$80.7 billion. That is the number circulating through financial media. Americans lost it to crypto scams in 2025, according to a report with no named author, no published methodology, and no on-chain verification.
The code does not lie; only the founders do. This number does not come from code.
It comes from multiplication.
Reported losses: $11.4 billion. Estimated losses: $80.7 billion. The gap between these figures is exactly sevenfold. That multiplier was borrowed from a 2017 survey about general financial fraud reporting. It was never validated against crypto-specific data. It was never adjusted for changing fraud patterns, shifting demographics, or the rise of sophisticated laundering networks. It was applied like a flat tax rate to produce a headline.
Here is what will happen next. Legislators will cite the number. Regulators will use it in enforcement actions. Mainstream media will run the headline. And the crypto industry will again complain that it is misunderstood, without ever addressing the sloppy statistics that make the misunderstanding possible.
I have spent ten years auditing blockchain systems. I have torn apart token sales, stress-tested interest rate models, and traced exploiter wallets through mixing services. When I see a number this large, generated with this little rigor, I treat it the way I treat an unaudited contract with a privileged owner: as a vulnerability waiting to be exploited.
The exploit path here is not technical. It is political. Let me show you how it works.
The report surfaces at a specific moment in the American regulatory cycle. The SEC has spent years pursuing enforcement actions against crypto projects, from unregistered securities to market manipulation. The CFTC has its own docket. The FBI's Internet Crime Complaint Center publishes annual reports documenting crypto-related losses. Congress holds hearings where industry critics and defenders rehash the same statistics. Into this ecosystem drops a new figure: $80.7 billion in estimated crypto scam losses for 2025. On the surface, it follows a familiar pattern.
The FBI's 2023 IC3 report documented approximately $5.6 billion in crypto-related investment fraud. The FTC has published consumer loss data for years. The new report does not cite these agencies directly. That absence matters. The only hard number in the report is the $11.4 billion in reported losses. The $80.7 billion is derived, not observed. The derivation hinges entirely on that sevenfold multiplier.
Why does a multiplier matter so much? Consider the implications. If the multiplier is too high, the report inflates the scale of crypto fraud by tens of billions. If it is too low, the report understates the true damage. Either way, the precision of the headline figure is an illusion. The difference between $80.7 billion and, say, $40 billion is not a rounding error. It determines whether crypto fraud is a crisis requiring exceptional regulatory intervention, or a serious problem demanding measured responses.

This distinction matters because the United States is in a regulatory consolidation phase. Post-FTX, post-Terra, the political appetite for sweeping digital asset legislation has been inconsistent. Some members of Congress want comprehensive market structure bills. Others want outright restrictions, especially on self-custodied wallets and privacy tools. The release of a large, credible-looking loss figure feeds the latter camp.
The European Union's Markets in Crypto-Assets Regulation has already demonstrated what a coherent framework looks like, and also what it costs. MiCA gave Europe stablecoin reserve requirements and CASP compliance rules. The burden of those rules is crushing small projects, which was part of the design. The American approach is different: not a framework, but a grievance. And statistics are how grievances get weaponized.
Here is what I find most telling about the report's timing. The data claims to cover calendar year 2025. Annual reports of this kind usually surface in the first quarter of the following year, once the data is cleaned and validated. But this figure is circulating before any comparable FBI or interagency annual assessment is available. It fills a vacuum. In policy-making, the number that lands first often becomes the number that sticks.
The same dynamics played out in 2018, when I was a student in Warsaw hand-auditing ICO contracts. Project Aether's token sale function had a reentrancy vulnerability. I documented the exploit path, showed how an attacker could drain the treasury, and posted the evidence on GitHub. The founders ignored it. The community ignored it. Then 40 ETH disappeared from the treasury, and everyone wanted to know why no one had caught it.
The answer is the same in every episode of this comedy: someone had caught it. But warnings do not travel as fast as narratives. A messy, unverified story spreads. A precise correction limps behind it. The $80.7 billion figure is a story. The correction, if it ever comes, will not get the same coverage.
To be clear, I am not writing this to defend crypto against accusations of fraud. There is plenty of fraud. I have profiled enough malicious contracts to know that the predators are real, sophisticated, and well-funded. My objection is narrower. It concerns the quality of the evidence. And the quality of this evidence is insulting to every analyst who has ever traced stolen funds to an exchange wallet and documented the chain of custody.
Now let me take the argument apart. I will examine the multiplier, the definitional boundaries, the missing forensics, the amplification pipeline, and the regulatory consequences.
Part One: The 2017 Multiplier
Here is the methodological chain, as best I can reconstruct it. The report takes an observed figure, $11.4 billion in reported losses, and multiplies it by seven, based on survey research from 2017 suggesting that only about one in seven fraud victims reports losses to authorities. The result: $80.7 billion.
I have no issue with the existence of under-reporting. It is real. In my work, I have seen victims of wallet drains decline to report because they are embarrassed, because they believe law enforcement cannot act, or because the amount is too small to justify the paperwork. Under-reporting exists. What I question is the uniform application of a decade-old multiplier to a category of fraud that barely existed in 2017.
The 2017 survey that produced the 7x multiplier was not designed for crypto. It was a consumer fraud survey, part of a long tradition of estimating hidden crime. The methodology asks victims whether they reported an incident to any authority. The ratio of non-reporters to reporters forms the multiplier. In 2017, crypto fraud was a tiny subset of the fraud landscape. Most of the fraud surveyed involved credit cards, bank transfers, and identity theft. The reporting behavior of a credit card fraud victim is irrelevant to the reporting behavior of a victim who sent USDT to a pig butchering platform. The former has a bank, a statement, and a dispute process. The latter has a WhatsApp chat, a transaction hash, and a scammer who vanished.
Think about what crypto fraud looked like in 2017. The ICO boom was peaking. Scams were mostly fake token sales and phishing sites. The typical victim was a retail investor who had bought Bitcoin through Coinbase and encountered a fraudulent offering. Their reporting behavior was shaped by the expectation that authorities might respond. A victim in 2025 deals with a different landscape: pig butchering syndicates operating from compounds in Myanmar, AI-generated deepfake videos of celebrity endorsements, fake wallet applications distributed through official app stores, social engineering via crypto communities that discourage legal recourse entirely. Reporting incentives are different. Reporting barriers are different. The demographic profile is different.
If the true under-reporting rate for crypto scams is lower than one in seven, the $80.7 billion figure is inflated by tens of billions. If the rate is higher, and for pig butchering victims in particular there is reason to believe it is, the figure could be too conservative. Either way, the report's confidence is unearned.
A similar flaw appears in official reporting. The FBI's IC3 numbers blend crypto and non-crypto investment fraud. The FTC captures only consumer complaints, which miss protocol-level thefts entirely. The point is not that these agencies are dishonest. The point is that measurement error compounds. When you multiply an imprecise base by an unverified factor, the confidence interval becomes a placeholder for unknown unknowns.
My experience with the Terra collapse comes to mind. After the UST depeg, I audited the peg mechanism and reproduced the death spiral using public data. The mathematical impossibility of the algorithmic backstop was provable. But there was no single official number for total losses. Estimates ranged from $20 billion to $60 billion, depending on which oracle price was used and where the countdown started. Every estimate was defended by someone. Every estimate was wrong by design. Statistics in crypto, when not anchored to on-chain data, are marketing.
Part Two: The Definitional Problem
The $80.7 billion figure does not exist in a definitional vacuum. Every fraud taxonomy makes arbitrary choices. The report appears to include any fraud in which cryptocurrency served as a payment rail. That is a generous definition.
Consider a common pig butchering scheme. A victim is contacted on a dating app or through a misdirected text. Over weeks, the scammer builds trust. Eventually the victim is invited to invest on a fake trading platform. The platform shows fabricated returns. The victim deposits funds, often in USDT, because crypto transfers are irreversible and borderless. The victim loses everything.
The fraud is real. The damage is real. But is this a crypto scam? The cryptocurrency element is incidental. The fraud is social engineering. Scammers increasingly request crypto because transactions are final, the recipient is pseudonymous, and the laundering infrastructure is mature. A credit card charge can be reversed. A wire transfer can be flagged. A USDT transfer to a Binance account, withdrawn within minutes, disappears. Using that mechanism is not the same as being a crypto-native crime, but the classification treats them identically.
By contrast, the report likely undercounts pure crypto-native attacks. Reentrancy exploits, malicious token contracts, governance attacks, private key compromises. These do not always get reported as fraud. A protocol that loses $50 million to a private key compromise may not generate a single consumer complaint. There is no victim who calls the FTC. There is only a treasury drain, sometimes undisclosed for months.
So the $11.4 billion base is questionable in both directions. It captures social engineering frauds in which crypto was a delivery mechanism. It misses protocol-level thefts that belong in any honest assessment. Then it multiplies the muddy number by seven.
I remember auditing a project during the NFT mania. The minting contract had an owner function without access controls. Anyone could pause the mint. Anyone could mint infinite tokens. I flagged it. The founders knew. They launched anyway. The rug was pulled before the mint even finished. Victims did not file FTC reports. They created Telegram support groups. The losses were real but unregistered. If a victim cannot identify the perpetrator, and in most cases they cannot, why engage a system not built for cross-border pseudonymous theft?
Here is the uncomfortable truth: the unmeasured part of crypto crime is probably larger than the measured part. This is the strongest argument in the report's favor. But a valid direction of bias does not justify an invented magnitude.
Part Three: The Missing Forensics
This is the part that bothers me most professionally. The report contains no evidence of on-chain verification.
In 2025, we have better tools than ever for measuring crypto fraud. Chain analysis firms maintain databases of tagged addresses, including known scam wallets, ransomware operators, and darknet markets. Exchange compliance teams use transaction monitoring software. An independent researcher can pull public blockchain data and trace funds from a known scam address to an exchange deposit. I have done this work. It produces numbers with confidence intervals, not certainties, but at least they are grounded in observable facts.
The $80.7 billion figure appears to be derived entirely from survey extrapolation. No address clustering. No flow analysis. No reconciliation with exchange data. No deduplication of losses across reporting channels. The report does not even explain how it arrived at the $11.4 billion base. Which categories? Did it count non-custodial wallet theft? Smart contract exploits? Romance scams that merely used crypto for payment? Without a category breakdown, the base number is unverifiable.
A real forensic estimate would start with the FBI's IC3 data, cross-reference it with Chainalysis-tagged addresses, identify which exchanges received stolen funds, and measure the actual flows. It would isolate crypto-native scams, such as compromised private keys, honeypot contracts, and liquidity pulls, from payment-rail crimes. Only then would it apply under-reporting factors derived from crypto-specific victim surveys, not from a decade-old consumer study. The final number might be $30 billion or $50 billion or $90 billion. But it would come with a methodology that could be tested.
This matters because the difference between a good and bad fraud estimate is not philosophical. I don't trust the audit; I trust the gas fees. Market participants pricing regulatory risk on the basis of this report are making decisions with data no forensic analyst has vetted. If the report overstates losses by a factor of two or three, entirely plausible given the methodology, it will still be cited as fact. That citation will have consequences. Capital allocation will shift. Compliance teams will change onboarding procedures. Institutional adoption timelines will adjust.
In my audit work, I have never seen a client accept a vulnerability assessment based on multiplication rather than testing. If I told a client a contract was exploitable because a 2017 survey of unrelated systems suggested a sevenfold probability of hidden vulnerabilities, I would be fired. The standard of evidence here should be no lower because the subject is statistics rather than code.
I led an audit for an ETF issuer's cold storage solution in early 2025. We found a side-channel vulnerability in the multi-sig signing logic. The client's first response was to ask whether the proof was real. That is the correct question. The report's first response should be to show its work. It has not.
Part Four: The Amplification Pipeline
Once a number enters the media ecosystem, it takes on a life of its own. This is not new, but crypto is particularly susceptible because its external reputation is polarized. The playbook runs like this: a report produces a dramatic figure. A wire service covers it. Legislators cite the coverage, not the report. The anonymous authorship is laundered through the media chain. After three hops, the number is widely reported and the source is forgotten.
I have watched this happen repeatedly. During the Terra collapse, early damage estimates varied wildly. The higher numbers made better headlines. They appeared in congressional testimony months after better data had contradicted them. Corrections never caught up with headlines.
This report will follow the same trajectory. The number is already circulating in the crypto community and the trad-fi press. It will appear in a congressional hearing. The 7x multiplier will not stop that. The unknown authorship will not stop that. The number is too convenient.
The regulatory consequences are predictable. The SEC will use it to justify expanded investor protection rules, likely targeting non-custodial software and decentralized applications that cannot perform traditional KYC. The CFTC will reference it in cases involving derivatives. FinCEN will cite it in support of tighter reporting requirements, potentially expanding surveillance of self-hosted wallets. Privacy tools will feel the pressure first. Mixers, privacy coins, zero-knowledge applications. They remain the politically easy targets because the association between privacy and fraud is simple to draw, even if it is difficult to justify.
There is also the recovery blind spot. The report treats every loss as permanent. That is an analytical choice, and a pessimistic one. Major exchanges run proactive fraud-detection programs that freeze suspicious accounts before adversaries withdraw. Federal recovery teams return a portion of stolen funds every year. The true net loss is certainly lower than the gross figure. An inflated gross number, repeated without context, causes the industry to over-regulate in response to a problem that is partially being contained.
I am not making a policy argument about whether these measures are good or bad. I am making an epistemic argument. When a regulation is premised on multiply flawed data, the regulation inherits the flaws. Bad data produces bad rules. The people affected by those rules will not cross-examine the statisticians. They will update their compliance systems and pay their lawyers.
Part Five: The Cost Structure Angle
Even if the methodology is weak, the pressure it creates has a real cost structure. I will not pretend otherwise. As someone who has led security audits for institutional clients, I have watched the compliance burden grow every year. The average institutional-grade audit involves substantially more regulatory and operational diligence than it did three years ago. Custodial compliance, transaction monitoring, legal review. The costs keep rising. This report, if it gains traction, will accelerate the trend.
The result will be a bifurcated market. Heavily capitalized exchanges with established compliance departments will absorb the costs. Smaller platforms will face a choice: invest in compliance infrastructure or exit the American market. Many will exit. That is not necessarily bad. The attrition of undercapitalized, under-compliant platforms is not a systemic risk. It may be a feature of maturation.
The report also has a silver lining for the security industry. The more the public understands that crypto fraud is measurable, the more demand there will be for forensic tooling. Chainalysis, Elliptic, and their competitors will benefit from the narrative even if the number is wrong. So will custody providers with strong insurance and exchanges that offer fraud monitoring to retail users. When the market narrative is risk, the companies that sell risk management win.
That is the uncomfortable dynamic at the center of this story: an inaccurate report, if widely believed, still changes behavior. Some of that changed behavior, such as better KYC, more fraud monitoring, and institutional caution, is beneficial. The problem is that we could implement all of those improvements without inventing a fake precision that distorts the public debate.
Let me now steelman the case I have been tearing apart, because the bulls have a point that deserves respect.
The reported $11.4 billion is itself a catastrophe. If every victim reported their losses, the true figure would be higher. The 7x multiplier is an arbitrary instrument, but the direction of the bias it corrects, under-reporting, is real. Even if the true multiplier is 2x or 3x, the annual losses remain enormous. And for certain categories, the under-reporting is staggering. Pig butchering victims are often ashamed. Some are actively threatened by the syndicates that defrauded them. A case can be made that for that category alone, a 7x multiplier is generous, not excessive.
The structural point is harder to dismiss. Crypto is permissionless. That means it is available to criminals and to legitimate users alike. There are no chargebacks. There is no KYC at the protocol layer. There is no global dispute resolution mechanism. Scammers will always be able to operate unless the system is deliberately designed against them, and deliberate design against them will never be complete because the same properties that protect criminals are the properties that protect users from censorship and seizure. This is a trade-off with no clean optimization.
In that context, the report's distortion does not invalidate its warning. The problem is real even if the number is wrong. My objection is not to the direction. My objection is to the method. A community that claims to value cryptographic proofs should not accept unverified arithmetic when discussing its own exposure. When I shorted the governance token of that NFT project with the broken mint function, I did not do it because of a survey. I did it because I had read the code. The difference between code and survey is the difference between evidence and vibes.
Here is what should happen next. The industry should publish its own chain-verified estimate of 2025 scam losses. It should disclose definitions, category boundaries, and confidence intervals. It should publish before the next congressional hearing, not after. If the industry remains silent while an anonymous report defines its reputation, it forfeits the right to complain about the consequences.
I do not care whether $80.7 billion is true or false. I care that no one can verify it. In an industry built on public verifiability, accepting an unverifiable statistic on faith is the most bearish signal of all. The code does not lie; only the founders do. But statistics can lie too, when no one holds them accountable. Reentrancy is not a bug; it is a feature of trust. You trusted the number. You should not have.
The next time a regulator quotes $80.7 billion at a hearing, the honest industry response is not to wave a dismissive hand. It is to provide better data. If not, the only story that survives is the one that sold the most headlines. In crypto, that is almost never the true one.