Everything a New Crypto Token Tells You Can Be Faked for $500. We Tested What's Left.
A single operator can now buy a synthetic face for about $500, and generate the name, the logo, the site and the whitepaper for nothing. So we scored 373 tokens using none of it, and then checked what happened to them.
Since 7 August this site has published a risk score for every token it covers. The score comes from a fixed model, published in full at /risk/, and it reads nothing a human wrote. It cannot see the token's name, its logo, its website, its documentation or the thread announcing it. It sees a liquidity pool, a contract and a trade history: eight components, weighted identically for every token, with the weights public.
Measured on 30 August 2026, the corpus stands at 1,093 published pages covering 596 distinct tokens, the earliest published on 7 August. Of those tokens, 373 have now been covered for at least seven days and re-measured since. Grouped by the risk band the model assigned at the moment of publication, before anything had happened to any of them:
Low: 13 tokens, 0 later dead (0 per cent)
Moderate: 127 tokens, 10 later dead (8 per cent)
Elevated: 218 tokens, 76 later dead (35 per cent)
Severe: 15 tokens, 10 later dead (67 per cent)
“Dead” here is a narrow and deliberately boring definition rather than a verdict on anyone: liquidity below $5,000, the point at which a pool stops being tradeable in any practical sense. Ninety-six of the 373 reached it. Median liquidity at publication was $62,855 for the tokens that got there and $84,649 for the tokens that did not.
The ordering is the finding. Four bands, monotonic, running from nothing to two in three, produced by a model that has never been shown the pitch.
The part of this that is not a discovery
That on-chain signals predict token failure is not news, and we are not claiming it as ours. Academic work has established it on samples that dwarf this one. A recent Solana dataset labelled 76,469 high-risk candidates among 100,063 tokens issued across three exchanges in six months, and there is comparable work on wash-trading patterns on BSC and on detectors that combine chain data with open-source intelligence. Any of those is a stronger statistical instrument than 373 tokens.
What is different here is the order in which things happened. Those studies fit a model to history and report how cleanly it separates outcomes that had already occurred. This model was published first. Its components and weights went up at /risk/ before these tokens existed. Every score was attached to an article at the moment of publication and has not been edited since. The outcomes arrived afterwards and were recorded automatically every fifteen minutes. Nothing was tuned once the answers were visible, because the answers were not yet available to tune against. That is a smaller claim than the literature makes, and a harder one to arrive at by accident.
The report that prompted the measurement
TRM Labs published its 2026 AI-in-Crime Adoption Index on 17 August. It scores criminal adoption of AI across four typologies on three pillars: how much of the activity shows an AI nexus, how many stages of the crime it touches, and how sophisticated that use is. It lands on a composite of 54 out of 100, up from 28 in 2024. Scams come in at the top maturity tier. Hacks and ransomware sit a rung below. Narcotics and darknet markets score lowest, where AI use is confined almost entirely to marketing: product photography, logos, listings.
The headline numbers have travelled widely. AI-specific involvement in scam activity has grown roughly thirteenfold since 2022. Deepfake losses reported so far in 2026 exceed the whole of 2025 by 263 per cent. Pig butchering losses reported to the FBI's Internet Crime Complaint Center rose from $5.8 billion in 2024 to $7.2 billion in 2025, with the number of distinct operations TRM tracks up 164 per cent over the past year. On the intrusion side, TRM counted 201 hacks in the first half of 2026 against 83 in the same period a year earlier, 4 per cent of incidents drove 75 per cent of the losses, and roughly $600 million, or 61 per cent of the half's stolen crypto, is attributed to North Korea-linked activity.
Ari Redbord, TRM's global head of policy and government affairs, puts the thesis in a line: “AI has not invented new crimes. It removed the constraints on old ones. The skill floor collapsed, the scale ceiling lifted, and fake identity went industrial. What used to take a team of operators now takes one person with a subscription.”
That reading looks right to us. It also has a gap in it, and the gap is where this site spends its working day.
The typology that is not scored
None of TRM's four categories is the token launch.
That is a boundary rather than an oversight. The scams tier is built on approach-and-persuade crimes, among them pig butchering, impersonation and investment fraud, where a victim gets talked to, at length, by someone pretending to be a person. AI's fit there is obvious and the report documents it thoroughly. A promoted token launch involves no conversation at all. Nobody messages you. The artefacts do the persuading on their own: a name, a logo, a site, a document that looks like a whitepaper, an account with a following, replies underneath it that read like other traders.
The second half of Redbord's comment names the control point: “The pressure point remains identity verification at the on- and off-ramp. A synthetic passport gets a criminal onto the rails, and the money still moves on a public blockchain, where we can follow it.”
Both halves of that are true, and the second is the reason blockchain analytics works at all. But the first describes a control that is structurally absent from the venue in question. There is no ramp at a decentralised exchange. Nobody verified anything about a deployer, because there was nobody to present a document to. Deploying a token is a transaction, and listing it is a pool. Identity verification is the correct pressure point for the crimes TRM scored. It simply does not reach this one.
What got cheaper
The report's own price list is the useful part, and it is more specific than most.
A single-operator face model, enough for one person to appear as someone else on a video call, runs about $500. A one-year deepfake package goes for around $3,000. No-code ransomware kits sell for $400 to $1,200. TRM names vendors: Novin Verify for Iran-linked synthetic documents, NiMingZhe for face swap and voice cloning. Seventeen per cent of crypto scam domains the firm sees now claim AI in their branding, which is a measure of AI as a lure rather than AI as a tool, and worth keeping separate from the rest.
Set that against the inputs a trader actually uses to form a view on a token that appeared an hour ago. The ticker, the artwork, the site copy, the documentation, the thread explaining the thesis, the replies under the thread, and, at $500, a face to put on a call. Every one of those is now generated-content territory, at a cost that rounds to nothing against the sums involved.
This is a claim about cost, not about any particular token. We have no way to know which launches were assembled this way, and did not test for it. What the report establishes is that the narrative layer of a token launch has gone from a team-week to an afternoon, and that the floor Redbord describes fell out from under exactly the kind of material that used to take effort to fake.
What we are not claiming
The Low and Moderate rows are thin, and thin for a reason we caused. In August we tightened the band gate on our largest automated article type, which cut future output of it by around 40 per cent and pushed low-band tokens into other coverage. Those two rows hold 140 tokens between them and would carry more weight if we published more of them. The model's fifth band, High, holds no token old enough to count, and so does not appear in the table at all.
Our 26 per cent overall rate will look low to anyone holding the figure that circulates most widely, which is that roughly 98.6 per cent of tokens launched on the largest memecoin platform fail, most of them losing their liquidity within the first hour. Both numbers can be right, because they count different populations. That figure counts every launch on a launchpad, including the overwhelming majority that never attract a single buyer. This corpus is drawn from paid-promotion feeds and filtered by a liquidity floor, so a token only enters it if somebody spent money to put it in front of traders and a real pool was standing behind it when we looked. It is a sample of the launches that got far enough to be worth someone's attention, which is a much smaller and much healthier population than all launches. It is also, for that same reason, not a random sample of anything.
We checked the obvious thing as well. Tokens in the corpus carrying AI branding in the name or ticker, meaning AI, GPT, bot or agent, number 10 out of 596, under 2 per cent, and among those old enough to score they reached the dead threshold less often than the rest of the corpus rather than more. Ten is not a sample. We are reporting that we looked, not what we found.
And the model sorts the survival of a liquidity pool, which is a far smaller claim than sorting anything about price.
What it leaves
Redbord's framing survives the extension, which is the mark of a good one. AI removed constraints on old problems rather than inventing new ones. Applied to a token launch, it says the story is now the cheapest component in the thing: cheaper than the liquidity behind it, cheaper than the lock on that liquidity, cheaper than the weeks a pair has been alive.
There is no advice in that and none is offered here. But if the persuasive layer costs $500 and the structural layer costs whatever a real pool costs, the two have stopped being the same class of evidence, and it is worth knowing which of them you are reading at any given moment.