminal-revolution"},{"credibility":2,"name":"LLMs Are Recommending Phishing Sites — Netcraft","type":"research","url":"https://www.netcraft.com/blog/large-language-models-are-falling-for-phishing-scams"},{"credibility":2,"name":"Lighthouse and Lucid: Netcraft Exposes 17,500+ Phishing-as-a-Service Domains","type":"research","url":"https://www.netcraft.com/blog/inside-the-lighthouse-and-lucid-phaas-campaigns-targeting-316-global-brands"},{"credibility":2,"name":"CertiK Flags Deepfakes and Phishing as Top 2026 Crypto Threats — CoinMarketCap","type":"research","url":"https://coinmarketcap.com/academy/article/certik-flags-deepfakes-and-phishing-as-top-2026-crypto-threats"},{"credibility":2,"name":"Deepfakes of Elon Musk are pushing crypto giveaway scams on YouTube Live — Engadget","type":"news_article","url":"https://www.engadget.com/deepfakes-of-elon-musk-are-pushing-crypto-giveaway-scams-on-youtube-live-200700886.html"},{"credibility":2,"name":"YouTube Flooded with Over 35 Deepfake Videos of Elon Musk During SpaceX Launch — CryptoNews","type":"news_article","url":"https://cryptonews.com/news/over-35-deepfake-videos-of-elon-musk-during-spacex-launch/"},{"credibility":2,"name":"The Voice of Fraud: Deepfake Vishing — Group-IB","type":"research","url":"https://www.group-ib.com/resources/research-hub/voice-of-fraud/"},{"credibility":2,"name":"New GhostGPT AI Chatbot Facilitates Malware Creation and Phishing — Infosecurity Magazine","type":"news_article","url":"https://www.infosecurity-magazine.com/news/ghostgpt-ai-chatbot-malware/"},{"credibility":2,"name":"How LLMs Like WormGPT Are Reshaping Cybercrime in 2025 — Rapid7","type":"research","url":"https://www.rapid7.com/blog/post/ai-goes-on-offense-how-llms-are-redefining-the-cybercrime-landscape/"},{"credibility":2,"name":"FEMITBOT Network Abuses Telegram Mini Apps for Crypto Scams — HackRead","type":"news_article","url":"https://hackread.com/femitbot-telegram-mini-apps-crypto-scam-android-malware/"},{"credibility":2,"name":"Cybercriminals Abuse AI Website Creation App For Phishing — Proofpoint","type":"research","url":"https://www.proofpoint.com/us/blog/threat-insight/cybercriminals-abuse-ai-website-creation-app-phishing"},{"credibility":1,"name":"Unmasking the Shadow Economy: Drainer-as-a-Service Phishing on Ethereum — ACM IMC 2025","type":"research","url":"https://dl.acm.org/doi/10.1145/3730567.3764476"},{"credibility":2,"name":"LLM Slop Links Ignite a Surge In AI Cyberattacks — IEEE Spectrum","type":"news_article","url":"https://spectrum.ieee.org/ai-cyberattacks-llm-slop-squatting"},{"credibility":2,"name":"Crypto romance scams in 2026: How AI changed the threat — Crystal Intelligence","type":"research","url":"https://crystalintelligence.com/thought-leadership/crypto-romance-scams-in-2026-ai-and-the-new-threat/"},{"credibility":2,"name":"OpenAI Shuts Down ChatGPT Accounts Powering a Cambodia-Based Scam Factory — GBHackers","type":"news_article","url":"https://gbhackers.com/openai-shuts-down-chatgpt-2/amp/"},{"credibility":2,"name":"AI and Cyber-Enabled Tools Are Changing Sanctions Compliance Risks — Holland and Knight","type":"other","url":"https://www.hklaw.com/en/insights/publications/2026/04/ai-and-cyber-enabled-tools-are-changing"}],"summary":"A broad, industrialized criminal ecosystem has emerged in 2025–2026 in which threat actors use generative AI tools — including large language models, deepfake video engines, and voice-cloning services — to produce and operate crypto phishing infrastructure at unprecedented scale. Chainalysis documented $17 billion in crypto scam losses in 2025, with AI-enabled operations generating 4.5 times more revenue per campaign than traditional methods. Law enforcement agencies across the US, UK, and Canada have begun coordinated enforcement actions, but the pace of tool proliferation continues to outpace disruption.","timeline":[{"date":"2023-07-22","event":"FraudGPT first documented circulating on dark web and Telegram channels, advertising crypto phishing page generation among its capabilities at $200/month.","source":"Asia Times / IronScales","source_url":"https://asiatimes.com/2024/07/fraudgpt-wormgpt-and-the-rise-of-dark-llms/"},{"date":"2024-06-01","event":"YouTube livestream featuring an Elon Musk deepfake promoting a crypto giveaway scam draws approximately 30,000 concurrent viewers; face and voice were AI-generated.","source":"Engadget","source_url":"https://www.engadget.com/deepfakes-of-elon-musk-are-pushing-crypto-giveaway-scams-on-youtube-live-200700886.html"},{"date":"2024-07-01","event":"Netcraft documents a 5.2x month-over-month increase in websites with AI-generated text used for phishing, concentrated in July 2024; crypto brands are a primary target.","source":"Netcraft","source_url":"https://www.netcraft.com/blog/llms-fueling-gen-ai-criminal-revolution"},{"date":"2024-09-01","event":"Netcraft publishes research on over 17,000 AI-written GitBook phishing lure sites targeting more than 30 crypto brands including Coinbase, MetaMask, and Trezor, traced over a one-year tracking window.","source":"Netcraft","source_url":"https://www.netcraft.com/blog/ai-generated-gitbook-lures-phishing-the-crypto-industry"},{"date":"2024-12-01","event":"GhostGPT identified by Abnormal Security researchers operating through Telegram, providing jailbroken LLM access to criminals with no technical setup required.","source":"Infosecurity Magazine","source_url":"https://www.infosecurity-magazine.com/news/ghostgpt-ai-chatbot-malware/"},{"date":"2025-01-14","event":"Chainalysis publishes its 2026 Crypto Crime Report, reporting $17 billion in crypto scam losses in 2025, 1,400%+ growth in impersonation scams, and 4.5x revenue premium for AI-enabled operations.","source":"CoinDesk / Chainalysis","source_url":"https://www.coindesk.com/business/2026/01/14/chainalysis-report-reveals-impersonation-and-ai-crypto-scams-surpass-cyberattacks"},{"date":"2025-07-01","event":"Ripple CTO publicly debunks AI-generated video falsely depicting CEO Brad Garlinghouse endorsing an XRP reward scheme, illustrating executive deepfake targeting of crypto executives.","source":"CloudSEK","source_url":"https://www.cloudsek.com/knowledge-base/elon-musk-deepfakes-are-fueling-crypto-scams-a-dangerous-trend"},{"date":"2026-02-01","event":"OpenAI identifies and disrupts 'Operation Date Bait,' a Cambodia-based romance and task scam targeting Indonesian men in which ChatGPT was used to generate advertising, brand imagery, and fake personas.","source":"OpenAI","source_url":"https://openai.com/index/disrupting-malicious-uses-of-ai-criminal-scam-operation/"},{"date":"2026-02-26","event":"OpenAI publishes its February 2026 threat intelligence update documenting fraudster integration of ChatGPT into global scam campaigns.","source":"Help Net Security","source_url":"https://www.helpnetsecurity.com/2026/02/26/openai-malicious-chatgpt-use-report/"},{"date":"2026-03-12","event":"OFAC sanctions six individuals and two entities tied to North Korean IT-worker fraud scheme, which used AI tools and deepfake personas to infiltrate US companies, funneling approximately $800 million to North Korea in 2024.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/ofac-sanctions-cambodian-senator-and-scam-center-network-targeting-americans-with-digital-asset-fraud"},{"date":"2026-03-28","event":"Operation Atlantic concludes: US Secret Service, UK NCA, Ontario Provincial Police, and Ontario Securities Commission freeze $12 million in crypto, flag 20,000+ wallet addresses, and shut 120 scam domains in a one-week multinational approval phishing enforcement action.","source":"US Secret Service","source_url":"https://www.secretservice.gov/newsroom/behind-the-shades/2026/04/multi-national-operation-atlantic-targets-approval-phishing"},{"date":"2026-04-09","event":"US Secret Service announces Operation Atlantic results publicly, calling it the first coordinated multinational enforcement action specifically targeting approval phishing.","source":"The Block","source_url":"https://www.theblock.co/post/393746/us-secret-service-uk-and-canada-launch-operation-atlantic-targeting-crypto-approval-phishing-scams"},{"date":"2026-04-23","event":"OFAC designates 29 individuals and entities tied to Cambodia's cyber-fraud and human-trafficking scam compound economy, targeting infrastructure used in AI-assisted pig butchering operations.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/ofac-sanctions-cambodian-senator-and-scam-center-network-targeting-americans-with-digital-asset-fraud"},{"date":"2026-04-28","event":"FEMITBOT campaign comes to public attention; large-scale Telegram Mini App fraud network impersonating Binance, Bitget, NVIDIA, Netflix, and BBC with fake crypto dashboards and AI chatbot support.","source":"HackRead / Dataconomy","source_url":"https://hackread.com/femitbot-telegram-mini-apps-crypto-scam-android-malware/"},{"date":"2026-07-31","event":"OpenAI publishes major report confirming shutdown of a larger Cambodia-based criminal network using ChatGPT for romance fraud, fake crypto investment platforms, illegal gambling, and law enforcement impersonation.","source":"OpenAI / GBHackers","source_url":"https://gbhackers.com/openai-shuts-down-chatgpt-2/amp/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 8df6eba0-7dce-46b1-9330-040520a2e4f9
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.