TL;DR: Crypto scams are getting more sophisticated as AI, fraud-as-a-service networks, and cross-border operations raise the bar for exchanges and investigators, according to SumSub. The identity lesson is that trust in digital financial systems now depends on stronger user education, better fraud detection, and tighter collaboration across security and law enforcement.
At a glance
What this is: This episode looks at how crypto fraud is evolving, with AI, fraud-as-a-service networks, and cross-border operations making trust harder to maintain.
Why it matters: Identity teams should treat fraud defence as a trust and governance problem, because user education, investigative workflows, and ecosystem collaboration now sit alongside technical controls.
Context
Crypto fraud is no longer only a detection problem. In the episode, SumSub frames the issue as a trust problem because scammers use AI, social engineering, and coordinated networks to make fraudulent activity harder for platforms and users to distinguish from legitimate behaviour.
That matters for identity programmes because crypto ecosystems sit at the intersection of user onboarding, fraud monitoring, law-enforcement collaboration, and privacy constraints. The operational question is not only whether an event is suspicious, but whether the identity layer can support investigation, containment, and user protection without breaking legitimate access.
Key questions
Q: What breaks when stablecoin fraud controls rely only on transaction monitoring?
A: Transaction monitoring alone fails when the attacker has already taken over a legitimate account. By the time a transfer looks suspicious, the damage may be irreversible because stablecoins move quickly and can be off-ramped through multiple wallets. Effective defence has to start earlier with authentication, recovery, and behavioural risk detection.
Q: Why do AI scams increase fraud risk for identity and trust programs?
A: AI raises fraud risk because it makes deception cheaper, faster, and more convincing. Attackers can generate fake content, automate phishing, create deepfakes, and personalize social engineering at scale. That combination reduces the value of traditional pattern-based defenses and increases the chance of account takeover, fake account creation, policy abuse, and financial loss across customer-facing systems.
Q: What are the signs that crypto fraud education is failing?
A: Warning signs include repeated high-risk transfers after prompts, persistent support contacts about lost funds, and users bypassing or ignoring safety messaging during onboarding or withdrawal flows. If fraud cases keep succeeding despite user-facing warnings, the programme is not changing behaviour at the decision point where the scam completes.
Q: How should security teams handle crypto fraud across security, compliance, and law enforcement?
A: They need a defined operating model for preserving evidence, routing cases, and sharing relevant context without overexposing personal data. That means fraud response cannot sit only with security or only with compliance. It requires agreed escalation paths, privacy-aware case handling, and clear ownership for cross-border incidents.
Technical breakdown
Why crypto fraud now looks like an identity trust problem
Crypto fraud increasingly depends on convincing identity interactions rather than purely technical compromise. AI-generated lures, impersonation, and fraud-as-a-service operations let attackers scale deception across onboarding, support, and transaction flows. That shifts the control problem from single-point detection to the trustworthiness of the identity signals surrounding each user action. In practice, the challenge is not just spotting bad transactions, but identifying when a real account, a synthetic identity, or a manipulated user is driving them.
Practical implication: teams need identity, behavioural, and fraud signals to be evaluated together instead of in separate silos.
How investigations rely on blockchain analytics and human review
The episode points to a combined model in which blockchain analytics help trace activity while human investigators interpret patterns, privacy constraints, and legal context. This is important because fraud operations often span platforms, jurisdictions, and accounts that do not present as a simple authentication failure. Blockchain visibility can show movement, but it does not by itself prove intent or ownership. That means operational trust depends on evidence correlation, escalation paths, and disciplined case handling.
Practical implication: integrate investigative workflows so analysts can move from transaction anomalies to account-level and case-level attribution.
Why user education still sits inside the control stack
The discussion treats education as a defensive control, not a soft awareness add-on. That matters because crypto scams often succeed by pushing the user to authorise the harmful step themselves, which means traditional perimeter controls may never see a clean intrusion event. If the user is the one clicking, sending, or approving, the control environment must recognise social engineering and trust abuse as part of the security model. In other words, informed user behaviour becomes a compensating control for identity systems that cannot block every fraudulent interaction.
Practical implication: build fraud education into onboarding, warnings, and escalation workflows so users receive help before they authorise suspicious actions.
Threat narrative
Attacker objective: The attacker wants the victim to trust the interaction long enough to authorise payment, reveal information, or move funds.
- Entry occurs through scam contact, impersonation, or fraud-as-a-service outreach that convinces the target to engage.
- Credential or trust abuse follows when the victim authorises the transaction, shares sensitive information, or gives the fraudster a usable identity signal.
- Impact lands as financial loss, account compromise, and reduced confidence in the platform’s ability to protect users.
Breaches seen in the wild
- Coinbase insider bribery breach 2025: Criminals bribed overseas Coinbase support agents to copy data on 69,461 customers, then tried to extort $20 million.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Crypto fraud has become an identity trust issue, not only an anti-scam issue. The article shows that attackers now exploit the trust layer around identity, not just transaction monitoring. That means identity teams have to think about who is being persuaded, how trust is established, and which signals prove that a user interaction is genuine. The practitioner takeaway is that fraud defence must be designed as trust governance across the full user journey.
Education is now a control, not a communications exercise. SumSub’s framing makes clear that user behaviour can be the last line of defence when the scammer’s goal is to induce an authorised action. That makes warnings, onboarding prompts, and contextual interventions part of the control stack rather than optional awareness material. The practitioner implication is that user guidance must be timed to decision points, not delivered as generic advice.
Identity trust debt: when a platform cannot reliably distinguish legitimate user intent from manipulated intent, fraud detection becomes reactive rather than preventative. AI-driven scam tooling and fraud-as-a-service networks increase that debt by scaling persuasion and impersonation. The field should treat this as a programme design problem across identity verification, behavioural detection, and case management. Practitioners need controls that reduce the amount of trust they extend before a transaction is fully understood.
Cross-border fraud requires governance across security, compliance, and law enforcement. The article highlights that no single control domain can own crypto fraud response end to end. Investigations must preserve evidence, respect privacy, and support escalation across agencies and jurisdictions. The practitioner takeaway is that fraud handling needs a formal operating model, not ad hoc analyst effort.
What this signals
Identity trust now sits inside fraud operations. Crypto platforms cannot separate user safety from identity governance when the attacker’s main tactic is to manipulate the user into taking the harmful action. That pushes teams toward controls that evaluate intent, context, and behavioural consistency before trust is extended.
Human investigators remain essential because fraud is now a hybrid problem. Automation can surface suspicious patterns, but the article shows that analysts still have to interpret privacy limits, transaction paths, and cross-jurisdiction evidence. Practitioners should expect investigation workflows to stay human-led even as detection becomes more automated.
For practitioners
- Embed scam warnings at decision points Place contextual warnings at onboarding, first transfer, device change, and high-risk withdrawal steps so users are alerted before they authorise suspicious activity.
- Fuse fraud and identity signals Correlate behavioural anomalies, account history, device context, and transaction patterns so analysts can distinguish manipulated users from ordinary high-risk activity.
- Formalise escalation with investigators Create a documented path for sharing evidence, preserving case context, and escalating cross-border incidents to internal specialists and external agencies.
- Measure how often users stop at warnings Track how many users abandon or challenge a transaction after a warning, because that shows whether trust interventions are interrupting scam completion.
- Review fraud education as a security control Treat onboarding content, safety prompts, and support scripts as part of the fraud control set and test them against real scam scenarios.
Key takeaways
- Crypto fraud in this episode is framed as a trust problem because scams succeed by manipulating legitimate users, not only by breaking systems.
- The article ties the threat to AI-enabled scams, fraud-as-a-service networks, and cross-border operations that make identity signals harder to trust.
- Fraud defence works best when identity controls, user education, investigation workflows, and law-enforcement coordination operate as one programme.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | The episode is about humans being manipulated through trusted identity interactions in crypto flows. |
| Recommendation — Reduce human misuse of identity trust by hardening decision points where users can authorise fraudulent actions. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Crypto fraud defence depends on controlling when trust and authorisation are extended to an account action. |
| Recommendation — Apply PR.AA-05 to limit authorisation paths that let manipulated users complete high-risk transfers. | ||
| MITRE ATT&CK | TA0001;TA0006 — Initial Access; Credential Access | Scams use initial contact and trust abuse to obtain the victim action needed for fraud completion. |
| Recommendation — Map scam-driven fraud activity to Initial Access and Credential Access to improve detection and case triage. | ||
| CIS Controls v8 | CIS-5 — Account Management | Fraud response depends on knowing which accounts, sessions, and recovery paths can be abused. |
| Recommendation — Use CIS-5 to review account and recovery workflows that can be exploited during scam-driven fraud. | ||
Key terms
- Identity trust: The set of assumptions an environment makes about how a user, device, or service proves who it is. When those assumptions are weak, attackers can enter through valid authentication instead of breaking infrastructure, which turns identity into the primary attack surface.
- Fraud-As-A-Service: Fraud-as-a-service is the outsourcing of scam operations through rented tools, stolen data, and ready-made attack services. It lowers the skill needed to commit fraud and lets bad actors scale quickly across industries. For defenders, it means attacks are faster, cheaper, and more operationally organized than traditional one-off fraud attempts.
- Behavioural Signal: A pattern in how a user acts over time that can help distinguish normal activity from abuse. In fraud operations, behavioural signals include timing, repetition, device consistency, channel switching, and claim history. They are most useful when combined with human review and case context.
- Cross-Border Fraud: Cross-border fraud is fraudulent activity that moves across countries, jurisdictions, or payment routes, making detection and enforcement harder. Different privacy laws, uneven reporting standards, and fragmented legal authority can slow response. Security teams need controls that account for geography, data movement, and local regulatory obligations.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org