
What happened
Anthropic's Chris Cronbaugh told Sleuthcon that after a prepaid account sent over 100,000 API requests a day to Claude, it found a network of around 28 dating apps where most chats were run by AI personas.
Why it matters
The apps presented themselves as ordinary dating services while the conversation layer was automated, so the people paying to chat had no way of knowing what they were actually paying for.
What to watch
The apps stayed live on major US app stores even after the talk, so the test is whether app stores and payment processors act on Anthropic's shared findings; Anthropic says disrupting this needs cross-industry collaboration.
WHO IT HITSEveryday users — mostly men in their mid-to-late 30s — who pay for coins and gems on dating apps are the ones exposed, while app store trust-and-safety teams and payment processors are the parties Anthropic says must act.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
The case came to light because Anthropic, a normally tight-lipped company, let its threat intelligence researcher Chris Cronbaugh give a public talk at Sleuthcon. Anthropic had noticed unusual activity on Claude: a single five-day-old prepaid account with no history suddenly started sending out 100,000+ API requests a day. That trail led to the dating app network, and the company published its findings in the "scams and fraud" section of its "Detecting and countering misuse of AI: September 2026" report — but only after The Verge had spent extensive time trying to corroborate them.
The operation was not a typical romance scam: there was no money "borrowed" by fake romantic partners, and no cryptocurrency involved. The apps themselves were the scam, charging for coins that users spent talking mostly to machines. Gig workers were hired to pass liveness checks or follow social media accounts, while AI personas kept conversations going 24/7. Claude ran the conversation layer, but the report says a small non-Anthropic model generated short reply suggestions for the gig workers, and an image-editing model generated avatar imagery.
The reporting also rests heavily on the work of security researcher Matthew "Zigula" Gore-Kormanik, who pulled the APKs, ran static and dynamic analysis, and found a leaked internal protocol manual shipped inside Doni. That manual documented monitoring of gig workers, call recording, transcripts, performance ranking, and the technique of pretending people had called users to lure them into conversation. Cronbaugh said accounts tied to the network had all been created in the previous month, underscoring how cheap it is to rebuild. The test for app stores and payment processors is whether they act on signals they already had, such as customer reviews, before the next network is built.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Calls to moderate frontier AI development have surfaced a financial dilemma alongside the safety debate, since…

Palo Alto Networks' Leeor Piazza said an AI agent scanned the internet, found a public API endpoint, then move…

At the Pro-Human Assembly in Washington, Bernie Sanders and Steve Bannon both called for tighter AI limits, wh…

Mozilla and Mistral launched Firefox Smart Window (beta), an AI assistant that helps with complex searches, re…

TypeSafe AI introduced Jev, a classification-only model that scores developer-defined options instead of gener…

Cognition's Devin began offering macOS inside its hosted virtual environment on September 15, 2026, joining th…
