What the AI Crypto Crime Index 2026 Actually Shows
TRM Labs published its 2026 AI-in-Crime Adoption Index on Friday, and the headline number is real: the firm's composite score for AI use across crypto crime jumped from 28 in 2024 to 54 this year, an "Emerging" reading overall. Within days, that single number had been stretched into a story it doesn't support — that Coldcard's $116 million hardware-wallet hack, the $8.5 million Term Labs governance drain and last week's Sandbox bridge exploit are three data points in one AI-driven hacking wave. Read the index itself, and that framing falls apart. TRM doesn't score crypto crime as one lump. It breaks it into typologies, and on that breakdown, scams sit at "Mature" AI adoption while hacking and ransomware sit at "Emerging" — the same tier the index uses for tools criminals have only just started picking up.
Is AI Really Behind Coldcard, Term Labs and Sandbox?
Check the three incidents against the facts, not the narrative, and none of them cleanly fits an AI-hacking story. Term Labs wasn't hacked in any technical sense: the attacker quietly bought up 91-100% of a thinly held governance token, then used that voting power to redirect a vault — a purchase, not an exploit, and nobody has claimed AI helped price the buy. The Sandbox bridge drain traced to a LayerZero delegate-permission misconfiguration, a plumbing error with no AI mentioned in any technical writeup. Coldcard is the only one with an AI thread at all, and it's thin: Galaxy Research assessed with high confidence that at least some of the attackers likely used AI models without safety guardrails, Coinkite's CEO has said only that the firm must now assume its public firmware is already being read and probed with AI by both attackers and defenders — not that AI is confirmed to have found this specific bug — and independent researchers describe the underlying entropy flaw as computationally straightforward — the kind of bug a patient human or an off-the-shelf script could have found without any AI involved. Bundling these three under one AI banner is journalism reaching for a cleaner story than the evidence gives it.
The Real Culprit Behind Record Hack Numbers
The actual explanation for 2026's hack total is less viral but better supported. Crypto hacks hit roughly 201-207 incidents in the first half of 2026, more than double the same period last year, but TRM's own data shows just 4% of those incidents accounted for roughly 75% of the dollar losses. That concentration points straight at North Korea, whose state-sponsored operations are estimated to account for somewhere between two-thirds and three-quarters of all stolen value this year, driven by a handful of attacks rather than a broad wave of new exploits. This matters because it's the opposite mechanism from "AI is automating hacking." A small number of well-resourced, state-backed teams pulling off a few very large thefts is a concentration story, not a democratization story — and concentration is what you'd expect from a nation-state operation with recruiting pipelines and years of tradecraft, not from AI tools lowering the skill floor for random attackers.
Where AI does show up in North Korea's playbook, it's in the surrounding tradecraft rather than the exploit itself: deepfake video calls used to land fake IT-worker jobs inside crypto firms, and AI-assisted social engineering used to build trust before a theft. That's a real and growing risk. It's also a different risk than "AI wrote the exploit code," which is the claim the viral synthesis narrative implies and the one none of this week's incidents actually back up.
Where AI Crime Is Actually Maturing
If hacking isn't where the AI-crime story lives this year, scams are. TRM rates AI use in scams as "Mature," the only category to earn that tier, and the numbers behind it are the ones worth internalizing. AI involvement in scam reports — deepfake videos, AI chatbots running the con, AI-branded fake endorsements — has grown roughly 13-fold since 2022. Deepfake-scam losses reported so far in 2026 already exceed all of 2025 by 263%. That's the mechanism working exactly as you'd expect: generative tools have gotten cheap and convincing enough that impersonating a person on video or running a personalized chat con no longer requires any technical skill, just access to widely available AI products. Hacking a bridge contract or a hardware wallet still requires the kind of specialized technical knowledge AI hasn't meaningfully automated yet, which is precisely why TRM scores that category three tiers behind.
What Would Change This Picture
The base case is that this gap holds for at least one more index cycle: scams keep climbing toward full "Mature" status, hacking and ransomware stay "Emerging," and North Korea's concentrated state theft — not AI tooling — keeps explaining most of the dollar losses in hacks. The forward risk isn't that this analysis is wrong today, it's that the viral "AI hacking wave" framing is more shareable than "a governance token was cheap to buy," so expect outlets to keep recycling it through the rest of the year regardless of what the index actually says.
Two things would genuinely move this call. First, a confirmed forensic finding that an AI system independently discovered or executed the Coldcard exploit — as opposed to a researcher's assumption — would give the hacking-AI narrative real evidentiary footing for the first time. Second, TRM's next index update, likely in the fourth quarter or early next year, will show whether hacking and ransomware have climbed off "Emerging" as agentic AI tools spread further into criminal use, a trend already visible in isolated cases like the JadePuffer ransomware operation. Until either of those lands, the evidence points to deepfakes and chatbots as 2026's real AI-crime story, and to old-fashioned governance failures, permission bugs and North Korean state theft as the explanation for the hacks getting blamed on AI instead.
Sources
- https://www.trmlabs.com/reports-and-whitepapers/the-2026-ai-in-crime-adoption-index
- https://www.theblock.co/news/web3/2026-08-21-ai-adoption-in-crypto-crime-trm-412297
- https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks
- https://cryptobriefing.com/north-korea-hackers-steal-643m-crypto-h1-2026/
- https://www.cryptotimes.io/2026/08/15/coldcard-attackers-likely-used-unrestricted-ai-models-galaxy-says/
- https://1023jack.com/market/forty-bits-the-coldcard-hack-and-the-question-of-whether-an-ai-found-it/
- https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack
- https://www.coindesk.com/web3/2026/08/22/web3-gaming-network-sandbox-stops-base-and-bnb-chain-bridging-after-exploit
- https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/
- https://finance.yahoo.com/markets/crypto/articles/another-defi-hack-term-labs-123536364.html
- https://medium.com/coinmonks/2026-cryptos-most-hacked-year-and-the-ai-race-to-defend-it-9ff0a1a17dec