Language

08 Oct 2026 in Identity fraud

Crypto KYC vs. Other Sectors: What Research Reveals About AI Fraud Readiness

Henry Patishman

Executive VP, Identity Verification Solutions

In brief: AI-assisted activity makes decision reconstruction more important because a suspicious signal rarely explains on its own what actually happened during verification.

And when a KYC record preserves enough context to reconstruct why a customer was approved or rejected, teams can distinguish a document problem from a holder or capture problem — and use confirmed failures to improve future checks. That is where traceability becomes part of the verification process itself.

In Regula’s recent research, 44% of Crypto respondents reported participation of AI automation in identity checks (confirmed through later case review), compared with 31% of peers. 

That does not necessarily mean Crypto faces more automated activity; rather it speaks to how well teams are able to investigate the chain of events post-identity verification — and detect this activity.

At the same time, even in the age of AI, document fraud remains the top identity threat for crypto companies. It was selected by 44% of respondents, ahead of deepfake impersonation at 37% in second place.

In this article, we look at what those findings mean for crypto KYC: verifying documents and their holders, investigating suspected manipulation, and using decision records to test improvements to future checks.

Regula's report on Crypto KYC - The New Shape of Identity Threats

The research covered 850 fraud and financial-crime decision-makers. We compare 102 Crypto respondents with 748 respondents from Banking, Financial Services, Gaming and Gambling, Government, and Telecommunications. Crypto is excluded from every peer calculation.

What does document fraud mean for Crypto KYC?

Regula's report on Crypto KYC - Document fraud

KEY FINDING | Document fraud concern — 44 vs. 34

Respondents selected their two greatest identity threats from external actors. Counterfeit, altered, or stolen identity documents were selected by 45 of 102 Crypto respondents and 258 of 748 respondents in the other sectors. Dividing each count by its group base gives 44 vs. 34 after rounding.

What the finding tells us

Document fraud leads the Crypto concern list, ahead of deepfake or AI-generated impersonation at 37%, stolen identity media at 35%, and AI agents or automated systems at 27%. Crypto also records the highest observed document-fraud response among the six industries, although Government is very close.

It’s worth paying attention to the form of the answer, as “counterfeit, altered, or stolen documents” brings several very different identity problems under one heading.

A counterfeit document is false evidence made to look like a document issued by a legitimate authority. With an altered document, the underlying document may be genuine, but somebody has changed information or other elements (e.g., a photo) afterward. In both cases, the immediate question is document authenticity.

A stolen genuine document creates a different problem. The layout can be correct, its security features genuine, its data internally consistent, and its RFID chip valid. Document authentication may therefore succeed exactly as intended. The unresolved question is whether the person presenting it has any right to use it.

That is also where AI can become part of an otherwise traditional document-fraud attempt. Generated, manipulated, or prerecorded biometric media may help an impostor resemble the legitimate holder during remote verification.

So the 44% result does not suggest that Crypto somehow failed to move on from counterfeiting. The document remains a strong identity anchor, while fraud can target either the document itself or the connection between that document and its rightful holder.

What this means for crypto KYC

It is therefore important to treat document authenticity and holder verification as connected parts of the same identity decision, while still asking each check to prove something specific.

Document authentication goes much further than reading the name, date of birth, and document number correctly. A strong check identifies the document type and version, examines available security features, and compares information stored in different document elements. A counterfeit can contain perfectly readable personal data, so accurate extraction alone says little about authenticity.

When an electronic document and the user’s device support it, NFC verification adds particularly strong issuer-backed evidence. Reading the RFID chip and checking cryptographically signed data can provide issuer-backed evidence that is unavailable from an image alone.

But that is still only the document checked. Next comes the holder.

Now is the time to establish whether the person in the session is the person the document belongs to. Face matching contributes to that comparison, while liveness and capture-integrity checks help establish whether a real person is present and whether the biometric media reached the verifier through the expected capture source.

Subscribe

Subscribe to receive a bi-weekly blog digest from Regula

What turns suspected AI activity into a confirmed case?

Regula's report on Crypto KYC - AI Activity

KEY FINDING | Confirmed AI-assisted or automated cases — 44 vs. 31

Respondents selected up to two descriptions of their organization’s experience with AI-assisted or automated actors interacting with identity processes during the previous 12 months. Cases confirmed through investigation or post-incident review were selected by 45 of 102 Crypto respondents and 231 of 748 respondents in the other sectors. Dividing each count by its group base gives 44 vs. 31 after rounding.

What the finding tells us

Crypto has the highest observed confirmed-case response among all six industries. 

In our context, “confirmed” means: AI-assisted or automated actors attempted to interact with identity processes — and the team confirmed that fact through investigation or post-incident review.

That does not mean 44% of Crypto respondents reported a successful AI fraud attack. Nor does it mean that every confirmed case involved a deepfake. The survey answer covers AI-assisted or automated activity, including: 

  • A script or automated tool interacting with an identity verification flow

  • An AI assistant or agent carrying out parts of the interaction on a user’s behalf

  • Automated behavior detected in the flow even when the organization cannot confidently attribute it to AI

And this result becomes more interesting once we look at the other answers to the same survey question.

Reported experience Crypto Other sectors
Confirmed through investigation or post-incident review 44 31
Uncertain automated or scripted behavior 34 35
Suspected synthetic or AI-generated evidence without enough proof 34 35
Attempts blocked or contained 20 21

 

Crypto and its peers look remarkably similar on three of the four answers shown here. Still, the pattern does not support a story in which Crypto respondents report more AI-related experience on every measure.

So why do more Crypto respondents report confirmed AI activity cases? We honestly cannot say for sure.

Crypto organizations may encounter a different mix of automated abuse. They may investigate suspicious identity events more deeply. They may also use different thresholds before calling a case confirmed. Most likely, several factors contribute.

Crypto’s strong traceability result, which we come to next, makes deeper investigative capability one plausible part of that explanation. The available data does not establish that relationship within the Crypto sample itself, so it should remain exactly that: a plausible explanation.

What this means for crypto KYC

That means the original session needs to leave enough usable evidence behind for an investigation to revisit it. Depending on the organization’s retention rules, that may include document verification, biometric results, capture-integrity findings, device and session data, the rule and model versions active at the time, and any reviewer actions.

A broad label such as “AI fraud” is rarely enough to tell the team what needs changing. The investigation needs to establish what actually happened during the identity check and how the verification process handled it.

For example, a synthetic-media alert may justify investigating whether the submitted face was generated or manipulated. A virtual-camera signal may justify checking whether the expected camera feed was replaced. Neither signal, on its own, establishes the full incident.

Once the failure is established, it points back to a much more specific part of the verification process:

  • An altered document was accepted: Review the document-authentication findings and whether the decision logic ignored an authenticity warning.

  • A genuine ID was accepted for an impostor: Review the document-holder comparison, biometric evidence, and any reviewer decision that allowed the case through.

  • Prepared media replaced the intended camera input: Review the capture-integrity controls and whether the substitution was detected and acted on.

  • The evidence remains inconclusive: Keep the case classified as suspected instead of turning uncertainty into a confirmed fraud finding.

WORTH KNOWING | Deepfakes and camera injection are different problems

A deepfake concerns the media itself. Camera injection concerns the route by which media reaches the verification system, and the injected material can include genuine prerecorded footage. Our guide to video injection attacks explains why capture integrity needs its own checks.

How can traceability improve the next identity decision?

Regula's report on Crypto KYC - Decision traceability

KEY FINDING | Fully reconstructable identity decisions — 62 vs. 49

Respondents described how well their organization can reconstruct an identity decision after it has been made. 63 of 102 Crypto respondents selected the strongest answer: all contributing systems, evidence, and decision logic can be traced. 365 of 748 respondents in the other sectors selected the same answer. Dividing each count by its group base gives 62 vs. 49 after rounding.

What the finding tells us

This is Crypto’s clearest reported capability advantage in the research. More specifically, Crypto has the highest observed share among all six industries selecting the strongest answer on full decision reconstruction.

Still, it gives the confirmed-AI result some useful context. In the full survey sample, confirmed AI-assisted or automated cases are reported by 36% of respondents with fully reconstructable decisions, compared with 25% of those with limited or unavailable reconstruction.

That does not prove that stronger traceability caused Crypto’s higher confirmed-case response. The comparison covers the full sample, not Crypto alone. One possible explanation is that when investigators can recover the evidence, rules, system findings, and reviewer actions behind a decision, they have more information available for post-incident analysis.

What this means for crypto KYC

Good traceability means the team can learn from errors found in the decision history and improve the verification process.

For example, a face comparison may succeed while the session contains strong evidence of camera substitution. In that case, the face-matching technology may have done exactly what it was asked to do; the problem can lie in the decision logic, which allowed a positive comparison to outweigh an untrusted capture source.

Once the cause is understood, it is important for the finding to make its way back into the verification process. The team can propose a rule change, test it against similar fraud attempts and legitimate customers, and only then apply it to future checks.

The cycle can look like this:

Identified failure → Proposed rule change → Testing → New rule rollout → Next verification

The testing step deserves some attention. A stricter rule may stop the fraud pattern it was designed for and still send too many legitimate customers into retries or manual review. So the investigation becomes more useful when the organization understands both sides of the change.

The same logic applies to human review. If reviewers repeatedly clear document-holder mismatches because the document itself authenticated correctly, the case history points toward the review policy rather than the document check.

That is where reconstruction starts earning its value: the organization can see what failed, change the relevant part, and test whether the next decision is better.

What makes identity evidence audit-ready?

Regula's report on Crypto KYC - Audit-ready evidence

KEY FINDING | External explanation requests — 87 vs. 81; audit-grade evidence — 70 vs. 68

Respondents reported whether their organization had been required to explain an identity-related decision to a regulator, court, or external auditor. 89 of 102 Crypto respondents and 606 of 748 respondents in the other sectors had received such a request, producing 87 vs. 81 after rounding. Among those respondents, 62 of 89 in Crypto and 411 of 606 among peers reported being able to provide audit-grade evidence, producing 70 vs. 68.

What the finding tells us

Requests to explain identity-related decisions to external parties are common among crypto respondents. 87% of respondents say their organization has had to explain an identity-related decision to a regulator, court, or external auditor. That is six percentage points higher than the pooled result for the other sectors.

At the same time, though, among respondents who had already faced an external request, reported audit-grade evidence is almost identical: 70 vs. 68.

Now, those figures are not proof that Crypto companies are losing information somewhere between investigation and audit. The questions use different respondent bases, and respondents assessed their own capabilities.

They do, however, describe two different jobs.

An internal investigator can often open several systems, recognize an internal result code, find a linked attachment, or ask the analyst who handled the case what happened. A regulator, court, or external auditor does not automatically have that context. The organization has to provide enough of it for somebody outside the original decision to follow the reasoning.

For example, “approved after manual review” tells an external reviewer very little. A record should be able to show what evidence was available, what the automated checks reported, which rule applied, whether somebody overrode the result, why they did so, and when each step happened.

What this means for crypto KYC

It is important for the case record to preserve three things:

  • Evidence: The submitted material and verification findings available when the decision was made

  • Reasoning: The applicable rules and any reviewer intervention, including the reason for an exception

  • History: The final decision and later changes, with timestamps that preserve their order

Later reassessment also needs its own place in that history. If old evidence is processed again with a newer model or different rule set, the new finding can be useful, but it should remain clear that the organization did not have that information when it made the original decision.

Making the next verification better than the last

Taken together, the findings do not point to one missing check. They show why an identity decision can depend on several kinds of evidence at once: 

  • whether the document is genuine, 

  • whether the person is its rightful holder, 

  • whether the biometric media came from a trustworthy live capture, 

  • how the system resolved those findings,

  • what remains available when somebody later asks why the decision was made.

Crypto already leads the surveyed industries in full decision reconstruction. The next opportunity is to use that visibility as a feedback loop. When an investigation reveals a recurring failure, teams can adjust the relevant workflow, test the change against both fraud attempts and legitimate customers, and apply it to comparable future cases.

There is a clear business reason for doing so: 48% of Crypto respondents associate incorrect identity verification results with financial loss, compared with 38% in the other sectors. 

Regula IDV Platform supports this approach by connecting onboarding, re-verification, customer history, case review, decision logic, and audit evidence across the identity lifecycle. This allows organizations to strengthen verification when risk or uncertainty increases while preserving the context needed to explain each decision later.

For Crypto, mature KYC means connecting identity evidence into a coherent decision, learning from failures, and preserving the context needed to explain why that decision was made.

Explore Regula IDV Platform

See how you can verify and manage customer identities with a single, all-in-one solution.

More findings from Regula’s research

The full Regula survey report contains the wider industry findings.

To discuss document authentication, biometric verification, or identity lifecycle management, talk to Regula’s experts.

FAQs

How can crypto exchanges detect AI-assisted identity fraud during KYC?

There is rarely one signal that proves AI involvement. Teams need to combine document, biometric, liveness, capture-integrity, device, and session evidence, then investigate how those signals behaved together in the actual verification.

Is document verification alone enough for crypto KYC?

No. A genuine passport can authenticate correctly and still be presented by the wrong person, so document authenticity needs to be connected with holder verification, biometric checks, and trusted capture.

How can a crypto exchange detect someone using a stolen genuine ID?

The document check may not fail at all: the security features, personal data, and RFID chip can all be genuine. The verification process therefore also needs to establish whether the applicant is the rightful holder of that document.

What is decision traceability in crypto KYC?

Decision traceability means being able to reconstruct what evidence was available, what individual checks reported, which rules were applied, and whether a reviewer changed the outcome. That becomes especially useful when a suspicious account needs to be investigated months after onboarding.

What KYC evidence should a crypto company keep for an audit?

The useful record is not just an approval or rejection. It should connect the evidence available at the time, the rules and reviewer reasoning behind the decision, and a history showing what happened later without rewriting the original record.

Are deepfakes and camera injection the same KYC threat?

No. A deepfake describes the media itself, while camera injection describes how media was substituted into the capture process; the injected footage can even be completely genuine and prerecorded.

What should a crypto company change after a KYC fraud incident?

First establish exactly what failed. An altered document, a genuine ID used by an impostor, and manipulated camera input point to different controls, so the response should target the specific failure and then be tested against both fraud attempts and legitimate customers before rollout.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules