Articles
Crypto Market Analysis

New AI cybercrime tool targets crypto, bank KYC systems via deepfakes

User Image

Por Anónimo

Creado April 06, 2026|2 minutos de lectura
Main Image

A darknet threat actor is selling new fraud kit to trick KYC identity verification systems on financial platforms via AI-generated deepfakes and real-time voice altering.

A threat actor known as “Jinkusu” is allegedly selling cybercrime tools designed to bypass Know Your Customer (KYC) checks at banks and crypto platforms.

The tool uses deepfakes and voice manipulation to trick KYC verification systems on finance platforms, cybercrime tracker Dark Web Informer wrote in a Sunday X post.

Cybersecurity company Vecert Analyzer added that Jinkusu uses AI for real-time face swaps via InsightFace for “fluid gesture transfers,” along with voice modulation to evade biometrics.

The emergence of deepfake tools is a “wake-up call” for the industry, as it highlights the shortcomings of KYC verification systems, according to Deddy Lavid, CEO of blockchain security platform Cyvers.

“As AI lowers the barriers to synthetic identity fraud, the front door will always remain vulnerable,” Lavid told Cointelegraph, urging platforms to adopt a layered security approach combining identity verification with real-time AI monitoring.

Binance chief security officer Jimmy Su highlighted the growing threat of deepfake technology back in May 2023.

He warned that improving AI algorithms will be able to crack KYC identity systems by using a single picture of the victim.

Related: Revolut confirms ex-employee threatened to leak KYC data for crypto ransom

The new fraud kit also enables scammers to run romance scams, such as “pig butchering,” with no technical knowledge.

Crypto investors lost $5.5 billion to 200,000 flagged pig butchering cases in 2024.

The author of the new fraud package, Jinkusu, is suspected to be the same threat actor who released the phishing kit Starkiller in February 2026.

Unlike traditional, HTML-based phishing kits, Starkiller creates a real-time reverse proxy by creating a headless Chrome browser inside a Docker container, loading the genuine login page of the target brand and relaying all user input, including login and passwords, to the threat actor, explained cybersecurity platform Abnormal, in a Feb. 19 report.

While losses to crypto phishing attacks fell 83% in 2025, malicious crypto wallet drainer scripts remained active and new malware continued to emerge, Scam Sniffer said in a January report.

Magazine: Everybody hates GPT-5, AI shows social media can’t be fixed

Source: CoinTelegraph


Otros artículos publicados recientemente

Bitcoin flat near $64,000 as oil hits a one-month high and Kimi AI selloff lingers
Bitcoin flat near $64,000 as oil hits a one-month high and Kimi AI selloff lingers

Bitcoin

Brent jumped almost 4% on escalating U.S.-Iran strikes, while Asian chip stocks stayed under pressur...

Bitcoin ETFs see new money again, but inflows remain ‘peanuts’ relative to the recent exodus
Bitcoin ETFs see new money again, but inflows remain ‘peanuts’ relative to the recent exodus

Bitcoin

Bitcoin ETFs have attracted $273 million in new inflows in two weeks, but the total is barely enough...

Will the US get CLARITY this week? Bitcoin’s new $80K target: Hodler’s Digest, July 19
Will the US get CLARITY this week? Bitcoin’s new $80K target: Hodler’s Digest, July 19

Bitcoin

The fate of the CLARITY Act hinges on Trump’s ethics, so the odds aren’t looking great. Predicti...

South Korea probed 40 cases of crypto manipulation over 2 years
South Korea probed 40 cases of crypto manipulation over 2 years

Crypto Market Analysis

Financial Services Commission Chair Lee Eog-won posted the figures on the second anniversary of the ...

Japanese logistics company eyes JPYC stablecoin to pay drivers
Japanese logistics company eyes JPYC stablecoin to pay drivers

Crypto Market Analysis

The planned rollout would let thousands of transportation contractors receive digital yen payments m...

Allbridge pauses cross-chain bridge after $1.65M exploit
Allbridge pauses cross-chain bridge after $1.65M exploit

Crypto Market Analysis

The attacker allegedly used a flash loan and rapid swaps to manipulate the bridge’s stablecoin exc...