An honest note before you read: this is a concept. I validated the problem with public data. The solution has not been tested with users yet, and the test plan is at the end of this page. I used AI as a design partner throughout; every decision on this page is mine.
The project at a glance
Koi helps bank customers use DeFi without signing blind. It explains what a signature lets someone do before you sign, shows every permission you have given like a direct debit, and, if money leaves your wallet, tells you what happened and stays with you until you are safe.
I have designed for banking, where confirming a payment is a ritual everyone understands. In crypto, the same moment is a block of code and a button.
When I read thousands of reviews from people who had lost money, almost none of them said "I signed something". They said "I was robbed", and they could not say how. The information was never missing. Nobody could read it, before or after.
TL;DR
- 01People who lose money in crypto wallets describe it as theft. Only 2.2% of 181 loss stories mention signing or approving anything.
- 02So the real problem is not only signing blind. It is that people cannot diagnose their own loss, and scammers fill that silence.
- 03Koi answers with banking rituals people already know, an AI that shows its reasoning, and a verified human when money is at stake.
Context
A problem measured in billions, felt one wallet at a time
In 2025, the FBI received 181,565 complaints about crypto-related fraud. The losses reported added up to more than eleven billion dollars, 22% more than the year before.
Two numbers in the same report shaped this case more than the total. Most victims did not know they were being scammed. And people who had already lost money became the next target.
Crypto losses reported to the FBI in 2025
181,565 complaints. US data.
Of notified victims did not know they were being scammed
Operation Level Up, crypto investment fraud.
Lost to "recovery" scams
Scams that promise to get your money back.
Source: FBI Internet Crime Complaint Center, 2025 Annual Report.
The problem, in their words
Nobody said "I signed something"
I started with 21 reviews read in depth. Then I tested the pattern at scale: 2,968 public App Store reviews of three of the most used wallets: MetaMask (1,117), Phantom (714) and Coinbase Wallet (1,137), from Spain, Mexico, the US and the UK. Before looking at the data, I wrote down what would prove me wrong.
The rule: if 25% or more of the loss stories mentioned signing, approving or authorising, my hypothesis was wrong. The result was 2.2%. Many people insisted they had never shared their seed phrase. They knew their money was gone. They did not know why.
Public reviews analysed
3 wallets, 4 countries, 2,143 of them negative.
Of 181 loss stories mention signing
Threshold set before looking: under 25%.
Loss stories also complain about support
And 1 in 4 warn others away from the whole category.
In their words
Six reviews, trimmed but not edited. Each one supports a claim in this case. Translated from Spanish; usernames removed.
A loss with no explanation
“They stole everything in the wallet. I only had the seed written on paper.”
A broken mental model
“I don’t understand what the seed phrase is for if, when I go to log back in, all my funds have disappeared [...]”
Beginners lose first
“I made my first top-up of 200 euros and they stole it. I need a solution.”
Alone after the loss
“[...] they stole 500 dollars from my account and never helped me [...]”
On screen is not understood
“I came from Binance and to transfer my assets they charged me more than 200 euros in fees.”
AI arrives under suspicion
“[...] you always get chat robots replying, saying they are hu...”
Where the AI sits
Rules calculate. The AI translates
In finance, a wrong sentence is a problem. A wrong number is a loss. So I drew a hard line between what the AI does and what it never touches.
How Koi reads a signature (conceptual architecture)
01
Read
RulesA decoder reads the signature: what it allows, which contract, how much and for how long. No AI here.
02
Score
RulesThree factors, and the final risk is the highest one. Same input, same result, every time.
03
Explain
AIA language model turns those facts into one plain sentence. It only sees the decoded facts and verified scam reports (retrieval, or RAG), never free text from the website.
04
Hand over
PersonIf the risk is high or the AI is not confident, a verified person is one tap away.
AI opportunity map
Where AI adds value
- Translate a signature into a consequence
- Facts come from the decoder, never from the model.
- Reconstruct what happened after a loss
- Every step links to its source ("See what I based this on").
- Answer first questions in Help
- It labels itself and hands over to a person.
- Group scam reports from many customers
- A person reviews a pattern before it becomes an alert.
Where I chose not to use it
- Calculating risk or amounts
- A wrong number costs money. Rules are predictable and auditable.
- Deciding for the customer
- Koi adds friction to risky signatures, but the customer decides.
- Confirming a high-risk signature
- That is a banking ritual: summary, checkbox, pause and the bank’s key.
- Talking to someone after a loss
- A verified person, because recovery scams use bots and fake support.
Notes for engineering
- Latency
- Reading and scoring must feel instant, under one second (Doherty threshold). The explanation can stream in after the risk is already on screen.
- Guardrail
- Every amount and name in the AI sentence must match the decoded facts. If they do not match, Koi shows the plain facts instead of the sentence.
- Context and tokens
- The prompt holds only the decoded facts and a few scam reports, so it stays short, cheap and easy to audit.
- Fine-tuning
- Not at the start. First, an evaluation set built from the three scenarios and the 2,968 reviews, to measure whether explanations are correct.
Conceptual. To be validated with an engineering team.
Five decisions that mattered
What I chose, and what I gave up
Each decision follows the same format: what was at stake, what I chose, what I gave up, and what happened.
01
Validate the problem before designing a single screen
- At stake
- Designing an elegant answer to a problem I had only seen in 21 reviews.
- I chose
- To test the pattern on 2,968 reviews, with a pass or fail threshold written down before I looked.
- I gave up
- Speed, and the comfort of a hypothesis nobody could disprove.
- What happened
- The hypothesis held with a wide margin: 2.2% against a 25% threshold.
02
Reframe the thesis when the data asked for it
- At stake
- Solving the wrong question. When people on Reddit described losing money without sharing their seed, the community often blamed a leaked phrase or malware, not a signature.
- I chose
- A wider thesis: people cannot diagnose their own loss, and that silence is filled by scammers.
- I gave up
- A neat, single-screen solution focused only on signing.
- What happened
- The flow after a loss became as important as the flow before signing.
03
Translate crypto into banking rituals people already know
- At stake
- Asking a bank customer to learn a new mental model in the most stressful moment.
- I chose
- Permissions shown as direct debits, and high-risk signatures confirmed like a bank transfer: summary, checkbox, a ten-second pause and the bank’s own key.
- I gave up
- Novelty, and most crypto vocabulary.
- What happened
- Every key screen now relies on a pattern customers already use (Jakob’s law).
04
Explain, never advise. Never promise recovery
- At stake
- Trust and regulation. A bank that promises to get your crypto back sounds exactly like a recovery scam.
- I chose
- Descriptive language ("this signature lets...") and an honest line: crypto transactions cannot be reversed, but we can help you lose nothing more.
- I gave up
- Comforting promises.
- What happened
- Clear content rules. For example, "Generating yield" instead of "vault" or "deposit", because "deposit" suggests money protected by the deposit guarantee scheme.
05
Govern the AI instead of hiding it
- At stake
- Customers already suspect support bots of pretending to be human.
- I chose
- An AI that labels itself, shows what it read, admits what it cannot know and hands over to a verified person. Risk is the highest of three visible factors, never an average.
- I gave up
- A seamless "magic" assistant and a single neat score.
- What happened
- Only 1% of negative reviews mention AI, so I treated it as a design principle, not a headline. The test will measure whether trust is calibrated.
The screens
Dark to watch, light to commit
Monitoring screens are near-black, so the eye scans for change. The screens that ask you to commit are cream, so the brighter ground slows you down. Every key moment maps to a screen you already know from banking.

Watch






Sign





After a loss




Prototype
Interact to explore further
Fifteen working screens, running in the browser. Designed in Spanish, for bank customers in Spain. Translated for this portfolio.
Things to try
- Open "Alerts" and review the pending signature request. Try limiting it instead of rejecting it.
- Go to "Permissions" and cancel a direct debit. Tap the info icon to see what "Unverified" means.
- Open "Help" and ask a question. Watch the handover from a person to the AI.
Design system and content
Colour carries meaning. Words carry trust
Severity in three tones
Low, medium and high risk are the only status colours, and they always come with an icon and a word. On the cream screens I use a darker variant of each tone, because the original coral does not reach AA contrast for text on cream.
Dark to watch, light to commit
Monitoring screens are near-black. The screens that ask you to commit, signing and protecting what is left, are cream, so the brighter ground slows the reading down.
One ramp per section
Each section owns a gradient ramp, so customers know where they are without reading a title. Content always sits on near-black panels, so text keeps its contrast on any ramp.
A typeface for every customer
Atkinson Hyperlegible, designed for low vision. The people with the biggest losses in the FBI data are over 60.
Words people use
"Radar" became "scams reported". "Vault" became "Generating yield". Any word that needed a glossary was replaced or explained the first time it appears.
How I will validate it
The part that is still to be proven
Reviews validate problems, not solutions. So the next step is a moderated test in two phases: a pilot with five sessions, then a comparative test with sixteen people. Half will see a current signing screen, half will see Koi, and each person will see only one version.
Five proto-personas, each built to break something
Marta, 58
The careful saver
False alarms. If she rejects a safe signature, the explanation scares too much.
Kevin, 24
The impulsive one
Signing without reading, and trusting the bank too much.
Laura, 36
The overconfident expert
Disguised signatures, and friction that annoys experts.
Antonio, 68
The assisted retiree
Accessibility, telling person and AI apart, and recovery scams.
Carmen, 43
The family manager
The direct debit model, and dropping out of long flows.
Success criteria, set before testing
| Comprehension | At least 80% explain the consequence correctly, clearly above the control group |
|---|---|
| Decision | More rejections of risky signatures, with no more rejections of the safe one |
| After a loss | At least 80% understand what happened and complete one protective action |
| Person and AI | At least 80% can tell when they are talking to a person and when to the AI |
No results yet. When the sessions are done, I will publish them here, whatever they say.
What this case shows
Explaining before is not enough
Phantom already previews transactions. Coinbase already shows its fees before you confirm. Their users still write "I was robbed" and "they charged me 200 euros". The information was on screen and it did not turn into understanding.
That is why Koi explains twice: what you are about to sign, and what happened after. And why, when money is at stake, there is always a verified person on the other side.
People did not need more information. They needed someone to read it with them, before and after.
Looking back
What I would do differently
- Talk to people earlier. Reviews told me what hurts, but not how people feel in the minute after they see their balance drop.
- Collect Google Play and Reddit at the same scale as the App Store. My Reddit layer was qualitative.
- Bring a compliance view into the content rules from day one, not as a review at the end.
Lessons that scale
Write the threshold before you look
AI makes it easy to find support for any idea. A pass or fail rule written in advance is what keeps the research honest.
AI did the volume. I did the judgement
AI collected and classified 2,968 reviews and helped me write the prototype code. The thesis, the thresholds, the five decisions and the ethical lines were mine.
Trust is a flow, not a screen
In finance, the moment after something goes wrong defines trust as much as the moment before.