Deepfakes to Bypass KYC - Does It Work?
Deepfake fraud accounts for 1 in 5 biometric fraud cases. Learn how AI bypasses KYC checks and what you can do to protect your crypto accounts.
Large language models were supposed to be used for boring, routine tasks—jobs that take up hours of your week but provide no meaning to your life. In fact, they have ended up learning to mimic your personality. At present, they are being employed in order to circumvent KYC restrictions, log into your exchange account, and convince a verification system that a fake person is acceptable for holding money.
The situation is simple in that all the material you give when checking your identity is digital information. This consists of a photograph of your face, a scanned copy of your ID, and a video of you blinking as told. All of this is just data travelling over the internet. If the data can be forged accurately enough, the machine on the other end will accept it just as easily. There is no human taking part in the process; instead, what happens is that one machine detects patterns and another machine is able to produce those same patterns. One artificial intelligence is therefore deceiving another, your money and your identity being at the centre of the issue.
It's not merely a theoretical concern; a global review of over one billion identity verification events reveals that deepfake fraud makes up one in every five cases of biometric fraud. The number of attempts using deepfake selfies increased by 58% in 2025 alone. There was a 783% rise in injection attacks in 2024, these being cases where fake video is inserted directly into the camera feed. The technology required to carry out such actions costs about twenty dollars and takes thirty minutes. Fully synthetic identities, which are able to pass KYC checks, can be bought from dark web marketplaces for two hundred dollars.
The system continues to work because the systems were never intended to detect this kind of thing; they were designed to recognise photocopies, screenshots, and instances in which someone used another person's identity. It was not the intention of the systems to pick up the case of a machine-generated face which had never actually existed together with a machine-generated ID that had never been issued and which was submitted by a person using real-time face-swap software in order to bypass the liveness check which was meant to confirm that they were human.
When Machines Lie to Machines
The fraud isn't confined to crypto exchanges, even though crypto accounts for 88% of all detected deepfake fraud worldwide; it also takes place at banks, online retailers, and fintech platforms, in any case where identity verification is automated and trust is assumed. The method employed to verify you looks for certain signs: does the face in the selfie match the face on the ID? Does the person blink when told to? Does the document have the correct fonts, holograms, and security features? All of these checks can now be bypassed not through sophisticated hacking but by using prompts input into an image generator and thirty minutes of video editing.
Kyle Holder had all of her retirement savings of three hundred thousand dollars stolen within three months due to a fraud involving AI manipulation.

The IRS officials in charge of her case said that nothing remained. The scam did not make use of deepfake KYC directly, but it was based on the same principle — that of AI-generated trust. It included fake trading platforms, fabricated profits, deepfake videos of executives, and cloned voices. When she tried to withdraw her money, the platform disappeared.
The fraudsters who stole her savings had no need to break in since it was enough for them to appear genuine for a sufficient length of time so that she came to believe the lie.
What Gets Faked and How
The visible aspect is deepfakes, but this does not represent the entire situation. Fraudsters are using artificial intelligence to produce fake documents, signatures, transaction histories, account balances, verification emails, customer support exchanges, and even real-time video calls. They create synthetic identities by combining stolen real data with made-up information—such as a genuine Social Security number, a false name, an AI-generated face, and a real address. Although each component of the identity passes individual database checks, there is no single person who actually underlies that identity.
Synthetic identity fraud, which is of this type, has taken on the role of the main form of financial crime in 2025 since it brings together the credibility of genuine data with the flexibility of complete fabrication. The individual applying for an account is not pretending to be some other person; rather, they are making up a new person, one who appears legitimate to all the automated systems used to check them, even though this person exists only as a set of data points that just happen to match.
An audit carried out on sixteen commercial AI image generators in 2026 discovered that of seventy-five attempts sixty-nine resulted in something that resembled an ID, and five of the models produced images which appeared to be genuine government documents. These were not elaborate forgeries that needed inside knowledge of security printing. They were images generated by publicly available tools, in response to prompts from people who had never set foot in a passport office.
The documents appear to be genuine since the AI was trained using real documents. The faces appear realistic because the AI was trained on actual faces. The system is not making guesses; rather, it is reconstructing what it has learned, and what it has learned is persuasive enough to deceive both machines and people.
Faking the Human Test
Liveness detection was meant to deal with this problem. The concept was straightforward: get the user to carry out an action which a photograph or a video cannot replicate. This could involve blinking, turning your head, smiling, or following a moving object with your eyes. If you can perform these actions in real time, then you must be a real person using a real phone, not somebody who is playing back a recording.
The issue is that liveness detection takes it for granted that the video feed is genuine; it assumes the camera is showing exactly what is in front of it. However, modern deepfake technologies don't need to trick the camera since they can inject fake video directly into the stream, completely avoiding the use of the lens. The software records the verification challenge, produces a synthetic reply in real time, and then sends that reply back to the system as though it had come from a camera. The liveness check therefore detects the person blinking when asked to, turning their head and smiling; it has no means of knowing that the person isn't actually there.
That is the reason why there was a 783% increase in injection attacks over a single year — the defence had been designed for the wrong type of threat; it was intended to detect replay attacks and printed photos, not real-time synthesis.

A number of platforms have switched to passive liveness detection, a method which examines the video without requiring the user to perform any action. It detects micro-expressions, blood flow beneath the skin, shadows and reflections that act as if they are in three dimensions. Although this approach is more effective it is by no means perfect. Fraudsters have already been training their own models on the signs that passive liveness detection looks for, eliminating the telltale features, adding noise that resembles genuine camera grain, and introducing the minor flaws which give something a human appearance.
A study conducted in 2026 discovered that just 0.1% of the participants were able to reliably tell the real content apart from content that had been generated by AI. Since humans cannot do so and automated systems are being trained to detect the patterns that AI is at the same time being trained to produce, the issue is not whether the defenses will succeed. The issue is after how long they will cease to do so.
What This Means for You
If you do hold crypto and have verified your identity on an exchange, having at some point submitted a selfie together with a photo ID to prove that you are the person you claim to be, the same system which was used to verify you can be deceived. This means that another person could set up a synthetic identity, go through the same verification processes that you did, open an account and then use that account to transfer money, launder funds, or take someone else's assets with them.
That also means your identity can be used without your knowledge. Nowadays, a fraudster no longer needs to steal your whole identity; all they have to do is obtain a photo of your face, something which is likely already available if you've ever posted on social media. They then use that photo with a face-swap tool to create a deepfake video of you carrying out a liveness check, combine it with a fake ID that includes your face but has a slightly changed name, and submit it to a platform which doesn't have strong deepfake detection capabilities. Once the platform approves the application, they will have an account that looks like you, sounds like you, and is able to pass the verification procedures that are meant to prove that you are who you say you are.
It's difficult to understand the extent of this problem until you look at the figures. In 2025 Americans suffered losses of over eleven billion dollars due to cryptocurrency fraud, which represents more than half of all the money lost from internet crime reported to the FBI. Worldwide, crypto scams earned at least fourteen billion dollars on-chain in 2025, an increase from under ten billion dollars in 2024. In the first quarter of 2026 alone, AI deepfakes caused losses amounting to 577 million dollars, and are now behind 40% of high-value crypto frauds.

The fraudsters aren't acting on their own; they are part of an organized scheme. An investigation carried out in 2025 revealed a fraud ecosystem worth 187 million dollars which extended across both Australia and the United States, relying on fake trading platforms, deepfake endorsements by celebrities, and trust that had been manipulated using AI. The operation took over popular YouTube channels, used deepfake audio and video to imitate the official communications of genuine crypto companies, and offered fake airdrops to people who sent money first. Thousands of individuals were deceived by it.
Protecting Yourself in a Deepfake World
While you can't prevent someone from faking your face, you can make it more difficult for them to use that fake to steal from you. Your first line of defence is not a technical one; it's behavioural.
1. Make sure that all the available security features are enabled on any accounts which contain money or other sensitive information, such as two-factor authentication, biometric login, a withdrawal whitelist of addresses, and email confirmations for each sensitive action. Each of these security measures makes it more difficult for someone else to run your account even if they manage to bypass the KYC process.
2. Whenever you receive a video, voice message, or other form of communication from someone asking you to send them money or to provide your credentials, treat it as fake until you have proof to the contrary. Crypto impersonation scams increased by 1,400% in 2025. If the person appearing to be your CEO, a friend, or a celebrity is contacting you about an investment opportunity, check the matter through an independent channel before taking any action.
3. It is never necessary to send cryptocurrency in order to claim an airdrop, unlock an account, or prove your identity; genuine platforms will never ask you to pay in order to receive money. This is the way in which every fake airdrop scam is structured, and people still fall for it because the videos and messages appear to be real.
4. Make use of platforms that have a strong anti-fraud system in place. Since not all exchanges or services have put themselves into deepfake detection, those that have will publicise it, as this has now become a competitive advantage. You should look for multi-modal verification, behavioural analysis, session-level integrity controls, and advanced liveness detection that goes beyond the basic blink-and-turn tests.
5. Make sure that the service makes use of 3D liveness detection or passive biometric analysis since these methods are more difficult to fool than active liveness checks because they check more than just whether you can carry out the instructions; they examine depth, micro-expressions, and physiological signals which synthetic video finds it hard to replicate convincingly.
6. Think of your face as a password and keep the number of high-resolution photos of yourself that are available publicly to a minimum. Fraudsters collect faces from social media sites in order to use them in deepfakes. The more high-resolution images of you that are online, the easier it is to create a convincing fake.
7. When you are transferring a large amount of money, in particular with respect to big USDT transfers or other high-value crypto transactions, you should use services which allow you to check the costs and the routes before proceeding. Fraudsters frequently take advantage of the urgency and the confusion about fees, leading victims to send the funds to the wrong address or to pay much more than is necessary. Genuine platforms, on the other hand, enable you to work out the costs in advance, verify the addresses of the recipients, and check all the details before the transaction is carried out.
The industry is reacting, but at a slow pace. Nowadays, enhanced verification processes involve multi-modal checks which together examine documents, facial biometrics, voice patterns, and behavioural signals. Certain platforms are developing evidence packages at the session level that timestamp and cryptographically seal each frame of a verification session, thus producing a forensic record which can show if the session was real or had been injected. A number of these platforms are also incorporating third-party trust service providers who act as neutral witnesses to the verification process and thereby make it much more difficult for a fraudster to forge their way through without leaving a trace.
However, these safeguards do not apply to all platforms. A great many of them still rely on the document-plus-selfie method, a technique which has been shown to be failing since 2024. The platforms have not upgraded their systems since the expense of detecting deepfakes is high and the effects of fraud are usually shouldered by the users rather than by the platform.
The Cost of a World Where Nothing Is Provably Real
The real issue is not one of technology but rather one of a fundamental nature. We are now entering a phase in which it has become far from easy to prove that you are who you claim to be. The systems meant to check people's identities are being overcome by tools that cost less than a meal and take less time than a commute. Trust, which had already been weak in the online environment, is now breaking down because of content that appears real, sounds real, and behaves in a real way even though it isn't.

It doesn't indicate that KYC has ended, merely that KYC needs to move beyond the idea that a selfie and an ID serve as proof of anything. The platforms that will survive this change will be those which regard verification as a continuous process rather than a single checkpoint; they will build up confidence over time by making use of behavioural signals, transaction patterns, device fingerprints, and frequent re-authentication rather than depending on a single instance of proof which can be forged.
This implies that users now have to take on the task of verification themselves. It is no longer something you can take for granted if a platform has approved a particular person then that person is genuine. Similarly, you can no longer assume that because a video appears realistic it actually is. You must verify it on your own by means of other channels and by using tools and methods which are more difficult to forge.
The financial consequences of getting this wrong are not the only ones; there is also a gradual undermining of the fundamental idea that the person on the other side of a transaction is the person they say they are. After that belief has disappeared, every interaction has to be met with suspicion and every transaction has to be verified independently, so that trust can no longer be given freely.
Deepfakes do manage to get around KYC procedures. It is not true in all cases or on all platforms, but frequently enough for the figures on fraud to reach billions. The issue isn't whether this will continue to happen. The issue is whether the defensive measures will be able to keep up before the cost of taking no action becomes too high to ignore.
Fraud and confusion come together in the case of transaction costs. The fees you pay when transferring money on-chain, particularly in the case of USDT transactions on networks such as TRON, can vary greatly according to the way in which the transfer is structured. Scammers take advantage of this by setting up fake platforms that display higher fees and keep the difference for themselves. They also send phishing messages saying that you have to pay an urgent blockchain fee in order to release your funds, even though such a fee does not actually exist.
If you understand how much a transfer should really cost, you can avoid being cheated by such scams. For instance, on TRON each transfer of USDT uses up some Energy and Bandwidth. When you don't have sufficient amounts of these resources, the network sells your TRX to meet the cost, and this can be costly. A transfer to an address which already contains USDT uses less Energy than one to an empty address since the network has to set up the token balance. By knowing this beforehand, you can tell when someone is lying about the amount you owe.

Tools such as the Netts USDT Transfer Calculator enable you to find out precisely how much Energy and Bandwidth a particular transfer will need and whether it would be cheaper to rent Energy than to use up TRX. For people who make frequent USDT transfers or who move large amounts of funds, this makes the difference between paying the lowest possible USDT fees and ending up paying twice or more than you should. It also provides a means of checking that the fee someone is asking you for is genuine and not a made-up amount intended to steal a little extra from you each time. Although transparent cost calculators don't eliminate fraud, they take away one of the simplest methods by which fraudsters can take money from people who don't know what a blockchain transaction should cost.