Security1 distinct publisher3 min readUpdated
404 Media reports a wave of minimally altered real photographs of celebrities on X, posted by monetized engagement accounts. The tell reporters and moderators leaned on, implausible context, is gone.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
404 Media reports that a category of nonconsensual AI imagery it calls "subtlefakes" has spread across X: real photographs of celebrities altered only slightly, a red carpet dress made more revealing, a body part enlarged, a pose changed [1][6]. The shift matters because the alteration is small enough to pass the check that has carried both readers and moderation queues since deepfakes appeared: the sense that the scene itself is implausible [4][5][9].
The 2017 baseline was a short clip of a woman on a bed with her face edited to look like Gal Gadot, circulated on Reddit and by DM [3]. It was convincing as an image and unconvincing as a claim about the world; nobody thought Gal Gadot had made a porn video [4]. That remains true of most fully synthetic nonconsensual material, according to the reporting: however photorealistic the render, it is unlikely that the biggest actor in the world would suddenly produce hardcore pornography posted by a random X account [5]. Subtlefakes strip that signal out, because there is nothing implausible about a famous person standing in a parking lot or on a step-and-repeat [9]. The reporter, who does this for a living, says he does not think he could identify these as AI-generated while scrolling [8]. If the load-bearing detector was context rather than pixels, then removing the context removes the detector [1].
The one case the reporter was willing to publish is instructive [c7b]. Actor Xochitl Gomez posted side-by-side comparisons on Instagram: a real photograph of her looking over her shoulder in a parking lot, reworked so she appears to be bending over and touching her butt, and a red carpet image reworked so she appears to turn away and stick her tongue out [7]. The proof came from the target, holding the original [7]. That is the operational problem. When the posted file is largely an authentic photograph with a small edited region [2], the question a reviewer has to answer is not "is this synthetic" but "how does this differ from the original frame," which requires the original frame and someone motivated to supply it [3]. The reporting does not test automated detectors, so treat claims about them carefully, but a policy or classifier keyed to wholesale generation has very little surface to work with here.
The economics point the same way. These images are almost always posted by verified engagement-farming accounts on X, which pays operators when posts draw enough impressions, and the accounts are earning millions of views [10][12]. The reporter found at least one account that posted subtlefakes and, further down its history, fully nude nonconsensual images monetized on other platforms [11]. So the same operator can collect impression revenue on the borderline material that stays up and route buyers to the explicit material hosted elsewhere [4]. The author's read is that X does not care [13], and that what is advancing is not only the tooling but the sophistication of the people using it maliciously [16]. The lineage is closer to the "cheap fakes" that Data & Society described in 2019, media edited to manipulate truth without advanced technology, than to face-swapping [14].
Watch three things. Whether platform rules and statutes written around "AI-generated" or "synthetic" images cover an authentic photograph with an altered pose [1][17]. Whether targets keep having to publish their own originals to establish that an edit occurred [7]. And whether X's impression payouts continue to fund accounts operating at this volume [10][12]. Harm here never depended on belief [15], but belief is what determines how long a post survives review.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The author argues that the problem with deepfakes was never that viewers believed the depicted person had actually made the video; deepfakes can look convincing but never fooled viewers into thinking what they saw was real.
According to the author, even photorealistic fully synthetic nonconsensual images are often clearly fake for contextual reasons: it is unlikely that the biggest actor in the world would suddenly produce hardcore pornography posted by a random account on X.
404 Media reports a new type of AI-generated nonconsensual image on X that the author calls "subtlefakes": images of celebrities based on real photographs that are subtly edited to be more revealing or provocative, rather than face-swapped porn or fully AI-generated nudes.
The author's first encounter with a deepfake was in 2017: a short gif from the start of a porn video, showing a woman lying on a bed talking to the camera, with the woman's face edited to look like Gal Gadot, posted to Reddit and sent to the author by Twitter DM.
Examples cited include a real photograph of a famous actor walking a red carpet edited to make her dress more revealing or her butt or breasts bigger, and entirely AI-generated post-workout selfies at the gym.
Actor Xochitl Gomez shared a side-by-side on Instagram showing that a real photograph of her in a parking lot, looking over her shoulder and smiling at the camera, had been altered with AI to make it look like she was bending over in one image and putting her hand on her butt in another; a red carpet image of her was also altered to make it seem like she was turning her back to the camera and sticking her tongue out.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One verifiable case, one inspected account, single outlet
The mechanism and reasoning are clearly laid out by a reporter with relevant beat expertise, and one instance is externally checkable because the target published the side-by-side herself. Everything else is first-person observation from a single publisher: one directly inspected account, no handle list, no sampling, no platform data, no outside expert, and no response from X. Provenance is explicitly unresolved.
Practice observed and monetized, but unmeasured
There is real signal that the technique is in active use and tied to a payout mechanism: verified engagement-farming accounts as the distribution channel, at least one account observed pairing it with off-platform explicit monetization, and a named target who documented being targeted. The magnitude, however, is asserted qualitatively ('many, many accounts', 'millions of views') with no figures, so measured adoption stays low.
Headline outruns a carefully hedged body
The analysis is unusually self-limiting: the reporter flags what he cannot verify, declines to republish examples, and admits he cannot determine provenance. But the 'taking over X' framing and the coinage of a new category rest on one target-published example, one inspected account, and an unquantified prevalence claim, and the moderation-failure conclusion is argued rather than observed. That leaves claims modestly overstated relative to the evidence and adoption actually presented.
Payout economics documented; outlet has a coinage stake
Incentives are legible on both sides. The actors' incentive is explicit and structural: X pays operators for impressions, non-explicit edits are likelier to survive moderation, and at least one operator funnelled audiences toward explicit material monetized elsewhere. The publisher also has a visible interest, coining and naming a category and stating the use is 'as far as I know, yet to be covered', which rewards novelty framing; that is disclosed in the text rather than hidden.
Reasoning credible, specifics largely unverifiable
Confidence is moderate-low. The mechanism argument — contextual implausibility was the tell, and minimally edited real photos invert the burden of proof for a takedown — holds up on its own terms and is consistent with the one verifiable case. But it rests on a single publisher's first-person observation, with no second observer, no platform response, no moderation-outcome data, no prevalence measurement, and a provenance attribution whose supporting sentence is truncated in the supplied text.
product
Grok CSAM suit gains a fourth plaintiff and a 7,000-image count2 distinct publishers
build
Grok Build's real product is the X timeline, not the code generator1 distinct publisher
product
A $500 fake cleared Rolex's own London workbench, and staff called it beautiful1 distinct publisher
product
X's ranker pays more for replies than likes, and that makes reach a bad proxy for quality1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026