Criminal adoption of artificial intelligence tools rose by 40% over the past 12 months, according to the 2026 AI-in-Crime Adoption Index from blockchain intelligence company TRM Labs. This increase coincides with two major hacks in April that targeted a Solana-based exchange and an Ethereum staking protocol, resulting in a combined loss of $577 million.
The surge in AI-enabled threats has prompted security experts to recommend specific measures for investors to protect their digital assets. One primary recommendation is to utilize large, regulated domestic exchanges like Coinbase Global rather than offshore venues or self-managed wallet applications. Major exchanges possess the financial resources to hire competent security teams and conduct extensive third-party audits. Additionally, these platforms typically hold the majority of customer funds offline, reducing exposure to online attacks.
Holding cryptocurrency through a spot crypto exchange-traded fund (ETF) offers another layer of security. In this structure, the asset manager appoints a specialist custodian to hold the underlying assets. The custodian manages the private keys for the fund's coin holdings in cold storage systems that operate on computers disconnected from the internet. These accounts are not commingled with the sponsor's assets or those of other clients, providing a distinct security advantage for which investors pay minimal expense fees.
For investors who prefer to hold coins directly, security best practices suggest using a two-wallet system. A "hot" wallet should be reserved for daily transactions, minting non-fungible tokens, and interacting with decentralized finance protocols. A separate "cold" wallet, managed on a secure computer system, should be used exclusively for sending and receiving bulk funds from the hot wallet. This approach concentrates the risk of a hack within the hot wallet, which holds significantly fewer funds.
A critical vulnerability remains social engineering, where attackers obtain credentials through deception. No legitimate customer support agent or exchange employee will request an account password or wallet private key. Coinbase's crime policy excludes recouping customer losses if an attacker accesses an account using the customer's own credentials. In one notable incident in April, hackers affiliated with the North Korean government spent months building rapport with Drift Protocol employees in person before obtaining the signatures necessary to steal $285 million in 12 minutes. As AI tools make it easier to clone voices or faces for video calls and chat interactions, the risk of such personalized attacks increases for individual investors.