Chainalysis reported on January 13, 2026 that cryptocurrency scams had received at least $14 billion on-chain during 2025, while projecting the total could exceed $17 billion as investigators identified additional illicit addresses. The distinction is essential: $14 billion was the firm's identified dataset at the reporting cutoff; more than $17 billion was an estimate based on the way its prior annual totals had grown after publication.

The release made fraud infrastructure, rather than a token price or a funding announcement, a consequential documented crypto development on January 13, 2026. It described a market in which impersonation, automation and specialized service providers were increasing the reach of scams, while the public ledger still allowed analysts and law enforcement to trace some flows.

What the report measured

Chainalysis said its initial 2024 scam figure of $9.9 billion had been revised to $12 billion by January 13, 2026 as more scam-linked addresses were identified. The company said annual estimates had historically increased by an average of 24% between reporting periods; applying that experience to the preliminary 2025 total produced its projection that the figure could pass $17 billion.

This was an attribution exercise, not a count of every victim's realized loss. It measured cryptocurrency received by addresses that Chainalysis classified as connected to scams. It could miss unknown addresses and activity settled outside observable blockchains, while later discoveries could move transactions into the scam category. The figures also should not be combined with hacking totals: theft through exploitation and transfers induced by fraud are different categories.

The firm reported that the average scam payment rose from $782 in 2024 to $2,764 in 2025. That is a $1,982 increase and approximately 253% when divided by the 2024 base, matching the published year-over-year rate. Chainalysis also reported more than 1,400% growth in inflows to impersonation-scam clusters and an increase of more than 600% in the average payment severity for those clusters.

AI was a signal, not a complete census

The report compared scam operations with observable on-chain links to Chinese vendors selling artificial-intelligence tools against operations without those links. In that subset, AI-linked scams received an average $3.2 million per operation, versus $719,000 for the comparison group, or about 4.5 times as much. Median daily revenue was reported at $4,838 versus $518, and average transfers per day at 35.1 versus 3.89.

Those measurements did not establish that AI caused every difference. The observable link was a proxy, and larger, better-organized operations may have been more likely both to buy such tools and to generate more revenue. Nor could the method capture tools purchased through non-crypto payment channels. The evidence supported an association between visible AI-tool procurement and higher-volume scams, not a comprehensive count of all AI-enabled fraud.

Why the institutional context mattered

A December 19, 2025 Brooklyn District Attorney record illustrated the impersonation pattern independently of the aggregate estimate. Prosecutors alleged that a defendant posed as a cryptocurrency-exchange representative and induced about 100 U.S. users to transfer nearly $16 million. The indictment was an accusation, not a conviction, but it documented the type of social-engineering risk the Chainalysis categories were intended to capture.

For exchanges, wallet providers and compliance teams, the January 13 report shifted the security question beyond smart-contract bugs and private-key protection. Account support, identity verification, transaction monitoring and victim communications had become part of the same control surface. For policymakers, the provisional nature of the totals also mattered: transparent ledgers can support retrospective attribution, yet address labels and incomplete reporting prevent a real-time, exhaustive measure of harm.

What remained unknown on January 13

The final 2025 total was not known on January 13, 2026, and the projected $17 billion threshold should not be presented as a closed accounting result. Follow-up required a frozen methodology, a later address-attribution cutoff and reconciliation with victim-reported datasets. Until those checks, the defensible event-day conclusion was narrower: identified on-chain scam receipts had reached at least $14 billion, and Chainalysis expected substantial upward revision.

Primary sourceChainalysis — 2026 Crypto Crime Report: Scams, January 13, 2026

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.