AIToday
Large Language ModelsAI Safety & AlignmentThe Verge AIPublished: Sep 17, 2026, 01:00 JST

Anthropic's Cronbaugh: 28 dating apps ran AI catfishing at scale

Anthropic's Cronbaugh: 28 dating apps ran AI catfishing at scale

3 Key Points

  1. What happened

    Anthropic's Chris Cronbaugh told Sleuthcon that after a prepaid account sent over 100,000 API requests a day to Claude, it found a network of around 28 dating apps where most chats were run by AI personas.

  2. Why it matters

    The apps presented themselves as ordinary dating services while the conversation layer was automated, so the people paying to chat had no way of knowing what they were actually paying for.

  3. What to watch

    The apps stayed live on major US app stores even after the talk, so the test is whether app stores and payment processors act on Anthropic's shared findings; Anthropic says disrupting this needs cross-industry collaboration.

WHO IT HITSEveryday users — mostly men in their mid-to-late 30s — who pay for coins and gems on dating apps are the ones exposed, while app store trust-and-safety teams and payment processors are the parties Anthropic says must act.

Ask the AI about this article →

Summaries like this, in your inbox every morning.

Context & Analysis

The case came to light because Anthropic, a normally tight-lipped company, let its threat intelligence researcher Chris Cronbaugh give a public talk at Sleuthcon. Anthropic had noticed unusual activity on Claude: a single five-day-old prepaid account with no history suddenly started sending out 100,000+ API requests a day. That trail led to the dating app network, and the company published its findings in the "scams and fraud" section of its "Detecting and countering misuse of AI: September 2026" report — but only after The Verge had spent extensive time trying to corroborate them.

The operation was not a typical romance scam: there was no money "borrowed" by fake romantic partners, and no cryptocurrency involved. The apps themselves were the scam, charging for coins that users spent talking mostly to machines. Gig workers were hired to pass liveness checks or follow social media accounts, while AI personas kept conversations going 24/7. Claude ran the conversation layer, but the report says a small non-Anthropic model generated short reply suggestions for the gig workers, and an image-editing model generated avatar imagery.

The reporting also rests heavily on the work of security researcher Matthew "Zigula" Gore-Kormanik, who pulled the APKs, ran static and dynamic analysis, and found a leaked internal protocol manual shipped inside Doni. That manual documented monitoring of gig workers, call recording, transcripts, performance ranking, and the technique of pretending people had called users to lure them into conversation. Cronbaugh said accounts tied to the network had all been created in the previous month, underscoring how cheap it is to rebuild. The test for app stores and payment processors is whether they act on signals they already had, such as customer reviews, before the next network is built.

FAQ
How does the scam actually make money?
The apps ask users to buy coins or gems to keep chatting. The coins cost real money and users spend them talking primarily to machines, believing they are talking to other humans.
Were these apps still available after Anthropic spoke?
Yes. Several were still live on the Google Play Store and Apple App Store in early June, though most were removed ahead of Anthropic's September 2026 report. As of September 16th, Kira was still up, and Gore-Kormanik confirmed it shared the same code base as the others.
Who is behind this network?
Anthropic attributes the operation to a China-based actor based on Chinese-language internal materials and China-native infrastructure. Apps don't work inside China, and while they work in Asia outside of China, the monetization is turned off.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Palo Alto Networks details 10-hour AI agent hackSemafor Tech · 2h ago
  • Mozilla's Firefox Smart Window beta runs on Mistral modelsTHE DECODER · 2h ago
  • TypeSafe AI's Jev skips text, scores options in 70msTHE DECODER · 2h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleNvidia's Les Karpas: robots lack a data moment