TL;DR
- The cost, the scale and the fluency: cloning a voice takes seconds of audio, deepfaking a live face is consumer-grade, and scam copy now reads native in any language. What it did not change: the requests themselves, which still reduce to urgency, secrecy and a payment that is hard to reverse.
- The family-emergency voice call, the executive or support deepfake, the celebrity endorsement video, and AI-fluent phishing and romance scripts. Each pairs synthetic identity with a classic ask, and each has a procedural check that makes it harder to pull off.
- The ones that bypass the media: call-backs on known numbers, pre-agreed code words, second-channel confirmation for any transfer, and treating urgency plus secrecy plus crypto as a strong warning sign. Impersonation counterfeits identity signals; it rarely also controls the channels you initiate, though a SIM swap or hijacked account can give it one.
ในบล็อกเดียว
AI voice-clone and deepfake crypto scams are a form of impersonation fraud that uses generative models to copy the voice, face or writing of someone the target trusts, such as a relative, executive, support agent or celebrity, to press for an urgent crypto transfer or login codes.
What did generative AI actually change about fraud?
ตอบด่วน
The cost, the scale and the fluency: cloning a voice takes seconds of audio, deepfaking a live face is consumer-grade, and scam copy now reads native in any language. What it did not change: the requests themselves, which still reduce to urgency, secrecy and a payment that is hard to reverse.
The capability shift is worth stating plainly because underestimating it is now the vulnerability. Voice cloning needs only a short sample. Microsoft researchers reported in January 2023 that their VALL-E model could synthesise personalised speech from a three-second recording of a speaker it had never heard (Wang et al., arXiv, 5 January 2023), and the same year the US Federal Trade Commission warned that a scammer needs only "a short audio clip of your family member's voice", often taken from content posted online, plus a voice-cloning program (FTC consumer alert, 20 March 2023). The FBI's December 2024 public service announcement describes criminals generating "short audio clips containing a loved one's voice to impersonate a close relative in a crisis situation" (FBI IC3 PSA, 3 December 2024). Samples are harvested from voicemail greetings, social videos or a pretext call that keeps you talking.
Video followed. The same FBI announcement records deepfake video used "for real time video chats with alleged company executives, law enforcement, or other authority figures", which retired the old advice that asking for video proves anything. Even a pre-recorded fake has been enough. Hong Kong's Secretary for Security told the Legislative Council that in a case reported to police at the end of January 2024, an employee received a phishing email impersonating the chief financial officer of the UK head office and joined a group video conference that had been "generated using downloaded online public video clips and voices of the impersonated officer". The employee then authorised transfers to five local bank accounts and lost about HK$200 million, roughly 25 million US dollars (Hong Kong Government, LegCo reply LCQ9, 26 June 2024). The reply does not name the company. The engineering firm Arup confirmed in May 2024 that it was the victim (as reported by the South China Morning Post, 17 May 2024), and Arup's own 2024 financial statement records that in January 2024 criminals used "fake voice, signatures and images to execute a fraud", adding that the attack "did not impact our networks or financial stability" (Arup, Financial Statement 2024).
Text was the quiet revolution: the broken grammar that flagged a generation of phishing is gone, replaced by fluent, personalised, unlimited copy. The FBI lists AI-generated text for "social engineering, spear phishing, and financial fraud schemes such as romance, investment, and other confidence schemes", including translation tools used to hide a foreign origin (FBI IC3 PSA, 3 December 2024). The grooming stage described in the pig-butchering guide now runs with AI assistance.
The constant is the shape of the ask. Strip the synthetic media away and the requests are the classics: an emergency needing money now, an authority instructing a transfer, an opportunity requiring immediate deposit, a login needing your code. The FBI's 2025 figures are consistent with that, within the limits of how they are collected. Of the roughly 893 million dollars reported in self-reported complaints that referenced AI, about 632 million dollars sat in investment fraud, with business email compromise, tech support and romance scams accounting for most of the rest (FBI IC3, 2025 Internet Crime Report). The split shows which classic schemes complainants linked to AI; it does not measure how much of each loss AI caused. AI upgraded the costume, and the play is unchanged, which is why the defences that target the play still work.
What the FBI's AI figures do and do not measure
The IC3 report counts complaints "reporting AI-related information", of any kind (text, images, voice or video) and in any crime category. Complaints are filed by victims; IC3 analysts then review them and apply descriptive data such as crime type and adjusted loss (FBI IC3, 2025 Internet Crime Report). Four cautions follow. First, 22,364 complaints and 893 million dollars are a small slice of the year's 1,008,597 complaints and 20.9 billion dollars in reported losses, and of the 11.4 billion dollars in losses that involved cryptocurrency. Second, the report does not publish a figure for losses caused specifically by voice clones or deepfakes in crypto; the closest it comes is a note that distress scams using cloned voices of loved ones drew reported losses above 5 million dollars in 2025. Third, all IC3 numbers are self-reported by victims and undercount fraud that is never reported. Fourth, a complaint that references AI records that AI featured in the scheme as the complainant described it; it does not establish that AI caused the loss, which might have occurred through the same script without synthetic media, and the report itself observes that many victims may not realise the extent to which AI is involved, so AI use can be missed as well (FBI IC3, 2025 Internet Crime Report). This guide therefore treats the AI figures as evidence that the technique is present across fraud types, and does not treat them as a measure of deepfake crypto theft.

What are the four patterns that carry the losses?
ตอบด่วน
The family-emergency voice call, the executive or support deepfake, the celebrity endorsement video, and AI-fluent phishing and romance scripts. Each pairs synthetic identity with a classic ask, and each has a procedural check that makes it harder to pull off.
The family emergency is simple and cruel: a call in a child's or grandchild's cloned voice, distressed, in trouble, needing money quietly and immediately, often with a "lawyer" or "officer" taking over the line. The FTC's alert names the payment rails to expect: a request to "wire money, send cryptocurrency, or buy gift cards" (FTC consumer alert, 20 March 2023). The age data suggest where such schemes land hardest: complainants aged 60 and over reported about 7.7 billion dollars in losses to IC3 across all fraud types in 2025, up 59 percent on 2024, a self-reported total that covers every scheme type and is not specific to AI (FBI IC3, 2025 Internet Crime Report). The defence is prepared in calm times: a family code word no public video contains, which the FBI itself recommends, and the habit of hanging up and calling back on the number you already hold (FBI IC3 PSA, 3 December 2024). Both raise the bar for the caller; neither is proof on its own if the relative's phone or accounts have been taken over.
The executive and platform deepfake is the same play against organisations and holders: a deepfaked chief financial officer on a video call instructing a payment (as in the Arup case), the exchange's "security team" calling about a compromise and walking you through a withdrawal to a "safe wallet", screen-sharing included. The FTC has recorded scammers using voice cloning "to impersonate business executives in order to fraudulently obtain money or valuable information" (FTC press release, 8 April 2024). The defence is channel discipline: no transfer on the strength of an inbound call or meeting alone, verification through the directory number or the app's own support channel, and, for organisations, the existing approval procedure plus the per-signer independent verification described in the blind signing guide, which can blunt a fake meeting in the same way it blunts a fake interface, provided each signer checks the request on a channel they already trust; the trade-off is extra coordination and slower legitimate payments.
The celebrity endorsement is synthesis at broadcast scale: deepfaked founders and public figures in videos announcing giveaways, doubling schemes and platforms, run as ads and hijacked streams; the FBI lists AI-generated images and video of celebrities promoting fraudulent products among the observed uses (FBI IC3 PSA, 3 December 2024). The giveaway arithmetic stays the same (a promise to send back double what you send is theft with one extra step, as the common scams guide explains), and the warning signs in the guaranteed-returns guide apply before any question about whether the face is real needs answering.
The fluency wave is less a pattern than an upgrade to all of them: phishing without tells, romance scripts with perfect patience, fake support with flawless jargon, at costs that make everyone worth targeting. The response is the retirement of prose quality as a signal, replaced by the source-and-channel checks that the dApps guide and the scams and threats guide already teach: legitimacy lives in where a message came from and what it asks, and how well it reads tells you nothing.
Which verification habits still work, and why?
ตอบด่วน
The ones that bypass the media: call-backs on known numbers, pre-agreed code words, second-channel confirmation for any transfer, and treating urgency plus secrecy plus crypto as a strong warning sign. Impersonation counterfeits identity signals; it rarely also controls the channels you initiate, though a SIM swap or hijacked account can give it one.
The logic is worth one paragraph because it is the guide's spine: a clone can be your daughter's voice, and synthetic audio alone does not make it answer her phone when you dial the number saved in your contacts; a deepfake can attend the meeting, and it does not thereby receive mail at the CFO's directory address; a fake support agent can know your name, and does not thereby appear inside the app's own message centre. Verification you initiate over a channel you already trusted sits outside the impersonator's synthetic media, which is why each defence in this guide is a version of it, and why the attackers' scripts discourage it: the urgency and the secrecy exist to keep you on their channel. The limit is the channel itself. In a SIM swap, a scammer persuades a mobile provider to move a victim's number to a SIM on the scammer's phone, and then gets "all your text messages, calls, and data" (FTC consumer alert, 23 October 2019); a hijacked email or messaging account works the same way, as the account security guide explains. A successful call-back therefore helps corroborate a request and cannot prove it. For consequential transfers, the stronger practice is confirmation over a second route that is controlled independently of the first (a different person, device or account, such as a colleague who knows the requester or an in-person check), combined with the existing approval procedure. The FBI's and FTC's published advice reduces to the same two moves: hang up and verify through a contact you already have, and agree a secret word or phrase with family in advance (FBI IC3 PSA, 3 December 2024; FTC consumer alert, 20 March 2023).
The habits, in the order to install them: agree family code words now, in person, and treat their absence on an emergency call as a strong warning sign; hang up and call back as a reflex, on stored numbers, for anything involving money, codes or fear, with no exception for callers who object; confirm any first-time or unusual transfer request on a second, independently controlled channel before signing, the same out-of-band principle the sending guide applies to addresses; and hold the three-signal warning above any performance, however moving: urgency, secrecy and crypto payment together are a strong sign of fraud, whoever appears to be asking, and a reason to stop and verify before anything moves. Organisations add the structural versions: dual control on payments, the existing approval procedure for every consequential transfer, no authority in a meeting alone, and staff explicitly permitted to be "rude" to any voice, however senior, that resists verification.
What deliberately is not on the list: detecting the fake. The FBI's own tips still include looking for distorted hands, teeth or eyes in images, and those checks are worth a glance, but artefact-spotting advice ages in months, the Arup transfers were authorised after a conference assembled from public clips and voices of a real executive (Hong Kong Government, LegCo reply LCQ9, 26 June 2024), and a defence that depends on out-performing the state of the art each year is a defence that expires. Procedure ages far more slowly, which is the guide's closing point and the reason its habits are teachable to the least technical people in your life, who are precisely whom this wave targets.

Frequently asked questions
Can I reliably spot a deepfake if I know what to look for?
Treat the honest answer as no: artefact lists age faster than they can be taught, and in the Arup case a pre-recorded conference built from public clips of a real executive was enough to secure transfers of about HK$200 million, according to Hong Kong's Secretary for Security (LegCo reply LCQ9, 26 June 2024). Spotting is a bonus when it happens; procedure is the defence.
Someone only needs seconds of my voice? Should I stop posting?
Reducing public voice and video shrinks the sample pool and is reasonable hygiene, in line with the disclosure principles in the on-chain privacy guide. The FBI's tips include limiting online content of your image and voice and keeping social media accounts private (FBI IC3 PSA, 3 December 2024). It is not the defence on its own: relatives' voices are harvestable regardless, and published research puts the sample needed at a few seconds (Wang et al., arXiv, 5 January 2023). Code words and call-backs protect a family whatever is public, which is why they come first.
What should I do the moment I suspect a call is cloned?
End it without ceremony and dial the person on the number you hold. If the call-back supports the story, that helps corroborate it without proving it, because a number can be hijacked through a SIM swap (FTC consumer alert, 23 October 2019); before any large transfer, add a second independently controlled check, such as another relative or colleague, and any approval procedure that already applies. If the call-back does not support the story, the reporting drill in the guide to responding after a theft applies. In the United States, complaints go to the FBI's IC3 at ic3.gov; in England, Wales and Northern Ireland, Report Fraud (formerly Action Fraud) takes reports at reportfraud.police.uk or on 0300 123 2040; in Scotland, reports go to Police Scotland on 101 (City of London Police, December 2025). A report adds to the data agency alerts are built from and does not guarantee that anything is recovered. Anyone who then offers to recover crypto for an upfront fee fits a known follow-on scam: the FBI warns that such fraudsters take the fee and either vanish or ask for more, and that private recovery companies cannot issue seizure orders (FBI IC3 PSA, 11 August 2023). The asymmetry is the point: the call-back check costs almost nothing, even though it is one layer of corroboration rather than proof.
Are exchanges and wallets doing anything about this?
Many platforms publish scam warnings and add checks or delays to withdrawals they flag, though practices differ and this guide does not assess any provider's controls. Support channels inside the authentic app are part of the defence this guide teaches. Warnings do not undo a transfer once the network has confirmed it: protocol-level reversal is generally unavailable, so a transfer signed under a convincing voice is as hard to reverse as any other, as the custody comparison guide explains. Whether a provider reimburses anything depends on its own terms and on the rules of the jurisdiction, which differ.
Is any of this different for businesses holding crypto?
Scale and formality: the same verification logic becomes dual control, out-of-band confirmation policies and signer independence, as the institutional custody guide describes, and the Arup case shows how large a single set of authorised transfers can be. The cultural change matters most: staff must be explicitly permitted to verify upward, against any apparent seniority.
Sources and further reading
- 2025 Internet Crime Report. FBI Internet Crime Complaint Center (IC3), 2026. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf (accessed 23 September 2026)
- Cryptocurrency and AI Scams Bilk Americans of Billions (press release on the 2025 Internet Crime Report). FBI National Press Office, 6 April 2026. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions (accessed 7 October 2026)
- Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, Public Service Announcement I-120324-PSA. FBI Internet Crime Complaint Center, 3 December 2024. https://www.ic3.gov/PSA/2024/PSA241203 (accessed 23 September 2026)
- Scammers use AI to enhance their family emergency schemes. US Federal Trade Commission, consumer alert, 20 March 2023. https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes (accessed 23 September 2026)
- SIM Swap Scams: How to Protect Yourself. US Federal Trade Commission, consumer alert, 23 October 2019. https://consumer.ftc.gov/consumer-alerts/2019/10/sim-swap-scams-how-protect-yourself (accessed 24 September 2026)
- FTC Announces Winners of Voice Cloning Challenge. US Federal Trade Commission, press release, 8 April 2024. https://www.ftc.gov/news-events/news/press-releases/2024/04/ftc-announces-winners-voice-cloning-challenge (accessed 23 September 2026)
- Increase in Companies Falsely Claiming an Ability to Recover Funds Lost in Cryptocurrency Investment Scams (PSA230811). FBI Internet Crime Complaint Center, 11 August 2023. https://www.ic3.gov/PSA/2023/psa230811 (accessed 24 September 2026)
- Report Fraud service goes live with full public launch in January 2026. City of London Police, December 2025. https://www.cityoflondon.police.uk/news/city-of-london/news/2025/december/report-fraud-service-goes-live-with-full-public-launch-in-january-2026/ (accessed 24 September 2026)
- Wang, C. et al., Neural Codec Language Models are Zero-Shot Text to Speech Synthesizers (VALL-E). Microsoft Research, arXiv, 5 January 2023. https://arxiv.org/abs/2301.02111 (accessed 23 September 2026)
- LCQ9: Combating frauds involving deepfake (written reply by the Secretary for Security, Mr Tang Ping-keung, in the Legislative Council). Hong Kong Government press release, 26 June 2024. https://www.info.gov.hk/gia/general/202406/26/P2024062600192.htm (accessed 24 September 2026)
- Financial Statement 2024. Arup, 2024. https://www.arup.com/en-us/about-us/corporate-reports/financial-statement-2024/ (accessed 24 September 2026)
- UK multinational Arup confirmed as victim of HK$200 million deepfake scam that used digital version of CFO to dupe Hong Kong employee (contemporaneous reporting of Arup's confirmation). South China Morning Post, 17 May 2024. https://www.scmp.com/news/hong-kong/law-and-crime/article/3263151/uk-multinational-arup-confirmed-victim-hk200-million-deepfake-scam-used-digital-version-cfo-dupe (accessed 23 September 2026)
แบบทดสอบด่วน: มันติดไหม?
คำถามสองสามข้อเพื่อตรวจสอบพื้นฐานที่มาถึง คำตอบพร้อมคำอธิบายจะตามมา และไม่มีใครให้คะแนนคุณนอกจากผลงานในอนาคตของคุณ
คุณทำแบบทดสอบเรื่อง “AI Voice Clones and Deepfake Crypto Scams” เสร็จแล้ว! แชร์ความสำเร็จของคุณบนโซเชียลมีเดีย




