- Fraud, Risk
New Currency, Same Dangers: Stablecoins and Familiar Risk Vectors
- The criminal playbook includes well-worn scams and new tactics designed specifically to exploit the digital asset ecosystem.
Katie Kuehner-Hebert
Share
Financial institutions exploring stablecoin strategies available to them under the GENIUS Act face a host of risk management challenges as digital-asset fraud continues to rise.
Using the tactics of conventional fiat currency fraud, alongside new methods designed specifically for targeting on-chain payment networks, fraudsters stole an estimated $17 billion through crypto scams and fraud in 2025, according to a report by Chainalysis, a blockchain data and analytics firm based in New York City.
That’s a portion of the $154 billion in total illicit on-chain activity the firm tracked last year. The bigger total includes different types of crime such as sanctions evasion, stolen funds, ransomware, and darknet market flows. Stablecoins accounted for roughly 84% of all illicit on-chain volume in 2025.
Among the actors driving the surge are state-linked groups working to evade sanctions, alongside cybercrime organizations operating around the world, the data showed.
“As banks evaluate stablecoin strategies, fraud risk is becoming a central consideration because these payment rails operate with greater speed, programmability, and interoperability than traditional systems,” said Caitlin Barnett, director of regulation and compliance at Chainalysis. “While stablecoins can reduce certain operational frictions, they also introduce new fraud vectors that financial institutions will need to manage carefully.”
Those vectors are strategy-dependent and reflect increasingly diverse techniques would-be criminals employ to target institutions today and to further exploit them as stablecoins modernize payment rails.
Tactics, Familiar and New
Some pages of the criminal playbook are familiar. Social engineering scams, where fraudsters trick their marks into freely sending them assets, are common in stablecoin fraud, said John Pachkowski, a legal analyst with Wolters Kluwer Legal & Regulatory U.S.
Thieves also can gain access to mobile wallets including stablecoin apps by stealing phones’ private keys, either forcibly in-person or remotely via phishing or malware, Pachkowski said.
And just like thieves steal conventional fiat currency, fraudsters use mule accounts and synthetic identities to “on-ramp” fiat currencies to stablecoin platforms and then “off-ramp” ill-gotten stablecoins by transferring them into fiat currencies, Chainalysis’s Barnett said.
Then there are those tactics designed specifically for on-chain networks such as using fake tokens or spoofed addresses. In the latter, a customer unknowingly transacts with fraudulent versions of legitimate stablecoin infrastructure.
There is smart contract and DeFi risk, too, where vulnerabilities or fraudulent schemes in decentralized applications lead to loss of funds, including DeFi lending apps where customers earn interest on deposited stablecoins. “The DeFi’s smart contract protocol could contain a re-entrance bug, whereby an attacker repeatedly triggers a function before the protocol finishes executing, resulting in unrecoverable funds,” Pachkowski said.
Right now, victims of stablecoin fraud lack protections like those offered on conventional currency fraud because the GENIUS Act doesn’t extend Regulation E-style coverage to stablecoins, said Anna Kooi, a partner at Wipfli who heads the firm’s financial services practice.
That means no mandated unauthorized transfer protection, no required error resolution process, and no private right of action against an issuer. “Stablecoin transactions are also irreversible, so once funds are off-ramped, recovery odds collapse,” Kooi said.
The regulatory framework outlined under the CLARITY Act, pending final Senate vote, hopes to close this gap in consumer protections, she noted.
Different Approaches, Different Risks
Banks exploring their options for stablecoins face different risks depending on whether they build the architecture themselves, join consortiums, or offer customers access to existing stablecoin networks.
Banks issuing stablecoins have the most control and the greatest amount of responsibility, Barnett said. They are directly accountable for onboarding, sanctions compliance, transaction monitoring, reserve management, cybersecurity, and fraud prevention. While the bank benefits from having maximum control over compliance and visibility into transactions, the risks include scams, mule activity, illicit wallet exposure, and smart contract vulnerabilities.
A breach of private keys or minting controls can drain or duplicate balances at the bank’s subsidiary that issues stablecoin, Kooi said. There could also be reserve fraud or misappropriation, because permitted reserves under GENIUS include uninsured bank deposits and repurchase agreements.
There is direct reputational and balance-sheet exposure for every dollar lost, particularly so for community banks—“disproportionately painful for an institution where one bad story travels the whole market,” she said.
In a consortium model, risk is shared across participants, which can reduce the operational burden but introduce governance complexity, Barnett said. Banks must align compliance standards, monitoring responsibilities, and liability frameworks. Weak controls at one participant can create broader network and reputational risk for the group.
With consortiums there can be ambiguous accountability when fraud hits—“who reimburses, who investigates, who does the customer call?” Kooi said. There can also be governance drift, because fraud loss allocation, dispute resolution, and incident response “tend to get under-papered in the rush to launch.”
If a bank integrates with external stablecoin networks or existing issuers, the operational burden is lower, but third-party risk increases significantly. Banks become dependent on the issuer’s compliance controls, reserve transparency, and security practices, while often having less visibility into activity occurring across external wallets and blockchain ecosystems.
“Regulators have been clear that outsourcing operational activities doesn’t outsource regulatory responsibility, and the customer absolutely doesn’t care whose token it is when they lose money,” Kooi said. “The bank’s name is the one on the relationship.”
Across all models, banks face fraud-related risks arising from both customer behavior and the broader ecosystem, Pachkowski said. They may be indirectly defrauded when customers fall victim to scams and demand reimbursement, creating financial and reputational exposure. Banks also face AML and sanctions risks, as illicit actors can use stablecoins to move funds rapidly across borders, sometimes evading detection through layering or cross-chain transfers.
Modernizing More Than Payments
While banks contend with new fraud vectors stablecoins introduce, blockchain-based payments also offer a level of transparency not available in traditional financial systems, Barnett said. With the right controls—including wallet screening, behavioral analytics, real-time transaction monitoring, sanctions screening, and robust third-party risk management—banks can build fraud programs that are more proactive and data-driven than those in legacy payment ecosystems.
“The institutions most likely to succeed will be those that treat stablecoin adoption not simply as a payments innovation initiative, but as a modernization of financial crime compliance and fraud prevention infrastructure,” she said.
Get access to an authenticated community of fraud professionals plus a
robust set of resources to help strengthen your fraud prevention and response.
Complimentary for ProSight members for one year.
Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.