AI Scams, Coin Surge…KuCoin Pushes New Security Standard

Cryptocurrency scammers can now automate conversations that trick victims into sending money. According to a TRM Labs report published in August, criminal adoption of artificial intelligence (AI) has increased by 40% over the past year, with fraudsters making the most extensive use of this technology.
Exchanges also leverage AI for detecting scams, monitoring market conditions, and identifying suspicious activity. However, this creates a dual challenge in security: the same technology used to detect threats can help criminals make those threats more scalable and persuasive.
This is why ISO/IEC 42001:2023 is important. It's an international standard for AI management systems. KuCoin is among the first digital asset platforms to obtain this certification.
While users may wonder why they should care about ISO 42001, it ensures that exchanges have the capability to review and correct AI-driven decisions that might mistakenly flag legitimate transactions or provide unreliable responses to help requests.
AI is spreading in cryptocurrency crime. According to TRM's AI-criminal adoption index, the score rose from 28 out of 100 in 2024 to an estimated 54 by 2026. The index measures how widely criminals use AI, with fraud being classified as 'mature' stage.
TRM reported over 200 cryptocurrency hacks during the first half of 2026, more than double the previous year's total. While only 4% of incidents accounted for 75% of total losses, most major breaches were due to infrastructure vulnerabilities.
This concentration of loss means access control remains central to exchange security. AI monitoring also depends on the integrity of observed systems and accounts that can modify them.
European AI regulations have limitations. While the EU's regulatory framework includes some requirements for AI oversight, their application varies based on system use cases. The Digital Omnibus Act, which came into effect July 27, defers high-risk system obligations related to Annex III until December 2, 2027.
Annex III covers credit rating systems but explicitly excludes financial fraud detection, meaning exchange trading monitoring software isn't automatically subject to the same high-risk requirements. This classification must be evaluated based on specific use cases.
Other obligations still apply. Since August 2, AI transparency regulations require platforms providing user-interaction systems to disclose when AI is involved in interactions—except when it's clearly visible. This applies to customer service chatbots as well.
Self-certification can provide exchanges with a framework for self-regulating their AI systems, but cannot replace relevant financial regulations or data protection obligations.
ISO/IEC 42001 implements these principles within a management system framework. The standard requires organizations to establish, implement, maintain, and continuously improve policies and procedures related to AI use.
KuCoin states its certification applies to both the AI management system and supporting organizational functions. Officially, fraud detection and market monitoring are explicitly listed as areas where AI is used across digital finance.
The certification includes external assurances such as SOC 2 Type II reports, which assess control measures over a period. Other standards focus on information security or data privacy, while business continuity certifications relate to crisis preparedness.
KuCoin's ISO 42001 covers five key areas of assurance: it focuses on how an organization manages AI throughout its lifecycle, including accountability and performance monitoring. The standard provides auditors with criteria for evaluating these processes.
Organizations must clearly define the purpose of AI use and consider potential impacts on people. Since model updates may alter behavior from initial assessments, change review procedures are required.
This certification is part of KuCoin's long-term 20 billion USD Trust Project launched in 2025, aimed at strengthening security, compliance, transparency, user protection, and operational resilience.
The significance of ISO/IEC 42001 certification for cryptocurrency's next phase: the standard doesn't guarantee individual AI models always reach correct conclusions. Its value lies in verifying whether an organization has established systematic processes to manage AI use effectively.
As platforms face more scrutiny, users and institutional clients will increasingly ask practical questions: Who is responsible for AI system decisions? Who can override automated decisions? How are model changes reviewed? How are errors recorded and corrected? And how can users challenge outcomes that affect them?
These questions become more critical as cryptocurrency platforms transition toward more autonomous systems supported by AI. Future applications will go beyond identifying suspicious transactions or summarizing market data to initiating workflows, managing permissions, and executing actions on behalf of users.
In this environment, trustworthy AI depends on clear identity, permissions, transaction limits, human intervention mechanisms, and auditable records.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: AI 사기, 코인 급증…쿠코인 새 보안 표준 추진