Skip to content

Product1 publisher2 min readPublished

Paid gig workers passed the video liveness checks for an AI-run catfishing network

Anthropic's misuse report and The Verge's tour of the still-listed apps describe a dating-app network that ran most of its conversations on models and paid a small human crew to appear on camera.

The Product Desk · Product desk

What happened

  • Anthropic's threat intelligence researcher Chris Cronbaugh described the network on June 5 at the Sleuthcon security conference, in a talk titled "Swipe Right, Pay Up: Industrial-Scale AI Catfishing."
  • Cronbaugh said the majority of chats across the network's dating apps did not involve a human agent at all.
  • Only one match in four had a real person behind it, and that person was a paid gig worker instead of someone using the app to find a date.
  • Security researcher Matthew Gore-Kormanik answered a video call from "Jennifer" inside the app Dora, saw a moving tapestry, and was later told "your voice is way better than expected" although his microphone was not connected.
  • Anthropic later published the findings in the "scams and fraud" section of its report "Detecting and countering misuse of AI: September 2026."

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint A video liveness check establishes that some human is reachable on camera, and an operation with a payroll can satisfy that without ever tying a face to the profile that used it.
  • decision App review has to decide whether a listing's claim to connect users with real people is copy it waves through or a statement it checks against the app's own backend.
  • exposure Suspicion became an operational signal for the fraud side, because the backend logged which users had begun to doubt the persona they were talking to.
  • precedent When a model provider discloses a live fraud network before the stores act on it, the provider becomes the enforcement point of record for products the stores distribute.

Anthropic's report says the workers were hired to pass liveness checks on video or to follow social media accounts, and that they answered messages by picking one of three pregenerated replies [8].

That leaves three matches in four with no person behind them [18], and those personas could only put off a video call with a plausible explanation for why it was not possible [9]. According to The Verge, the few real interactions were enough that some users came to believe the entirely AI-generated replies were from real people too [16].

Anthropic found the network because one prepaid account was sending more than 100,000 Claude API requests a day [1]. Across the roughly 28 apps described in the talk [2], that is an average of about 3,600 requests per app per day [17].

Claude was one part of the stack. The report says "a small non-Anthropic model generated the short reply suggestions the gig workers tapped, alongside face-attractiveness scoring and photo/voice moderation. An image-editing model generated avatar imagery" [11]. Counting the conversational personas, five separate functions were split across three kinds of model [19].

The video side of it was pre-recorded. Anthropic's report says "Backend components fabricated likes, visitors, and pre-recorded 'video' when no real person was available, and tracked which users had begun to suspect they were talking to a bot" [10]. The report does not say what the operators did with that list.

Listings for the apps promised people. Romi's description said it "helps you discover, connect, and chat with real people," and Doni's tagline was "start real companionship" [14]. None of them looked like a companion app such as Replika, where it is clear the personas are AI [15]. The Verge reported that many of the apps were still live in both major US app stores while Anthropic was discussing the network in public [6].

Anyone shipping a profile and a message box can get most of the way here by asking whether passing a check requires a live human at all, and whether it binds that human to the same account on an unannounced second attempt. Video liveness requires the live human and stops there. Its price to an attacker is a few minutes of a stranger's time in the cheapest labour market they can reach. The people this network was built for were mostly men in their mid-to-late 30s [7], and three of every four women they matched with were a model with an image-edited avatar [18].

What to watch

  • Whether Apple and Google pull the remaining listings now that Anthropic has published the network's pattern in its September 2026 misuse report.
  • Whether Anthropic identifies the vendors behind the reply-suggestion, attractiveness-scoring and avatar-editing models it describes only by category.
  • Whether operators drop the paid human layer once passing a video call with generated footage costs less than hiring someone to sit on camera.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories