Join our Newsletter — 33% off our NHI Course
Home FAQ Foundations & NHI Taxonomy Why do emerging technologies like AI and blockchain…
Foundations & NHI Taxonomy

Why do emerging technologies like AI and blockchain create new opportunities for fraud and cybercrime?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Foundations & NHI Taxonomy

Emerging technologies create risk because threat actors adapt faster than many defenders do. AI can improve scam realism, automate malicious code, and help attackers cross language barriers, while blockchain ecosystems introduce new operational surfaces and new forms of deception. The core issue is not the technology itself, but the speed and creativity with which criminals repurpose it for abuse.

Why AI and blockchain expand the fraud surface

New technologies do not create fraud by themselves, but they change the economics of abuse. AI lowers the cost of convincing deception, while blockchain systems expand the number of places where users must trust code, keys, wallets, smart contracts, bridges, and exchanges. That combination gives criminals more ways to impersonate, mislead, or exploit process gaps.

The practical shift is that defenders are no longer only evaluating a product feature, they are also evaluating how easily that feature can be repurposed. AI can speed up content generation, social engineering, and malicious code adaptation; blockchain can introduce trust assumptions around irreversible transactions, pseudonymous actors, and hard-to-reverse operational mistakes. Fraud becomes easier when abuse scales faster than verification.

How threat actors reuse AI and blockchain capabilities

AI is attractive to fraudsters because it improves both volume and quality. It can generate multilingual lures, tailored phishing, fake support chats, synthetic voice or image content, and code that changes quickly enough to frustrate pattern-based detection. For blockchain, the fraud opportunity often comes from ecosystem complexity, including wallet-draining scams, fake token launches, social engineering around seed phrases, and exploitation of poorly governed smart contracts or compromised third-party services.

That does not mean the technologies are inherently unsafe. It means the attacker can borrow legitimate capabilities and convert them into deception, credential theft, payment fraud, or unauthorized transfer. In practice, the most dangerous part is often not the core protocol or model, but the surrounding human workflow, permissions, and exception handling that assume a trusted environment.

AI-enabled abuse patterns are already documented in the wild, including autonomous or semi-autonomous attack support, which is why threat intelligence sources such as CISA cyber threat advisories and MITRE ATLAS adversarial AI threat matrix matter for fraud and cybercrime analysis. When the abuse chain includes automated recon, content generation, or tool misuse, the issue stops being a simple scam and becomes a scalable adversary workflow.

What practitioners should watch for in fraud and abuse pathways

Fraud risk rises fastest where trust is concentrated but verification is weak. In AI-driven cases, watch for identity impersonation, unusually polished but low-context communications, and workflows that rely on human judgment without a second check. In blockchain environments, watch for irreversible actions, unclear ownership, blind trust in smart contract code, and rapid movement of funds through services that make recovery difficult.

Practitioners should also treat operational surfaces as part of the fraud story. A blockchain ecosystem may be attacked through exchange onboarding, wallet handling, developer tooling, key management, or bridge dependencies, not just through the chain itself. Similarly, AI fraud often succeeds because the surrounding process does not require strong provenance, step-up verification, or independent confirmation before action is taken.

For incident-driven prioritisation, threat advisories and exploited-vulnerability tracking remain useful context, especially where fraud is enabled by compromised platforms or supporting infrastructure. For organisations that need a broader defensive baseline, the control logic in CISA Known Exploited Vulnerabilities Catalog and secure-design guidance such as CISA Secure by Design help reduce the attack paths that fraudsters commonly exploit.

Practitioner Guidance: Treat fraud prevention as a workflow and trust problem, not just a content or platform problem. Verify the steps where humans approve money movement, account recovery, code deployment, or wallet access, because those are the points where AI-generated persuasion and blockchain irreversibility become operationally expensive.

Practitioner takeaway: The best defence is to raise the cost of abuse at the decision point, not after the fraud has already scaled.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATLAS address the attack and risk surface, while CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATLASATLAS — Adversarial Threat Landscape for AI SystemsAI-driven fraud uses adversarial AI techniques and automated abuse patterns.
Recommendation — Map AI-enabled fraud scenarios to ATLAS techniques and add detections for model abuse and tool misuse.
CIS Controls v8CIS 6 — Access Control ManagementFraud often succeeds through weak approval paths and excessive access.
Recommendation — Apply access control rigor to restrict high-risk actions and reduce unauthorized transfers.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org