Artificial intelligence is becoming one of the most useful tools in finance—and one of the most efficient tools for criminals.
According to TRM Labs, criminal use of AI rose 40% over the past year, reflecting how quickly scammers are incorporating the technology into increasingly sophisticated attacks.
The development points to a broader transformation in digital crime: the problem is no longer simply that criminals have better tools, but that those tools can operate at scale.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
For years, online scams depended heavily on human effort. A fraudster might manually contact potential victims, construct convincing messages, impersonate a company executive or search for information that could make a scam more believable.
Generative AI changes the economics of that process. It can produce personalized messages, imitate communication styles, translate languages and automate repetitive interactions, allowing relatively small operations to target far more people.
Crypto markets are particularly exposed because transactions can move rapidly across borders and, once completed, can be difficult to reverse. A convincing phishing message or fabricated investment opportunity can therefore become a financial event within minutes.
AI does not necessarily create entirely new forms of fraud; instead, it can make existing techniques cheaper, faster and more convincing.
That creates an uncomfortable symmetry for cryptocurrency exchanges. The same technology being used to attack financial infrastructure is increasingly being deployed to defend it.
Exchanges can use AI and machine-learning systems to identify unusual transaction patterns, flag suspicious accounts, detect coordinated activity and prioritize investigations.
But this introduces another layer of risk. When an exchange relies on automated systems to identify potentially criminal behavior, the quality of those systems becomes part of the security architecture.
A model can produce false positives, miss sophisticated attacks or react incorrectly to unusual but legitimate behavior. In a financial environment, an error is not merely technical. It can mean a delayed withdrawal, a frozen account or a legitimate transaction being treated as suspicious.
This is where governance becomes as important as detection. KuCoin’s acquisition of ISO/IEC 42001:2023 certification for its AI management system illustrates the emerging focus on that problem.
The international standard addresses how organizations establish governance around artificial intelligence, including responsibilities, processes and oversight. Its significance is therefore different from a claim that an AI system will always make the correct decision.
An AI management certification cannot guarantee that an automated fraud-detection model will never make a mistake. What it can provide is a framework for asking whether an organization has established procedures for managing those risks.
Who is responsible when an AI system produces an erroneous result? How are models reviewed? How are failures documented? Can decisions be challenged? And how does an organization respond when criminals adapt to the system?
These questions will become increasingly important as AI becomes embedded in financial infrastructure. The next phase of crypto security may therefore involve an arms race between automated offense and automated defense.
Criminal groups can use AI to increase the volume and sophistication of attacks, while exchanges can use AI to process enormous quantities of transactions and identify anomalies that humans could not efficiently detect.
The decisive issue may not be whether AI is used, but whether its use is governed responsibly. As artificial intelligence becomes part of the machinery protecting billions of dollars in digital assets, transparency, accountability and human oversight are becoming security controls in their own right.
The technology can detect threats, but governance determines what happens when the technology itself becomes wrong.



