Bitget has released its Anti-Scam Report 2026, marking the third year of its Anti-Scam Month initiative, and warned that fraud in digital finance is increasingly adapting to a multi-asset ecosystem. The report, developed with blockchain security firm SlowMist, focuses on how scams are evolving as investors use a wider mix of crypto products, tokenised assets, stocks, CFDs, wallets and AI-driven investment tools.
According to the report, fraud tactics are becoming more integrated with the customer journey: rather than relying on a single breach, many operations now move victims through a sequence of interactions spanning social media, messaging platforms, investment communities, phishing infrastructure and wallet activity.
Key takeaways
- Multi-asset participation is rising: The report says active users participating across two or more asset classes rose from under 1% in mid-2025 to more than 10% by May 2026.
- Scams are blending narratives and channels: Fraud campaigns increasingly combine social engineering, AI-generated content and multiple communication methods in one operation.
- Compromise is less “single-point”: Many successful scams now avoid one-off breaches and instead stage step-by-step interactions that culminate in asset theft.
- Security operations scale with threats: Bitget’s infrastructure intercepted more than 150 million malicious requests and supported the recovery of $32.3 million tied to security incidents between July 2025 and June 2026.
- Implication for users: The report highlights the need for improved account security and stronger scrutiny of AI-enabled deception and investment claims.
What drove the report’s findings
Bitget and SlowMist attribute the changing fraud landscape to shifts in how users engage with digital finance. As participation expands across multiple products and platforms, the report says fraudsters are tailoring campaigns to that behavior—using broader entry points and more sophisticated ways to build credibility.
In particular, the report describes a move toward campaigns that merge several deception layers at once: social engineering tactics, AI-generated materials and the use of multiple messaging and community channels. That combination can make scams appear more legitimate to victims, especially when they are exposed to consistent messaging across different environments.
How scams are evolving in a multi-asset environment
The report identifies several trends shaping the current threat environment, including AI-generated investment personas, deepfake-enabled scams, voice-cloning attacks and synthetic investment communities. It also flags wallet-draining operations, malicious smart contracts and increasingly advanced phishing campaigns.
Bitget’s analysis suggests that scams are increasingly orchestrated as multi-step experiences rather than one-time lures. Victims may be guided across platforms and then funneled into phishing and wallet-related actions, according to the report, before assets ultimately move out of control.
Among the cases cited, the report describes a deepfake investment scam impersonating Cypriot President Nikos Christodoulides. It also references an AI-generated investment advertising effort that reportedly defrauded thousands of Swedish investors, and a “Truman Show” synthetic community scam using approximately 90 fabricated investor identities. The report further points to the “Rublevka Team” wallet-draining operation documented in early 2026.
Security infrastructure metrics and what they suggest
Bitget said its security infrastructure intercepted over 150 million malicious requests between July 2025 and June 2026 and identified more than 13,000 high-risk malicious IP addresses. The firm also reported handling 18,135 user protection cases and supporting the recovery of $32.3 million linked to security incidents and fraudulent activity.
While the figures reflect Bitget’s own security operations rather than the overall market, they offer a signal that fraud volumes and operational complexity are increasing enough to require broader defensive coverage across attack types, infrastructure sources and user-protection workflows.
Practical recommendations and the campaign’s focus
Beyond documenting how scams operate, the report says it examines victim psychology, common scam entry points, the movement of assets after theft and the challenges involved in recovery. It also outlines practical measures for users, including steps to strengthen account security, recognize AI-enabled deception, evaluate investment opportunities more effectively and respond appropriately to security incidents.
Bitget said the Anti-Scam Month program, which began in 2024, has involved collaboration with security researchers, ecosystem partners and industry organizations to improve threat awareness and promote stronger user-protection practices.
During June, Bitget’s campaign is set to include educational content and security-awareness initiatives, along with partner collaborations designed to help users identify emerging threats and better protect digital assets.
Looking ahead, users and platforms will likely be watching for how AI-driven social engineering, deepfake impersonation and wallet-targeting tactics continue to evolve across jurisdictions and product categories. Additional security guidance and user-protection measures from industry participants may remain in focus alongside broader market developments that increase cross-platform participation.







