Skip to main content
AVOID.NET
← AI-Powered Crypto Phishing Infrastructure 2026reviewed 2026-09-06 · 40 claims checked

Fact-check findings

What an automated fact-checker found when it re-read AI-Powered Crypto Phishing Infrastructure 2026 against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

3 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #3[disputed][awaiting moderator]in section: Overview and Threat Landscape
    “AI-enabled scam operations were found to generate approximately $3.2 million in revenue per operation, compared to $682,000 for operations without AI linkage — a 4.5x efficiency premium.”
    reviewerNon-AI-linked scam operations generate $682,000 in revenue per operationThe cited source contradicts the page's specific dollar figure. Note also that $3.2M/$719K ≈ 4.45x (rounds to the stated 4.5x), while $3.2M/$682K ≈ 4.7x — the page's own stated multiple is internally consistent only with the correct $719,000 figure, reinforcing that $682,000 is a transcription error.
    Proposed correction (not yet applied)
    AI-enabled scam operations were found to generate approximately $3.2 million in revenue per operation, compared to $719,000 for operations without AI linkage — a 4.5x efficiency premium.
  2. #23[disputed][awaiting moderator]in section: FEMITBOT and Telegram Mini App Exploitation
    “In April 2026, security researchers documented a large-scale fraud campaign named FEMITBOT, which abused Telegram's Mini App feature to deliver fake cryptocurrency platforms and Android malware.”
    reviewerIn April 2026, security researchers documented the FEMITBOT campaignAll four cited sources for this section (HackRead, Dataconomy, CybersecurityNews, Security Boulevard) published their FEMITBOT coverage in early May 2026, not April 2026 as the page states.
    Proposed correction (not yet applied)
    In May 2026, security researchers documented a large-scale fraud campaign named FEMITBOT, which abused Telegram's Mini App feature to deliver fake cryptocurrency platforms and Android malware.
  3. #31[disputed][awaiting moderator]in section: Pig Butchering and AI-Assisted Romance Scams
    “The FBI IC3 2025 report attributed over $11 billion in cryptocurrency-related fraud losses to investment and relationship-based schemes in 2025.”
    reviewerFBI IC3 2025 report attributed over $11 billion in crypto fraud losses to investment and relationship-based schemesThe page conflates the report's aggregate crypto-fraud total with a category-specific figure, overstating how much of that $11B is attributable to investment/relationship schemes specifically.
    Proposed correction (not yet applied)
    The FBI IC3 2025 report attributed over $11 billion in total cryptocurrency-related fraud losses in 2025, with investment fraud specifically accounting for $7.2 billion of that total.

unverifiable

2 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #33[unverifiable][awaiting moderator]in section: Pig Butchering and AI-Assisted Romance Scams
    “Chainalysis found $341 million in a single wallet tied to one pig-butchering laundering ring.”
    reviewerChainalysis found $341 million in a single wallet tied to one pig-butchering laundering ringCould not locate this specific figure in any Chainalysis publication or secondary source after multiple targeted searches. Not contradicted by another source, simply unconfirmed.
  2. #40[unverifiable][awaiting moderator]in section: Detection Evasion and Technical Capabilities
    “Human detection rates for high-quality deepfakes are reported to be at or near chance level in published behavioral studies.”
    reviewerHuman detection rates for high-quality deepfakes are at or near chance level in published behavioral studiesThe claim is broadly consistent with general deepfake-detection literature, but none of the sources cited in this section actually support it, and the page does not name the study being referenced.

partially supported

5 claims

The cited evidence supports part of the claim but not all of it.

  1. #10[partially supported][awaiting moderator]in section: Deepfake Celebrity and Government Impersonation
    “Celebrity and government impersonation fraud accounts for approximately 52% of documented deepfake fraud losses according to incident-database data compiled through March 2026, representing roughly $1.13 billion of total deepfake fraud losses reported in that period.”
    reviewerCelebrity/government impersonation accounts for ~52% of deepfake fraud losses, roughly $1.13 billionThe number itself checks out against independent research, but none of the four sources cited for this section actually contains this statistic — the citation does not support the specific figure it is attached to.
  2. #12[partially supported][awaiting moderator]in section: AI Voice Cloning and Social Engineering
    “Group-IB's threat intelligence researchers documented the use of AI voice cloning in what the FBI characterized as a 312% rise in AI-fraud complaints from U.S. businesses between 2024 and 2026.”
    reviewerGroup-IB documented AI voice cloning behind a 312% rise in AI-fraud complaints from US businesses, 2024-2026, per the FBIThe number is real but the page conflates two different sources and mischaracterizes what the 312% figure measures and who produced it.
  3. #18[partially supported][awaiting moderator]in section: LLM-Generated Phishing Sites and Automated Phishing Kits
    “Palo Alto Networks reported that LLMs have been prompted to generate approximately 2.1 million URLs resembling major brands, which criminals then register and deploy as malicious sites.”
    reviewerPalo Alto Networks: LLMs prompted to generate ~2.1 million brand-resembling URLs, which criminals register and deploy as malicious sitesThe 2.1 million figure is accurate, but the page's characterization of what happens to those URLs overstates the actual (much smaller) subset criminals have registered and weaponized.
  4. #24[partially supported][awaiting moderator]in section: Approval Phishing and Wallet Drainers
    “Operation Atlantic, a multinational law enforcement action co-led by the US Secret Service, UK National Crime Agency, Ontario Provincial Police, and Ontario Securities Commission in late March 2026, specifically targeted approval phishing infrastructure.”
    reviewerOperation Atlantic was co-led by the US Secret Service, UK NCA, Ontario Provincial Police, and Ontario Securities CommissionThe participants, timing, and target of the operation are accurate; the 'co-led' framing overstates the Secret Service's role relative to the NCA's, which multiple sources including the NCA's own release describe as the lead agency.
  5. #30[partially supported][awaiting moderator]in section: Sanctions and Regulatory Enforcement Actions
    “The FTC has pursued enforcement actions against AI-powered investment fraud schemes and is preparing to enforce a new law targeting AI-generated deepfakes and voice cloning used in scams.”
    reviewerThe FTC is preparing to enforce a new law targeting AI-generated deepfakes and voice cloning used in scamsThe underlying facts (FTC enforcement activity and a forthcoming law) are accurate, but the page's description blurs the distinction between the TAKE IT DOWN Act's actual scope (intimate-image deepfakes) and general scam-related voice cloning enforcement, which rests on separate FTC authority.

confirmed

30 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    “Chainalysis documented $17 billion in crypto scam losses in 2025, with AI-enabled operations generating 4.5 times more revenue per campaign than traditional methods.”
    reviewerChainalysis documented $17 billion in crypto scam losses in 2025The page's use of 'estimated' matches Chainalysis's own framing of $17B as a projection above the $14B confirmed on-chain figure. Confirmed as stated.
  2. #2[confirmed][no action needed]in the summary
    “Chainalysis documented $17 billion in crypto scam losses in 2025, with AI-enabled operations generating 4.5 times more revenue per campaign than traditional methods.”
    reviewerAI-enabled operations generate 4.5x more revenue per campaign than traditional methodsThe 4.5x multiple itself is correctly stated, independent of the dollar-figure error found elsewhere in the page.
  3. #4[confirmed][no action needed]in section: Overview and Threat Landscape
    “The average payment made by victims to scammers rose 253% year-over-year, from $782 in 2024 to $2,764 in 2025.”
    reviewerAverage victim payment rose 253% YoY, from $782 (2024) to $2,764 (2025)Confirmed against the primary source.
  4. #5[confirmed][no action needed]in section: Overview and Threat Landscape
    “Impersonation scams specifically grew more than 1,400% year-over-year, according to the same report.”
    reviewerImpersonation scams grew more than 1,400% YoYConfirmed.
  5. #6[confirmed][no action needed]in section: Overview and Threat Landscape
    “CertiK, a blockchain security firm, separately reported that phishing attack losses in the crypto sector increased approximately 200% year-over-year in early 2026.”
    reviewerCertiK reported crypto phishing losses rose approximately 200% YoY in early 2026Note that CertiK's later H1 2026 Hack3D report shows a subsequent reversal (phishing incident volume falling, losses roughly flat), but that does not contradict the 'early 2026' framing used on the page.
  6. #7[confirmed][no action needed]in section: Deepfake Celebrity and Government Impersonation
    “Engadget documented livestreams on YouTube featuring Musk deepfakes promoting crypto giveaway scams, with roughly 30,000 concurrent viewers at peak.”
    reviewerAn Elon Musk deepfake livestream drew roughly 30,000 concurrent viewersConfirmed by topical corroboration; consistent with well-documented pattern of large-audience Musk-deepfake livestreams.
  7. #8[confirmed][no action needed]in section: Deepfake Celebrity and Government Impersonation
    “During a SpaceX launch event, Cryptonews reported more than 35 deepfake videos of Musk operating simultaneously on the platform.”
    reviewerMore than 35 deepfake Musk videos ran simultaneously during a SpaceX launchConfirmed via corroborating syndicated copies; the 403 on direct fetch appears to be anti-bot protection rather than link rot.
  8. #9[confirmed][no action needed]in section: Deepfake Celebrity and Government Impersonation
    “In July 2025, Ripple's Chief Technology Officer publicly debunked an AI-generated video showing Garlinghouse endorsing an XRP reward scheme.”
    reviewerIn July 2025, Ripple's CTO publicly debunked a deepfake video of Garlinghouse promoting an XRP reward schemeConfirmed at month-level granularity; the CTO is not named in the page (correctly, David Schwartz).
  9. #11[confirmed][no action needed]in section: AI Voice Cloning and Social Engineering
    “AI voice synthesis tools require as little as 3–10 seconds of source audio — obtainable from LinkedIn profiles, conference recordings, or public interviews — to produce a convincing facsimile of a target's voice.”
    reviewerVoice cloning tools need 3-10 seconds of source audioConfirmed. Note: this URL is marked unarchivable in sources_used (archive_error: unauthorized) but is live and functional when fetched directly — this is an archiving gap, not link rot.
  10. #13[confirmed][no action needed]in section: AI Voice Cloning and Social Engineering
    “A widely reported 2024 case in Hong Kong involved fraudsters impersonating a company's finance manager via WhatsApp using AI-generated voice cloning, resulting in a loss of HK$18.5 million.”
    reviewer2024 Hong Kong WhatsApp voice-clone finance-manager scam cost HK$18.5 millionConfirmed.
  11. #14[confirmed][no action needed]in section: AI Voice Cloning and Social Engineering
    “A separate Hong Kong incident involved real-time voice and video deepfaking during a video call, resulting in a reported $25 million wire transfer.”
    reviewerA separate Hong Kong deepfake video-call incident led to a $25 million wire transferConfirmed via independent CNN reporting on the Arup case, which the page describes generically without naming the company.
  12. #15[confirmed][no action needed]in section: AI Voice Cloning and Social Engineering
    “the FBI IC3 2025 Annual Report documented 22,364 complaints about AI-assisted crimes totaling $893 million in losses, with investment fraud — heavily overlapping with crypto — accounting for $632 million of that total.”
    reviewerFBI IC3 2025 report: 22,364 AI-crime complaints, $893M in losses, $632M from investment fraudExact match to the primary regulatory source.
  13. #16[confirmed][no action needed]in section: LLM-Generated Phishing Sites and Automated Phishing Kits
    “Netcraft researchers tracked a threat actor that deployed over 17,000 AI-written GitBook phishing and lure sites over a one-year period, targeting more than 30 major cryptocurrency brands including Coinbase, Crypto.com, MetaMask, and Trezor.”
    reviewerNetcraft tracked over 17,000 AI-written GitBook phishing sites targeting 30+ crypto brands over a one-year periodConfirmed exactly.
  14. #17[confirmed][no action needed]in section: LLM-Generated Phishing Sites and Automated Phishing Kits
    “Netcraft separately documented a 3.95x increase in websites featuring AI-generated text between March and August 2024, with a 5.2x increase in a 30-day window in July 2024.”
    reviewerNetcraft documented a 3.95x increase in AI-generated-text websites March-August 2024, with a 5.2x spike in a 30-day window in July 2024Confirmed, minor rounding of 'starting July 6' to 'in July 2024' but not materially inaccurate.
  15. #19[confirmed][no action needed]in section: LLM-Generated Phishing Sites and Automated Phishing Kits
    “one campaign in 2025 redirected nearly 10,000 emails to an Aave-impersonating application built with Lovable.”
    reviewerA 2025 Lovable-based campaign redirected nearly 10,000 emails to a fake Aave appConfirmed; page omits the specific month (June) but that is not an error, just less precise.
  16. #20[confirmed][no action needed]in section: LLM-Generated Phishing Sites and Automated Phishing Kits
    “Commoditized phishing kits are available for as little as $500 on cybercrime forums and include hosting, phishing pages, fake investment dashboards, and victim-tracking tools.”
    reviewerCommoditized phishing kits sell for as little as $500 on cybercrime forumsConfirmed via cross-referenced reporting.
  17. #21[confirmed][no action needed]in section: Dark LLM Infrastructure: FraudGPT, WormGPT, and GhostGPT
    “It was sold on a subscription model at $200 per month or $1,700 per year.”
    reviewerFraudGPT circulated from July 22, 2023, sold at $200/month or $1,700/yearConfirmed exactly, including the specific date.
  18. #22[confirmed][no action needed]in section: Dark LLM Infrastructure: FraudGPT, WormGPT, and GhostGPT
    “GhostGPT, identified by Abnormal Security researchers in late 2024 and operating primarily through Telegram, uses a wrapper connecting to a jailbroken version of ChatGPT or an open-source LLM, making it accessible to less technical operators with no setup friction.”
    reviewerGhostGPT was identified by Abnormal Security researchers in late 2024, operating via TelegramConfirmed. The timeline entry dating this to '2024-12' is a reasonable approximation of 'end of 2024.'
  19. #25[confirmed][no action needed]in section: Approval Phishing and Wallet Drainers
    “The operation identified more than 20,000 victim wallet addresses across 30+ countries, froze over $12 million in stolen cryptocurrency, identified an additional $33 million under active investigation, and shut down more than 120 scam web domains. Total disrupted fraud exceeded $45 million.”
    reviewerOperation Atlantic identified 20,000+ wallets, froze $12M, flagged $33M more, shut 120 domains, disrupted $45M totalFully confirmed against the primary regulatory source.
  20. #26[confirmed][no action needed]in section: Approval Phishing and Wallet Drainers
    “the Drainer-as-a-Service (DaaS) ecosystem — in which operators sell specialized phishing toolkits on an affiliate model offering approximately 80% commission to deploying affiliates — was documented in a 2025 ACM Internet Measurement Conference paper.”
    reviewerThe Drainer-as-a-Service ecosystem offers ~80% commission to affiliates, documented in a 2025 ACM IMC paperConfirmed; the page correctly cites only the commission-split finding, not the $135M total (which it does not claim).
  21. #27[confirmed][no action needed]in section: Approval Phishing and Wallet Drainers
    “The 'Inferno Drainer Reloaded' operation was reported to have siphoned over $9 million from more than 30,000 wallets in a six-month period in early 2025.”
    reviewerInferno Drainer Reloaded siphoned over $9 million from more than 30,000 wallets in a six-month period in early 2025Confirmed.
  22. #28[confirmed][no action needed]in section: Sanctions and Regulatory Enforcement Actions
    “On April 23, 2026, the US Treasury's Office of Foreign Assets Control (OFAC) designated 29 individuals and entities tied to Cambodia's cyber-fraud and human-trafficking economy, targeting property owners, financial networks, and armed groups that facilitate scam compound operations generating AI-assisted pig butchering and romance fraud.”
    reviewerOFAC designated 29 individuals and entities tied to Cambodia's scam-compound economy on April 23, 2026Confirmed exactly against Treasury's own release.
  23. #29[confirmed][no action needed]in section: Sanctions and Regulatory Enforcement Actions
    “On March 12, 2026, OFAC sanctioned six individuals and two entities connected to North Korea's IT-worker fraud scheme, in which North Korean agents used AI-enabled tools, stolen identities, and fraudulent online personas to obtain remote employment at US companies and funnel approximately $800 million to the regime in 2024.”
    reviewerOFAC sanctioned six individuals and two entities tied to North Korea's IT-worker scheme on March 12, 2026, funneling ~$800M in 2024Confirmed exactly. Note this is a distinct OFAC action from the April 23, 2026 Cambodia designation, and the page's cited sources_used entry for this claim links to the same TRM Labs URL used for the Cambodia action — the two OFAC actions share a source citation, which is imprecise but not inaccurate since TRM Labs covers both in related posts.
  24. #32[confirmed][no action needed]in section: Pig Butchering and AI-Assisted Romance Scams
    “Crystal Intelligence documented that in Northern California alone, romance scam losses rose from approximately $22 million in 2024 to more than $40 million in 2025.”
    reviewerCrystal Intelligence: Northern California romance-scam losses rose from ~$22M (2024) to more than $40M (2025)The specific dollar figures are independently corroborated by FBI-sourced regional reporting, though the cited Crystal Intelligence page could not be directly accessed (403) to confirm it is the correct attribution for the statistic.
  25. #34[confirmed][no action needed]in section: Pig Butchering and AI-Assisted Romance Scams
    “In February 2026, OpenAI published findings from its own threat intelligence investigation identifying a Cambodia-based operation it designated 'Operation Date Bait,' a romance and task scam targeting men in Indonesia.”
    reviewerIn February 2026, OpenAI identified 'Operation Date Bait,' a Cambodia-based romance/task scam targeting men in IndonesiaConfirmed.
  26. #35[confirmed][no action needed]in section: Pig Butchering and AI-Assisted Romance Scams
    “On July 31, 2026, OpenAI published a broader report confirming the shutdown of a larger Cambodia-based criminal network that used ChatGPT for automated fraud, encompassing romance scams, fake cryptocurrency investment platforms, illegal online gambling, and law enforcement impersonation.”
    reviewerOn July 31, 2026, OpenAI published a report on shutting down a larger Cambodia-based network using ChatGPT for romance scams, fake crypto platforms, gambling, and law-enforcement impersonationConfirmed exactly, including the date.
  27. #36[confirmed][no action needed]in section: Lighthouse Phishing-as-a-Service and Chinese Criminal Infrastructure
    “Chainalysis identified the underlying operator group as the 'Smishing Triad,' also known as 'Darcula,' which received over 7,000 cryptocurrency deposits and amassed more than $1.5 million over three years.”
    reviewerChainalysis: Smishing Triad/Darcula received 7,000+ crypto deposits, amassing $1.5M+ over three yearsConfirmed exactly.
  28. #37[confirmed][no action needed]in section: Lighthouse Phishing-as-a-Service and Chinese Criminal Infrastructure
    “sending as many as 330,000 texts in a single day and, according to Chainalysis estimates, generating $1 billion in fraudulent proceeds over three years while affecting over one million victims.”
    reviewerThe E-ZPass campaign sent up to 330,000 texts/day, generated $1B over three years, affected over 1 million victimsConfirmed exactly against independent reporting on Google's lawsuit.
  29. #38[confirmed][no action needed]in section: Lighthouse Phishing-as-a-Service and Chinese Criminal Infrastructure
    “Netcraft separately documented the Lucid PhaaS campaign operating alongside Lighthouse, with the two campaigns collectively associated with over 17,500 phishing domains targeting 316 global brands.”
    reviewerNetcraft: Lighthouse and Lucid campaigns collectively associated with 17,500+ phishing domains targeting 316 global brandsConfirmed exactly.
  30. #39[confirmed][no action needed]in section: Detection Evasion and Technical Capabilities
    “Netcraft researchers found that 34% of hostnames provided by LLMs in response to natural language queries about major financial brands were not controlled by the brands at all”
    reviewerNetcraft found 34% of LLM-suggested hostnames for major financial brands were not controlled by the brandsConfirmed exactly against the primary source.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.