Blockchain forensics has come a long way. Chainalysis, TRM Labs, and Elliptic have frozen or recovered roughly $34 billion in stolen crypto. Over 45 regulators now use these tools as standard practice. Wallet clustering and entity attribution? Good enough to hold up in court.
AI-powered versions of these tools go further. Some claim to flag suspicious wallets before they even act. One vendor says it scores 98% accuracy across 14 million wallets. We’ve got rug-pull scanners inside AI trading agents that check liquidity locks and freeze authority in about five seconds. One service scanned over 881,000 token addresses and flagged 271,000 as high-risk.
Sounds like crypto fraud is basically solved, right?
Then you look at the other side of the ledger.
Chainalysis puts total crypto scam losses for 2025 at roughly $17 billion — up from $9.9 billion the year before. The FBI’s number for the US alone is $11.36 billion, a 22% jump. And here’s the stat that actually matters: AI-powered scams are 4.5x more profitable than traditional ones. Same con, same target — but now scammers can manufacture fake support agents and fake investors at scale.
Impersonation fraud posted 1,400% year-on-year growth. The average payment per victim jumped from $782 in 2024 to $2,764 in 2025. That’s a 253% increase.
Here’s the uncomfortable truth: defensive tooling got better. So did the offense. Both sides draw from the same AI capability well. Right now, that well favors whoever moves first.
Forensic tools are built for detective work, not prediction. A crime needs to happen before they can trace it. Even predictive models are trained on yesterday’s scams — and tomorrow’s scammer read the same training data.
Case in point: the FBI’s NexFundAI sting. Federal agents created a fake honeypot token to catch wash traders. A day after the DOJ announced arrests, someone cloned the exact smart contract and made $127,000 in 24 hours using the same tactics the FBI just exposed. The operation became the attacker’s blueprint.
Or take the Clawdbot situation. Developer Peter Steinberger had his old GitHub and X accounts hijacked within minutes of a rebrand announcement. The hijacker launched a token that hit a $16 million market cap before crashing 90%. No malware. No stolen keys. Just someone fast enough to exploit a gap no forensic tool was watching.
AI agents get rugged too. One developer watched his Solana agent buy a token that rugged 94% after twenty minutes. The token had freeze authority enabled. Top 10 holders controlled 91% of supply. The deployer had launched three previous scams. The agent didn’t check any of that.
And some damage never touches a smart contract. A woman in Guelph, Ontario lost $14,000 to someone pretending to be MrBeast. The fraud happened in a video call. By the time a transaction exists for any analytics platform to score, the victim’s already made the decision that costs them.
So who’s winning? Neither side. Both sets of tools are real. The recoveries are real. But in dollar terms, offense improved faster than defense in 2025. Detection tools mainly answer one question: “is this wallet suspicious?” That question only gets asked after someone decides to check.
