← Back to Blog

VEYRNOX · Blog · September 1, 2026 · By Al Jobson, Founder

AI Security Protection for Self-Custody Wallets

Veyrnox AI security suite — wallet card with defensive AI layers for self-custody
Veyrnox's AI security suite: defensive layers built into a self-custody wallet, not bolted on.

Between 2022 and 2025, generative AI turned crypto phishing from a cottage industry into an industrial pipeline. Chainalysis now attributes an estimated $17 billion in 2025 crypto scam losses to a landscape "faster, more convincing, and more profitable" because of AI-generated content and impersonation, with on-chain-linked AI scam operations earning about 4.5 times what non-AI scams do[1]. SlashNext logged a 341% increase in malicious phishing links, BEC, QR-code and attachment threats in a single six-month window and a more-than-forty-fold rise in malicious email volume since ChatGPT launched in November 2022[2]. Wallet-drainer kits stole $494 million from around 332,000 addresses on EVM chains in 2024 alone, up 67% year over year[3].

The uncomfortable part: none of these attacks depend on breaking cryptography. They depend on convincing a human to type twelve words into a box, sign a transaction they do not understand, or believe that the CFO on the video call is actually the CFO. This piece is about which of those failure modes AI has made worse, which defensive layers meaningfully help, and why removing the seed-phrase input surface entirely, the way Veyrnox does, is the structural counter to an AI-scaled attacker rather than another patch on top of one.

What "AI-scaled" actually means for a wallet holder

Phishing has always been a numbers game. Send a million lures, convert a fraction of a percent, cash out. What generative models changed is not the shape of the funnel but every input at the top of it.

Volume. SlashNext's 2024 intelligence report recorded a 703% surge in credential phishing attacks in the second half of the year, with 80% of malicious links classified as zero-day, generated moments before deployment and never seen by signature-based filters[4]. A Chinese-speaking phishing crew tracked by Chainalysis, "Darcula" or the "Smishing Triad", sent as many as 330,000 texts a day using kits estimated to cost under $500[1].

Quality. Lures no longer read as translated. Grammar, tone, and localization match the target. OpenAI's October 2025 threat report describes threat actors integrating AI into existing workflows to rewrite phishing emails, translate lures, and adjust automation on the fly across ChatGPT, Claude and DeepSeek[5]. Anthropic's August 2025 threat report documents a Chinese state-sponsored group that ran 80% to 90% of an intrusion campaign against roughly thirty targets through Claude Code, with human involvement at only four to six decision points[6].

Trust. Impersonation, not novel exploits, is the growth channel. Chainalysis reports that scams using deepfaked images of government officials, financial institutions and crypto platforms grew more than 1,400% in 2025[1]. The Arup case in Hong Kong, reported by Hong Kong police in February 2024, is the canonical example: a finance worker made 15 transfers totalling roughly $25 million after joining a video call on which every other participant, including a lookalike of the UK-based CFO, was AI-generated[7].

Attack economics, before and after

The most honest way to read the shift is per-attempt cost. Below, each cell has a source.

Table 1. Pre-AI vs AI-era crypto phishing economics.
Dimension Pre-AI baseline 2024 to 2025 with generative AI
Phishing kit floor price Custom drainer contracts, hand-built lures, hundreds to low thousands of USD. SMS phishing kits estimated at under $500 per operator; AI-generated ransomware binaries sold for $400 to $1,200 by an operator with no reported technical skill[1][6].
Lure throughput Manual writing and translation; small batches per operator. Up to 330,000 phishing SMS per day per operation; 703% rise in credential phishing in H2 2024; more than 41x increase in malicious email volume since Nov 2022[1][4].
Wallet-drainer take, EVM chains Around $295 million stolen in 2023 (Scam Sniffer). $494 million stolen from about 332,000 addresses in 2024, up 67% YoY; single-victim losses up to $55.5 million[3].
Impersonation volume Occasional executive email fraud, low-fidelity voice spoofing. Deepfaked-official scams up 1,400% YoY in 2025; single incident of $25M stolen via deepfake video call at Arup[1][7].
Yield per operation Baseline for scams with no AI link. Scams with on-chain links to AI vendors averaged $3.2M per operation, roughly 4.5x the non-AI baseline[1].
US crypto complaint losses $5.6 billion reported to FBI IC3 in 2023. $9.3 billion in 2024 across 149,686 complaints, a 66% increase, with $5.8 billion tied to investment (pig butchering) fraud[8].
Reported crypto scam losses by year, 2022 to 2025 Bar chart showing FBI IC3 and Chainalysis reported crypto scam losses growing from $3.31 billion in 2022 to $17 billion in 2025. $0 $5B $10B $15B $20B 2022 2023 2024 2025 $3.31B $5.6B $9.3B $17B Reported crypto scam losses, USD 2022-2024: FBI IC3 annual reports. 2025: Chainalysis 2026 crypto crime preview.
Figure 1. Reported crypto scam losses climbed from $3.31B (2022) to $17B (2025) as generative AI compressed the cost of a convincing lure to near zero[1][8].

The AI-augmented crypto attack stack

A modern crypto phishing operation is a pipeline. Each stage has an AI-enabled acceleration and each stage is a place where a well-designed wallet can, or cannot, break the chain.

1. Reconnaissance and targeting

Attackers scrape public wallet balances, ENS registrations, NFT holdings, DAO forum posts and LinkedIn. Anthropic's report documents adversaries using Claude to correlate leaked data, filter high-value targets and draft personalized outreach[6]. On the crypto side, this feeds pig-butchering operations that Chainalysis measured up 40% in revenue in 2024, with deposit counts up nearly 210%[9].

Veyrnox threat intelligence radar tracking drainer contracts and phishing surfaces
Threat intelligence feeds inside the wallet flag known drainer contracts and lookalike surfaces before you sign.

2. Lookalike surfaces

Fake apps, fake extensions, fake support portals. Check Point Research disclosed a fake "WalletConnect" app that lived on Google Play for over five months from March 2024, was installed more than 10,000 times, and drained around $70,000 by prompting users into token approvals through the MS Drainer kit[10]. Fake Rabby Wallet clones were reported to have persisted on the Apple App Store in early 2024, draining funds after users imported their seed phrase[11]. Twenty additional Android apps have been catalogued impersonating wallets and DEXs including Suiet, PancakeSwap, Raydium and SushiSwap[10].

3. Approval phishing and payload signatures

The signature you sign matters more than the URL you visited. Scam Sniffer's 2024 report found 56.7% of drained value came from EIP-2612 Permit signatures and 31.9% from setOwner calls; both are innocuous-looking off-chain messages that grant token spending or contract ownership[3]. Chainalysis identified over 20,000 approval-phishing victims and $12 million in funds frozen in 2025[1].

Veyrnox approval control room — reviewing token allowances and Permit signatures before signing
An on-device approval control room surfaces Permit and setOwner signatures for what they actually do, not what the dApp claims.

4. Address poisoning and lookalike destinations

The attacker seeds your transaction history with an address whose first and last characters match one you have paid before. In May 2024 a whale sent 1,155 wrapped Bitcoin, about $68 million, to a poisoned lookalike after copying an address from history[12]. A separate Carnegie Mellon study documented 270 million address-poisoning attempts against 17 million wallets on Ethereum and BNB Chain between July 2022 and June 2024, with confirmed losses over $83 million[13]. The generation cost of a lookalike vanity address is trivial once GPU pricing is competitive; the poisoning transaction itself cost the attacker about $0.65 in the WBTC case[12].

5. Model-in-the-loop browser agents

Agentic browsers that read pages, click links, and sign transactions on behalf of the user are a new class of victim. Security researcher Simon Willison has documented "unseeable" prompt injections in screenshots and images that agentic browsers ingest, invisible to the human but fully readable to the model[14]. Brave's security team reported serious prompt-injection vulnerabilities in Perplexity's Comet AI browser[14]. The threat pattern Willison labels the "lethal trifecta" applies directly to any wallet-connected agent: private data access, exposure to untrusted content, and an exfiltration path, together produce silent asset transfers[14].

6. Deepfake social engineering

The Arup case is the anchor, but it is not the only one. Chainalysis groups deepfake-driven impersonation under a category that grew 1,400% in payment volume in 2025[1]. The relevant point for a self-custody user is that any recovery path that ends with a human on a video call authorizing a transfer, "please just read me the codes", is now cheap to break.

AI phishing kit flow with the Veyrnox break-point Left to right flow diagram: reconnaissance to lookalike site to seed or approval capture to drainer contract to laundering. A red break-point marks the seed-input step, which Veyrnox removes. 1. Recon LLM-scored target list 2. Lookalike Cloned dApp, fake wallet app 3. Capture Seed phrase or Permit signature Veyrnox breaks here 4. Drainer Auto-sweep contract 5. Launder Mixers, bridges, DEX hop Every stage 1, 2, 4, 5 is now AI-accelerated. Stage 3 is the pinch point. Remove the seed-input surface and no volume of AI lures produces a signable Permit. The AI phishing pipeline and the Veyrnox break-point
Figure 2. Stages 1, 2, 4 and 5 scale linearly with model capability. Stage 3 depends on a user typing a secret or signing a permit; that is the surface Veyrnox does not expose.

Defensive layers, what each one actually buys you

The defensive market answered with three broad approaches: warn the user, sign in a safer place, and remove the exploitable input. They are not equivalent.

Transaction simulation and warning banners

Blockaid, integrated by default into MetaMask by early 2024, simulates the effect of a pending transaction and warns before signing[15]. Similar tooling ships in Rabby, Pocket Universe, Wallet Guard and Fire. This is useful but partial. Blockaid's own research documents bypass techniques attackers use to evade transaction simulation, and any warning system still requires the user to interpret and refuse. In practice a well-designed drainer UI can override warning fatigue, especially when the attacker controls the surrounding trust context (see the fake WalletConnect app[10]).

Veyrnox pre-sign risk lab — simulating a transaction's effect before signature
Pre-sign transaction simulation translates raw calldata into a plain-English intent so warning banners are refusable, not just decorative.

Hardware wallets

Ledger, Trezor and Keystone move signing off the host device. This defeats a large class of malware but not the human-facing part of AI-scaled attacks: the seed phrase still exists as 12 or 24 recoverable words, and users have been social-engineered into typing that phrase into fake recovery screens for a decade. Trezor's SLIP-39 shamir-sharded recovery is the notable step forward on that front.

MPC and custodial

Multi-party computation wallets and custodial services remove the seed entirely at the cost of trust in an operator or a quorum of servers. They are architecturally strong against phishing but reintroduce the "not your keys" problem, and the account-recovery surface can itself become the AI-attacker's target through customer support impersonation, a pattern well documented in exchange breaches.

Secure-Enclave signing and no user-visible key material

Apple's Secure Enclave is a hardware key manager similar in role to a TPM or HSM. Private keys generated inside the enclave cannot be exported and are bound to that specific chip; hardware attestation lets a relying party verify that a signature came from a specific Secure Enclave rather than from software[16]. Google's Android StrongBox provides an analogous guarantee on supported devices. When a wallet generates its signing keys inside this boundary and never emits a plaintext seed, there is no artefact the user can be phished into typing.

Frameworks that let you compare defenses honestly

NIST published AI 100-2 E2023 in January 2024, formalizing the taxonomy of adversarial machine-learning attacks (evasion, poisoning, privacy)[17]. MITRE ATLAS extends ATT&CK into AI-specific tactics. ENISA's AI threat landscape adds ecosystem-level risk. For a wallet, these frameworks matter for a specific reason: they distinguish between adding a model as another sensor (transaction simulation) and removing an attackable surface from the design (no seed field, hardware-bound signing). Only the second class is stable when the attacker also has models.

Table 2. Defensive stack comparison, common self-custody architectures. Values grade defense strength for the property named in the row — Strong = the attack surface is closed by design; Weak = the surface is fully exposed.
Property Browser extension + seed Hardware wallet + seed MPC / custodial Seed-less, Secure-Enclave (Veyrnox)
AI phishing resistance Weak. Seed field exists; drainers target Permit signatures[3]. Partial. Seed still recoverable; users have been phished into typing it[3]. Solid. No seed, but recovery path is a social-engineering target. Strong. No seed UI to phish; signing is bound to the device.
Deepfake / voice-clone resistance Weak. Support impersonation and "read your code" flows still work. Partial. Physical device confirms, but recovery-seed pressure attacks apply. Limited. Recovery contacts and support can be impersonated[7]. Strong. Recovery is device + Shamir share; no support agent holds keys.
Approval-phishing defense Partial with Blockaid-style warnings; bypassable[15]. Partial. Screen shows raw calldata; interpretation still on the user. Strong. Policy engines can block risky call patterns. Strong. On-device intent verification and policy limits.
Coercion resistance (5-dollar wrench) Weak. One seed unlocks everything. Limited. PIN + hidden wallet feature helps if used. Partial. Quorum policy can slow release. Strong with decoy wallet; PIN reveals decoy under coercion.
Recovery UX Retype 12 words on a new device. Retype 12 or 24 words, or SLIP-39 shares. Password / OAuth / social recovery. Sign in on a new device, combine with cloud Shamir share.
Who holds keys You (browser storage). You (hardware). Quorum or custodian. You (Secure Enclave); Veyrnox never holds a share.

Where AI raises the ceiling vs where design lowers the floor

AI raises the ceiling on what an attacker can do per hour: more lures, better-written lures, cheaper deepfakes, faster reconnaissance. Blockaid, Fire, Wallet Guard and Pocket Universe raise your ceiling on what you can detect at signing time, but they still need you to read a warning and refuse.

What lowers the floor is a design that has no seed field, no support representative with recovery power, no browser-extension attack surface, and a private key that lives inside a Secure Enclave and cannot be exported[16]. AI at the attacker end can generate perfect lures; if the wallet has no artefact the user can be phished into disclosing, and no transaction path that bypasses on-device intent verification, the perfect lure has nowhere to land.

Veyrnox AI advisor chat surface explaining a risky signature request
A defensive AI advisor sits on the user's side of the screen, explaining what the attacker's page is actually asking for.

Why "no seed UI" is not marketing

Every wallet-drainer post-mortem from 2024 that we reviewed reduces to one of three inputs: a seed phrase typed into a phishing page, a Permit or setOwner signature approved on a fake dApp, or a token allowance granted to a malicious contract[3][10]. The generative-AI upgrade is that each of these can now be produced in volume by an operator with almost no technical skill and near-zero unit cost[1][6]. Better filters slow the volume; they do not close the underlying doors.

Veyrnox's design is deliberately narrow. Keys are generated inside the Secure Enclave on iOS (StrongBox on Android when we ship there); Apple documents that private keys generated in the enclave cannot be exported and are bound to that specific chip[16]. There is no 12-word phrase displayed, screenshotted, or typed. Recovery uses Shamir Secret Sharing (see our Shamir explainer) with one share on the device and one in your own iCloud Keychain, so no single stolen backup reconstructs the wallet. A PIN gates the app; under coercion, a duress PIN can reveal a decoy wallet instead of the main balance.

None of this stops an AI-scaled attacker from trying. It changes what the attempt produces. A perfect phishing SMS still arrives. There is nothing on the other end of a Veyrnox tap that will type twelve words into it. A deepfaked support call still gets through. There is no support agent at Veyrnox who can move funds. A malicious dApp still requests a Permit. The transaction is displayed, translated to intent on-device, and gated behind biometric authentication tied to the same enclave that holds the key.

What still requires user vigilance

Design lowers the floor; it does not eliminate the user. Three categories still depend on human judgment:

Address entry. A lookalike destination address will still be signed if the user pastes it. Copy-paste discipline, ENS resolution checks, and address-book use remain the mitigation. Address poisoning was responsible for the $68M WBTC loss in 2024[12].

Investment fraud (pig butchering). No wallet architecture stops a user from voluntarily sending funds to a scammer running a fake trading site. This is the single largest category in the FBI's IC3 numbers: $5.8B of the $9.3B 2024 US crypto losses[8]. Regulatory and platform-level intervention matter more here than wallet design.

Physical coercion. A wrench attack (see our wrench-attack piece) depends on physical access, not phishing. Decoy wallets and threshold recovery help; nothing eliminates the risk.

Bottom line

The 2024 to 2025 data is consistent across independent trackers: attackers with generative models steal more per operation, run more operations, and target more victims than they did before. Chainalysis puts 2025 losses at an estimated $17 billion; the FBI puts US losses in 2024 at $9.3 billion; SlashNext measures phishing volume growth in the hundreds of percent; Scam Sniffer measures the per-victim take rising even as the victim count barely moves[1][3][4][8].

Warning banners and simulation are worth having. Hardware wallets remain a strong choice. Custodial and MPC solutions have their place. But the class of attack that AI most efficiently scales, phishing for a secret or a signature from a user through a lookalike surface, is best answered by not having a secret to phish and by binding signatures to hardware that a lookalike cannot impersonate. That is why Veyrnox is a seed-less, Secure-Enclave-signing self-custody wallet rather than a nicer-looking version of a 2018 mnemonic app. It is the smallest attack surface we could design without giving up custody.

Download Veyrnox — Free on iOS

About the author

Sources

  1. Chainalysis. "2026 Crypto Crime Report preview: Impersonation and AI scams." January 2026. chainalysis.com; coverage: Decrypt, Infosecurity Magazine.
  2. SlashNext. "Mid-Year 2024 State of Phishing Report." May 2024. PR Newswire.
  3. Scam Sniffer. "2024 Web3 Phishing Report." January 2025. drops.scamsniffer.io; BleepingComputer.
  4. SlashNext. "2024 Phishing Intelligence Report: credential phishing up 703% in H2." December 2024. PR Newswire.
  5. OpenAI. "Disrupting malicious uses of AI: October 2025." openai.com; report PDF: cdn.openai.com.
  6. Anthropic. "Detecting and countering misuse of AI: August 2025." anthropic.com; "Disrupting the first reported AI-orchestrated cyber espionage campaign." anthropic.com.
  7. Reuters / SCMP via CoverLink: Arup $25M Hong Kong deepfake CFO scam, reported February 2024. CoverLink; AI Incident Database 634.
  8. FBI Internet Crime Complaint Center (IC3). "2024 Internet Crime Report." April 2025. fbi.gov; analysis: TRM Labs.
  9. Chainalysis. "2024 pig butchering crypto scam revenue grows 40% YoY." chainalysis.com.
  10. Check Point Research. "Wallet Scam: A Case Study in Crypto Drainer Tactics." September 2024. research.checkpoint.com; Infosecurity Magazine.
  11. FXStreet. "Apple yet to remove fake Rabby Wallet app as users report being drained." February 2024. fxstreet.com.
  12. The Block. "Crypto trader loses $68M in address poisoning attack." May 2024. theblock.co; Chainalysis: Anatomy of an address poisoning scam.
  13. Tsuchiya et al., "Blockchain Address Poisoning," USENIX Security 2025. usenix.org.
  14. Simon Willison. "Unseeable prompt injections in screenshots." October 2025. simonwillison.net; "New prompt injection papers: Agents Rule of Two." simonw.substack.com.
  15. Blockaid. "Transaction Security" and "Bypasses: How Attackers Evade Transaction Simulation." blockaid.io; MetaMask integration: Decrypt.
  16. Apple. "The Secure Enclave" and "Attestation process security," Apple Platform Security Guide. support.apple.com; Attestation process security.
  17. Vassilev, Oprea, Fordyce, Anderson. "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations." NIST AI 100-2 E2023, January 2024. csrc.nist.gov.
  18. Group-IB. "Inferno Drainer: Scam-as-a-Service." group-ib.com; The Hacker News: Inferno drained $87M from 137,000 victims.
  19. SlowMist. "Analysis of the 2024 Blockchain Security and Anti-Money Laundering Annual Report." slowmist.medium.com.
  20. CNBC coverage of Chainalysis 2024 estimate: "Crypto scams likely hit a new record in 2024, driven by pig butchering and AI." February 2025. cnbc.com.
  21. MITRE ATLAS: Adversarial Threat Landscape for AI Systems. atlas.mitre.org.
  22. ENISA. "AI Threat Landscape." enisa.europa.eu.