An unnamed report, distilled into a one-page news brief, claims Americans lost $80.7 billion to crypto scams in 2025. The same brief notes that the actual reported loss figure stands at $11.4 billion. Between those two numbers sits a multiplier: roughly seven times. That multiplier was not generated by any on-chain model or victim survey. It was sourced from a 2017 study of general fraud underreporting, and then dropped, unchanged, into a market that did not exist when the study was written. Code doesn't count as evidence just because it sits in a spreadsheet. Neither should a number assembled from assumptions that have never been tested against transaction data.
I have seen this shape before. In 2017, I audited 40 ICO projects line by line, matching whitepaper promises against ERC-20 contracts. The worst failures did not require a security laboratory. They required a journalist willing to divide projected returns by actual utility. The same instinct now applies. Before anyone treats $80.7 billion as a measure of the scam economy, the calculation itself deserves the audit it never received.
The brief contains almost no operational detail. It offers an estimated total, a reported total, a 7x underreporting assumption, and a U.S. jurisdiction. No protocol is named. No scam vector is identified. No wallet addresses are published. No institution is credited as the original author. That last absence is the most important detail in the entire document. An anonymous estimate, regardless of its scale, is an unverified contract with no code attached.
Yet it cannot be dismissed. The value of a statistic in Washington is not always tied to its accuracy. It is tied to its simplicity. A Member of Congress does not open a hearing with a discussion of confidence intervals; they open with a number. If $80.7B is read into the Congressional Record, the methodology behind it will matter far less than the rhetorical damage it creates.
The regulatory ecosystem treats such figures as raw material. The FBI's Internet Crime Complaint Center has documented crypto-investment losses in the billions for multiple years, but a number in the tens of billions changes the scale of the problem. It converts a serious issue into a moral panic. Every additional zero in the headline unit shrinks the space for nuance.
That is why the source matters. The report is unnamed, so there is no way to inspect whether the institution had a commercial stake in publishing the loss estimate. When I traced legal filings during the 2024 Bitcoin ETF approval process, I learned that any data point in the record can be weaponized. Defense lawyers, enforcement officials, and lobbyists all quote what is already on the record. A single polluted statistic can poison the well for years.
Let me reconstruct the data path as an auditor would.
The published baseline is $11.4 billion in reported losses. That is the only number in the brief that can be compared against future disclosures. Everything else is derivation.
The estimated total is $80.7 billion. If the multiplier were exactly 7, the resulting product would be $79.8 billion. The observed gap of roughly $900 million tells me the original report used either a slightly different multiplier, an adjusted baseline, or an additional recovery adjustment. None of that arithmetic appears in the brief. The missing detail matters because the eight-digit difference could represent a different interpretation of 'victim' or 'loss.' Without the raw model, the number is an ink blot.
The underreporting multiplier is the weakest link. The 2017 survey asked people about their willingness to report traditional fraud. The resulting 7x factor is now being applied to crypto scams in 2025. That requires the unstated assumption that the reporting behavior of crypto fraud victims is identical to that of card fraud victims in 2017. The assumption is implausible on two counts.
First, crypto transactions are public by design. A Bitcoin or ERC-20 transfer leaves a permanent address record. Even when victims do not file a police report, the transaction data remains visible to chain analytics firms. Law enforcement can identify clusters of scam addresses. This does not eliminate underreporting, but it compresses it. The 2017 survey could not account for this because the infrastructure was immature.
Second, the profile of victims has changed. The 2025 crypto user is more likely to have interacted with a decentralized application, connected a wallet, or signed a token approval. That sophistication influences whether a victim knows how to report. The multiplier from 2017 cannot capture that shift.
The per-capita dimension exposes the scale problem. Dividing $80.7 billion by an approximate U.S. population of 335 million yields about $240 per American. Narrow the denominator to adult internet users, and the figure remains in the low hundreds. That is a strange profile for an epidemic. If losses were broadly distributed, the policy response should focus on consumer education. If losses were concentrated among a small number of high-net-worth victims, the policy response should focus on recovery and seizure. The brief does not ask which actor the case is about.
The chain-analytics blind spot is more serious. The estimate appears to assume that every reported loss is a permanent loss. It makes no visible adjustment for funds frozen, seized, refunded, or recovered through interventions. Blockchain forensics teams have demonstrated that the window for freezing stolen assets closes within hours, but it does not close instantly. Any credible estimate of net losses must subtract the millions already recovered. An estimate that ignores recovery overstates the damage.
Code doesn't announce its own bugs; auditors have to trace the execution path. The $80.7B figure has no exposed execution path. It is a black box with a headline attached.
Any honest regression of the estimate would require at least three conditions to hold: one, the 7x factor from 2017 must remain statistically valid for crypto-specific fraud in 2025; two, every reported dollar must be counted without double reporting across state and federal agencies; three, the ratio between reported and unreported losses must be stable regardless of actor type, loss size, and asset moved. All three are testable. None are tested in the brief.
If this number enters the regulatory record, the consequences are predictable. The SEC and CFTC will cite it in budget requests. State attorneys general will use it in consumer alerts. The argument for expanded KYC obligations, restrictions on self-custody wallets, and a broader reading of the Howey test will all gain ammunition. The number does not need to be true to be effective. It needs to be convenient.
Now the counter-intuitive part: the estimate may be the strongest evidence that the panic-driven regulatory push is statistically weak.
During the 2020 DeFi summer, I built dynamic spreadsheets to test whether top yield farms could sustain their emissions. The models reliably predicted collapse, but only because I loaded them with the protocols' own aggressive assumptions. Garbage inputs, rigorous math, and compelling charts—every time. The $80.7B formula works the same way. The original report claims to measure the scam economy. In reality, it measures the statistical assumptions of an anonymous author.
Code doesn't lie precisely because it cannot; it simply executes the assumptions that were compiled into it. This estimate is no different. Feed the model a 2017 multiplier and 2025 crypto losses, and the output will always look like a catastrophe. The catastrophe was an input.
There is also an unintended market function. If the number dominates headlines, it accelerates a migration of users toward better-regulated platforms. Exchanges with strict KYC, transparent proof-of-reserves, and fraud-monitoring teams will appear safer by comparison. The single FUD wave may do more to concentrate users in audit-compliant venues than a year of voluntary self-regulation. That is little comfort to those who expect the industry to remain free-ranging, but it is not a uniform negative for all participants.
In that sense, the $80.7B report is a catalyst with two faces: it arms regulators, and it disciplines the market. The first face gets the attention. The second face is the one most projections will miss.
Watch the citation trail, not the headline. If $80.7B appears in an SEC press release or a Senate Banking Committee hearing within the next two quarters, expect a wave of stricter KYC rules and a broader application of Howey-test logic. If the original dataset remains anonymous, the number will fade like a fake trading pair.
The question that matters is not whether Americans lost $80.7 billion in 2025. It is whether the rows behind the decimal point will ever see the light of day. Given that the current model leans on a 2017 fraud survey, I am not holding my breath. And neither should the market.