Market Prices

BTC Bitcoin
$75,531 -1.73%
ETH Ethereum
$2,391.15 -3.32%
SOL Solana
$96.7 -3.66%
BNB BNB Chain
$705.4 -1.54%
XRP XRP Ledger
$1.28 -7.96%
DOGE Dogecoin
$0.0793 -3.88%
ADA Cardano
$0.1927 -5.59%
AVAX Avalanche
$7.2 -3.77%
DOT Polkadot
$0.9397 -4.72%
LINK Chainlink
$10.7 -5.96%

Event Calendar

{{年份}}
30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x3faa...896a
Early Investor
+$2.6M
89%
0xf54d...d8f1
Top DeFi Miner
+$1.7M
89%
0x91b1...0a6d
Early Investor
+$4.5M
79%

🧮 Tools

All →

When AI Meets Crypto Scams: The Kimi Fraud Case and the Case for On-Chain Identity

CryptoPomp
Culture

Over the past seven days, a single incident has quietly echoed through both AI and crypto circles: Kimi, a prominent AI company, publicly disclosed that it had been impersonated by fraudsters running a fake fundraising scheme. The fraudsters used terms like "Friend Fund" and "Special Channel" to lure investors. The company issued a statement, reported the case to the police, and warned the market. This is not a crypto-native story, but for anyone building in decentralized finance, it is a glaring signal. The playbook—fake internal channels, fabricated quotas, and the promise of exclusive access—is identical to the scams that have drained millions from DeFi protocols. The difference? Kimi has no smart contracts to audit. The fraud lives entirely off-chain, in the opaque space between a company's brand and a investor's trust.

Trust no one, verify the proof, sign the block. That is the mantra of crypto. But when the proof is a whitepaper and the block is a reputation, verification becomes impossible. The Kimi case exposes a fundamental vulnerability: the gap between corporate identity and cryptographic identity. In crypto, we have public keys, ENS domains, and signed messages. In the traditional world, a company's legitimacy depends on a website, a registered address, and a statement. The fraudsters exploited this gap, and they did so with a sophistication that mirrors the most advanced crypto phishing campaigns.

Context: The Anatomy of an Off-Chain Scam

Kimi, a company operating in the AI sector, discovered that unknown actors were using its name to solicit investments. The fraudsters claimed to represent special funds or internal share quotas, using English terms like "Friend Fund" and "Old Share Quota" to add a veneer of professionalism. Kimi responded by issuing a public statement, denouncing all unofficial fundraising channels, and filing a police report. The company stressed that it had no authorized agents or intermediaries operating outside its official domain.

When AI Meets Crypto Scams: The Kimi Fraud Case and the Case for On-Chain Identity

This is a textbook impersonation fraud. In crypto, we see the same pattern: fake Telegram groups, cloned websites, and social engineering that leverages the brand trust of established projects. The key difference is that in crypto, the primary attack vector is often a compromised smart contract or a phishing link. Here, the attack vector is purely social: the fraudsters never touched a blockchain. They relied on the credibility of a well-known name and the greed of investors who believed they had found a backdoor to an exclusive deal.

From a legal perspective, the analysis is clear. The fraudsters likely violated China's Civil Code (protection of corporate name rights), Criminal Law (fraud, contract fraud, illegal fundraising), and the Anti-Telecom and Online Fraud Law. Kimi's public statement is a critical piece of evidence: it establishes that the company did not authorize these channels, which significantly reduces the risk of "apparent authority" claims. But the legal machinery is reactive. By the time the police trace the funds, the investors may have already lost their capital.

Core: Code-Level Analysis and Trade-Offs

Let me be blunt: the current system of brand verification is broken. Kimi's statement is a band-aid. The only way to prevent this type of fraud is to make the verification process cryptographic and immutable. Here is where my experience as a protocol developer kicks in. I have audited several AI-crypto hybrid projects, and I have seen the same vulnerability repeated: off-chain communication is the soft underbelly.

Consider a simple solution: a signed message from an official public key. If Kimi had a widely recognized Ethereum address or a ENS domain, they could sign a message stating: "All official fundraising will be conducted through this address. Any other channel is fraudulent." This message can be stored on-chain, timestamped, and verified by anyone. No need for a police report. No need for a statement. The proof is in the block.

When AI Meets Crypto Scams: The Kimi Fraud Case and the Case for On-Chain Identity

But this is easier said than done. Not every company wants to associate with crypto. The regulatory landscape is murky, and a public address could be linked to illegal activity if the company ever interacts with a sanctioned wallet. There is a trade-off between transparency and privacy. Moreover, the average investor may not know how to verify a signed message. The UX friction is real.

Another approach is zero-knowledge identity verification. A company could issue a verifiable credential that proves its identity without revealing its private keys. Investors could verify the credential against a registry. This is the direction that regulatory tech is moving, but it is still in its infancy. The infrastructure for decentralized identity (DID) exists, but adoption is minimal.

During my audit of Fetch.ai's oracle systems in 2025, I identified a similar off-chain verification gap. The AI agents were making payments based on off-chain data, and the oracle was vulnerable to manipulation because the identity of the data provider was not cryptographically bound to the output. The solution was a zero-knowledge proof that tied the agent's public key to the data. The same principle applies here: bind the company's identity to a cryptographic key, and the fraud disappears.

Based on my audit experience, I can say with high confidence that the Kimi case would have been prevented if the company had a public key infrastructure. The fraudsters would have needed to compromise the private key, a much harder task than simply copying a logo.

Contrarian: The Blind Spots of Public Statements

The conventional wisdom is that a prompt public statement and police report are sufficient to protect a company from liability. The legal analysis supports this: Kimi's statement cuts off the possibility of "apparent authority." But there is a subtle counter-argument: the statement itself may not be enough if the fraudsters have already collected money from investors who reasonably believed they were dealing with an authorized agent.

In China's legal system, the concept of "表见代理" (apparent authority) can still apply if the company's conduct—or lack of conduct—led the third party to believe the agent was authorized. If Kimi delayed its statement, or if the fraudsters used official-looking documents that mimicked Kimi's branding, a court could find that Kimi had a duty to warn earlier. The statement is a shield, but it is not a force field.

Moreover, the fraudsters' use of English terms like "Friend Fund" is a blind spot. It suggests they were targeting a specific demographic: high-net-worth individuals familiar with Western investment jargon. This is the same group that often falls for crypto scams. The regulatory community is not yet equipped to handle cross-border, multi-lingual fraud that blends traditional corporate identity with crypto-style pitching.

Another blind spot: the possibility of insider involvement. The analysis notes that the fraudsters used terms like "Old Share Quota," which may have been derived from real internal conversations. If an employee leaked information, the company's internal controls are the real issue. A public statement will not fix a compromised internal culture.

Takeaway: The Future of Brand Verification

The Kimi case is a warning shot. As AI and crypto converge, the lines between off-chain identity and on-chain verification will blur. The most resilient projects will be those that adopt cryptographic identity verification as a standard practice. The question is not whether regulators will require it, but when.

Will the industry move fast enough to build a decentralized identity layer before the next wave of impersonation scams? Or will we continue to rely on reactive statements and police reports? The answer will determine whether the next victim is a Kimi or a major DeFi protocol. Trust no one, verify the proof, sign the block. It is time to take that advice seriously.

Fear & Greed

51

Neutral

Market Sentiment

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$75,531
1
Ethereum ETH
$2,391.15
1
Solana SOL
$96.7
1
BNB Chain BNB
$705.4
1
XRP Ledger XRP
$1.28
1
Dogecoin DOGE
$0.0793
1
Cardano ADA
$0.1927
1
Avalanche AVAX
$7.2
1
Polkadot DOT
$0.9397
1
Chainlink LINK
$10.7

🐋 Whale Tracker

🟢
0x8b2b...2435
12m ago
In
2,285,453 USDC
🔴
0x1720...3c1a
5m ago
Out
3,625,577 USDT
🟢
0x08ec...dbac
1d ago
In
3,055.72 BTC