Press play to start listening
Working from more than 2,500 post-incident investigations, AMLBot found that 65% of the crypto cases it handled in 2025 were driven by social engineering rather than technical exploits. This figure describes its own caseload rather than the market as a whole.
Platforms taking that seriously are starting to publish numbers. Binance reports that its user phishing simulation program cut the victim rate from 3.2% to 0.4%. The category responsible for most incidents is the one the industry has historically funded least, and that is beginning to reverse.
The Control Nobody Could Put a Number On
Security budgets go where the reporting is. A contract audit ends in a document with counts in it, and a bounty program produces a running tally of what was found and what it cost to find. Anything aimed at the people around the protocol produced a training completion rate and a feeling, so it sat in the compliance column rather than the controls column and got budgeted accordingly.
Simulation changed that. Attack your own users, or your own staff, and the result is a failure rate that moves between quarters. Behavioral monitoring produces an interception count on the same cadence. Neither is perfect, but both survive the only question a budget review actually asks, which is what happened to last year’s number.
AMLBot’s case distribution shows what that layer costs when it is left alone. Investment scams account for 25% of incident frequency and phishing for 18%. Device compromise sits at 13%, pig butchering and over-the-counter fraud at 8% each, and chat-based impersonation at 7%. Almost every entry in that taxonomy starts as a conversation rather than a corrupted contract.
Running the attack against your own staff converts a posture into a measurement, and a measurement into something a security team can be held to. It also moves the argument past protecting customers, since the credentials worth stealing usually belong to whoever administers the protocol.
“Code is no longer necessarily the weakest link in Web3,” says Jimmy Su, Chief Security Officer at Binance. “As smart contract security improves, attackers are shifting their attention to the people, credentials, and governance systems surrounding protocols. We saw this firsthand when Binance Security helped prevent a $1.2 million governance attack on BrainTrust. Protecting a protocol today means securing not just its code, but also who can control it, how that control is exercised, and the infrastructure and people behind it.”
The practice is not confined to exchanges. The Red Guild, a non-profit that has contributed to Ethereum security work for more than three years, runs a threat simulation program called the Phishing Dojo alongside the ETH Rangers program and SEAL’s security frameworks, and placed second in Giveth’s Ethereum Security Quantum funding round. Its founders have said publicly that public-goods funding alone has not been enough to sustain the work, which is a reasonable summary of where human-layer security financing still sits.
The caveat deserves stating rather than burying. Prevention figures of this kind are self-reported and unaudited, and a blocked attempt is not the same thing as a loss that would otherwise have happened.
Where the Security Budget Is Actually Going
The case for spending on this layer gets stronger the moment you look at what happens after prevention fails.
Almost nothing in decentralized finance is covered. Less than 2% of DeFi total value locked carries insurance or cover of any kind, with Nexus Mutual accounting for nearly the whole of the specialist sector’s $123.5 million.
Uninsured lending protocols alone have lost $7.7 billion to exploits since 2020. Where recovery happens at all, it depends on speed: AMLBot reports a roughly 75% freeze-success rate in cases where funds were still sitting in attacker-controlled wallets when the investigation began.
With no meaningful backstop and a recovery window measured in hours, interception carries the weight. MetaMask says its built-in protections blocked more than 6.5 million malicious site visits and nearly 150,000 malicious transactions in 2025, helping users avoid more than $500 million in losses. All of it happened at the interface layer, before a contract was touched.
Exchange-side figures show the same shift further down the stack. Binance reports that AI-driven decisioning powered 57% of its fraud controls by the first quarter of 2026, up from 41% at the end of 2025, and that its fiat card fraud rate sits roughly 60 to 70% below estimated industry benchmarks.
That is what the money is buying. Not a second opinion on the contract, but the screening layer that stops a transaction before it signs and the analysts who can read a conversation for what it is. Set against a recovery rate that only holds while funds sit still, and an insured share of the market under 2%, the case for paying for interception rather than remediation is close to arithmetic.
A Measurable Control Is Not a Solved One
The argument for funding human-layer defense used to rest on principle. It now rests on published results that can be compared between firms and challenged by anyone willing to read them.
Whether those self-reported figures survive independent verification is the open question, and it is the one worth watching as more of the security budget moves toward the people around the code and away from a second look at the code itself.

