Deepfakes broke identity-verification model—what replaces it?

BTCC
Coinmama


TL;DR: Generative AI is exposing a fundamental weakness in digital identity verification: photographs, document scans, video, and even biometric evidence can be manufactured much more easily than in the past. Deepfakes now account for one in five biometric fraud attempts, according to Entrust, while injection attacks rose 40% year-on-year. In response, digital identity is moving toward cryptographically verifiable credentials, where authenticity can be established by who issued them and whether they have been altered, rather than by whether they look convincing. Biometrics, liveness checks, and fraud detection will remain important components of a broader trust stack.

Key Takeaways:

Imagine a world where nobody could convincingly prove their identity.

With the rapid adoption of generative AI, deepfakes are edging us closer to such a world.

According to a 2026 report by Entrust, based on more than one billion identity verification events in 195 countries, deepfakes now account for one in five biometric fraud attempts.

Phemex

On top of that, injection attacks increased 40% year over year. Injection attacks involve attempting to inject manipulated images or video directly into the system, bypassing live capture altogether.

The implications are dire. Aside from traditional identity fraud, consequences could include exclusion from financial services, loss of access to public services, increased difficulty entering employment, and much more.

So much in our modern societies depends on verifying that an identity credential is genuine and that the person holding it is who they say they are.

With the problem likely to worsen as generative AI models become more accessible, digital identity will move toward cryptographic verification, where authenticity can be established by verifying who issued the credential and whether it has been altered.

The familiar pattern has been broken

For many years, online identity verification has followed a familiar pattern—take a photograph of a document, upload it, take a selfie or record a short video, and let software compare the face with the identity document and decide whether both are genuine.

It worked because it made sense in a world where convincingly forging all of those pieces required considerable cost and effort. However, generative AI is making it much cheaper and easier.

What this means is that AI isn’t just making fraudulent identity documents more convincing; it’s undermining the assumption that convincing digital evidence is sufficient proof of identity in the first place.

Back to the top ↑

You can’t revoke a JPEG

The reason it’s possible to attack the identity-verification model we use today is that it still relies on converting physical credentials into digital copies.

While passports and driver’s licenses may contain extra security features on physical copies, online services don’t have access to them. Instead, they receive a digital copy, and those can be stolen, edited, and manipulated.

A September 2026 Biometric Update analysis described the emerging alternative as a shift from document verification toward cryptographic proof. Instead of asking whether an uploaded credential appears genuine, a verification system can verify that the issuing authority actually issued it and, if possible, whether it has been tampered with.

So, while generative AI can create a convincing image that looks like a driver’s license, it cannot generate a valid cryptographic signature from the DMV.

Likewise, a stolen or manipulated image cannot be revoked once it’s in circulation, but a cryptographically verified credential can be revoked and reissued if compromised.

Back to the top ↑

Cryptography doesn’t eliminate biometrics

Cryptographically proving that a credential is authentic doesn’t prove everything about the person presenting it.

Genuine credentials could still be used by compromised devices, legitimate holders could be manipulated by scammers, authenticated sessions could be hijacked, and fraudulent transactions could still occur after verification has succeeded.

As a result, a replacement for today’s identity verification model will likely rely on multiple technologies. It will be a layered system using cryptography to establish the provenance and integrity of the document, device binding with local PINs to establish that the person holding it controls the device and the credential, liveness detection to combat injection attacks, and behavioral and transaction monitoring to continue assessing risk after the initial identity check is complete.

Entrust itself argues as much, saying that identity needs to be treated as a continuous control mechanism spanning initial onboarding, authentication, and ongoing use.

To sum it up, identity is becoming a trust stack rather than a one-time gate.

Back to the top ↑

Who provides the trust infrastructure?

Cryptographically verifiable credentials do not necessarily require a blockchain, as demonstrated by existing projects such as NIST’s mobile driver’s license.

However, a larger infrastructure question remains. When digital credentials are issued by governments, banks, universities, employers, and other institutions across thousands of unrelated services, and even across borders, how will they interact? Interoperability, standards, and scale will all be important.

Scalable public blockchains and digital ledger technology (DLT) can play a role in that infrastructure, particularly where multiple parties need access to common, independently verifiable records or credentials.

The problem is similar to the one already emerging around tokenization. Digitizing the asset is only the first step, and difficulties remain around how billions of independently issued digital objects need to interact across systems.

Deepfakes have accelerated that transition in identity. The old model asked humans and software to recognize evidence as genuine, but the emerging one asks whether authenticity can be proven.

Back to the top ↑

FAQs:

How are deepfakes used for identity fraud?
Deepfakes can create synthetic faces, videos, or biometric samples that imitate users during identity verification.

What is an injection attack
An injection attack bypasses normal live capture by feeding manipulated images or video into an identity verification system.

What is a cryptographically verifiable digital identity?
A cryptographically verifiable digital identity uses digital signatures and related cryptography to enable verifiers to check whether a trusted issuer created a credential and whether it has been manipulated since.

Will digital identity replace biometric verification?
Not necessarily. Biometrics will likely remain one layer of digital identity alongside cryptographic credentials, device authentication, liveness detection, anti-injection technology, and ongoing fraud monitoring.

Does digital identity require blockchain technology?
No. Cryptographically verifiable credentials can operate without a blockchain. However, public blockchains can provide a shared trust infrastructure where credential issuers and verifiers need interoperable, auditable, and widely accessible systems.

In order for artificial intelligence (AI) to work right within the law and thrive in the face of growing challenges, it needs to integrate an enterprise blockchain system that ensures data input quality and ownership—allowing it to keep data safe while also guaranteeing the immutability of data. Check out CoinGeek’s coverage on this emerging tech to learn more why Enterprise blockchain will be the backbone of AI.

Back to the top ↑

Watch: Building the tech of tomorrow with blockchain and AI

frameborder=”0″ allow=”accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share” referrerpolicy=”strict-origin-when-cross-origin” allowfullscreen>



Source link

Coinbase

Be the first to comment

Leave a Reply

Your email address will not be published.


*