For most of crypto's history, a scammer's ability to impersonate someone convincingly was limited by skill and effort. Faking a person's voice or appearance in a way that would survive close scrutiny took real production work. That constraint has effectively disappeared. Widely available AI tools can now generate a realistic video or audio clip of almost anyone speaking words they never said, and the crypto fraud economy has adopted the technology faster than almost any other sector.
The scale of the shift
Industry tracking of deepfake enabled financial fraud found global losses reached roughly 1.1 billion dollars in 2025, close to triple the 360 million dollars recorded in 2024. Deepfake related fraud cases nearly quadrupled in just the first half of 2025 compared with the entirety of the prior year, with cumulative losses approaching 900 million dollars by the midpoint of the year alone. Separately, blockchain analytics firm TRM Labs documented a roughly 500 percent increase in AI tool usage across crypto scam operations during 2025, a figure that reflects not just more sophisticated output but a much larger number of criminal groups adopting the technology at all.
The main categories of deepfake crypto fraud
Fabricated endorsement videos
The most visible category places a synthetic version of a recognizable public figure, whether a business leader, celebrity, or political figure, into a video praising a specific trading platform, token, or investment strategy. Our guides on Elon Musk impersonation scams and celebrity impersonation crypto scams cover this category in detail, since it is currently the most common way deepfakes reach ordinary crypto users.
Hijacked broadcast and livestream fabrication
A related but distinct pattern inserts synthetic video directly into what appears to be a live or breaking news broadcast. One widely documented 2025 case placed a deepfake of Nvidia's chief executive into a fake livestream timed around the company's own real developer conference, promoting a fraudulent cryptocurrency scheme to an audience that at points outnumbered viewers of the genuine event by roughly five to one. The fabricated stream borrowed the visual language of a real keynote, graphics, pacing, framing, to make the fraud significantly harder to distinguish from the authentic broadcast happening at the same time.
Deepfake CEO and executive impersonation
A more targeted and often more damaging variant is used against businesses rather than individual retail investors. Attackers generate a synthetic video or voice call impersonating a company's chief executive or a senior finance officer, instructing an employee to authorize an urgent cryptocurrency transfer. One documented case in Hong Kong resulted in a loss of roughly 25 million dollars after employees were convinced by a deepfake video call featuring what appeared to be several senior colleagues, and separate incidents in Singapore and elsewhere have produced losses in the hundreds of thousands of dollars through similar fabricated video calls. This overlaps closely with the mechanics described in our guide on business email compromise targeting crypto, since both rely on impersonating internal authority to bypass a company's normal approval process.
A convincing video or voice call is no longer meaningful proof of a person's identity or instructions. Any request involving a cryptocurrency transfer, personal or corporate, should be verified through a separate, independently confirmed channel before acting on it.
Inside a deepfake CEO call, step by step
The mechanics of the Hong Kong style deepfake CEO fraud are worth walking through in detail because the format has since been replicated in smaller versions against many other companies. A finance employee receives a video call invitation through the company's normal video conferencing tool, appearing to come from the chief financial officer, joined by several other apparent colleagues whose faces the employee recognizes from past meetings. The call opens with brief small talk consistent with how the real executives typically speak, before shifting into an urgent request, a confidential acquisition requires an immediate cryptocurrency transfer to a new counterparty, and the CFO explains that normal approval channels need to be bypassed temporarily due to the deal's sensitivity and time pressure.
In the real Hong Kong case, every other participant on the call besides the target employee was later determined to be a synthetic recreation, generated using publicly available video and audio of the real executives sourced from earnings calls, conference appearances, and internal recorded meetings. The employee, seeing and hearing colleagues they recognized, in a group setting that felt procedurally normal, proceeded with the transfer across several transactions before the fraud was discovered. The multi participant format is a deliberate refinement, since a single deepfake speaker is easier to second guess than an entire familiar looking group appearing together, which lends the interaction a social proof effect similar to what a fabricated giveaway chat achieves with bot comments.
The tools making this possible
- Real time face swap software that can overlay a synthetic face onto a live video call feed, reacting to the actual speaker's movements and expressions with only a small processing delay
- Voice cloning tools that can produce a convincing synthetic version of a specific person's voice from a relatively small sample of real audio, in some cases under a minute
- Text to video generation tools that can produce a standalone fabricated clip of a person speaking a written script, used for pre recorded endorsement style scams rather than live calls
- Automated scripting tools that let a fraud operation run the same deepfake template against multiple targets with minimal manual adjustment, lowering the cost of running the scam at scale
Access to these tools has moved from specialized technical circles into consumer facing apps and open source projects that require little more than uploading source material and describing the desired output, which is the single biggest factor behind how quickly this category of fraud has scaled since 2024.
Why deepfakes are unusually effective on video native platforms
Video carries a kind of implicit trust that text based scams never had. A written claim invites skepticism almost automatically, but a moving, speaking likeness of a familiar face triggers a much older and more automatic form of belief. Scammers have specifically gravitated toward platforms built around video and livestreaming, where that trust effect is strongest and where a fraudulent broadcast can reach large audiences quickly before it is identified and removed.
Detection is getting harder, not easier
Early deepfakes had reliable tells: unnatural blinking, poor lip synchronization, flat lighting, distorted hands. Current generation tools have closed most of these gaps, and detection increasingly requires specialized technical analysis rather than something a viewer can judge by eye. This means the practical defense has to shift away from trying to spot a fake visually and toward verifying claims independently, regardless of how convincing the video looks.
- Verify any investment claim tied to a video through the subject's own official, verified channels before acting on it
- For business contexts, require a second, independent verification step for any urgent transfer request, such as a callback to a known number rather than a reply to the same channel the request arrived through
- Treat urgency itself as a warning sign, since deepfake scams rely heavily on rushing the target before verification can happen
- Assume that video and audio alone are no longer reliable proof of identity for financial decisions of any size
Building organizational defenses against deepfake fraud
For businesses handling cryptocurrency, the defense against deepfake CEO fraud looks less like a technology purchase and more like a procedural change. The single most effective control is a rule that no cryptocurrency transfer above a defined threshold can be initiated based on a video call, voice call, or message alone, regardless of who appears to be requesting it or how urgent the justification sounds. That rule only works if it applies without exception, including to requests that appear to come from the most senior person in the company, since attackers specifically choose to impersonate the person whose authority is least likely to be questioned.
- Establish a fixed, out of band verification step for any transfer request above a set threshold, such as a callback to a phone number stored independently rather than one provided in the request itself
- Set up a shared internal code word or phrase for verifying unusual urgent requests, changed periodically, since this defeats even a highly convincing synthetic voice or video
- Train finance and treasury staff specifically on the existence of multi participant deepfake calls, since awareness limited to single speaker deepfakes leaves an obvious gap
- Apply the same skepticism to requests received through a company's video conferencing platform as would be applied to an unusual email, rather than treating video as inherently more trustworthy
- Log and review any request that bypasses a normal approval process for time sensitivity, even after it turns out to be legitimate, since this creates a habit of scrutiny around the exact pattern attackers rely on
If you have been targeted
Preserve the video or call recording if possible, along with wallet addresses, transaction records, and any related messages. For a business incident, this documentation is essential both for internal review and for any law enforcement report, and should include the meeting platform's own logs if available, since these can sometimes show technical details about the call, such as connection metadata, that support a fraud investigation even when the video itself looked flawless to the participants at the time.
Speed also matters more with cryptocurrency transfers than with a traditional bank wire, since blockchain transactions settle quickly and finally, leaving no window for a bank to reverse the transfer once it is confirmed. Notifying any exchange the funds may have passed through, and doing so within hours rather than days, gives the best realistic chance that an account can be flagged before the funds are moved onward again. Investigators can sometimes trace where funds moved after a deepfake driven transfer, and firms such as Coin Trace work with both individuals and businesses on this kind of tracing, though recovery ultimately depends on where the funds ended up and cannot be promised in advance.
Frequently asked questions
Global deepfake enabled financial fraud losses reached approximately 1.1 billion dollars in 2025, nearly triple the 360 million dollars recorded in 2024, with case volume nearly quadrupling in just the first half of the year compared with all of the prior year.
It is becoming much harder. Early tells like unnatural blinking or poor lip sync have largely been resolved by current tools. The more reliable approach is independent verification of the claim itself rather than visual judgment of the footage.
Both are targeted, but through different formats. Individuals are most often targeted with fabricated celebrity endorsements of investment platforms, while businesses face a more targeted risk from deepfake executive impersonation used to authorize fraudulent transfers, sometimes resulting in losses in the millions of dollars from a single incident.
Independent verification through a separate, trusted channel. Whether the claim comes from a video, a call, or a livestream, confirming it through an official account, a known phone number, or an established internal process before acting is far more reliable than trying to detect the fake visually.
Sources and further reading
- A deepfake video of Nvidia's CEO sent thousands of viewers to a crypto scam · PCWorld
- $25M Deepfake CEO Scam Shakes Hong Kong Firm · GetClarity
- The Deepfake Deception: How a CEO Video Call Cost $499K in Singapore · Tookitaki