Smartphone displaying a digital face scan overlay on a mannequin, with red and green check and cross icons below.

Anthropic Exposes AI-Powered Dating App Scam Network Built to Catfish Users at Scale

Anthropic exposed AI dating scams that used fake personas, gig workers and in-app coins to catfish thousands of users at scale.

In short

Anthropic says it uncovered a large AI-powered dating scam network that used fake personas, gig workers and paid coins to trick users across dozens of apps. Many of the apps were later removed from Apple and Google stores, but the case raises broader questions about app-store oversight and AI abuse.

  • Anthropic identified a network of roughly 28 dating apps tied to AI-driven catfishing.
  • The operation used Claude, other models and gig workers to keep fake chats going at scale.
  • Users paid real money for coins or gems to continue conversations they believed were with real people.
  • Many of the apps remained available on major app stores for weeks after the investigation began.
  • The case highlights how AI can turn romance scams into a business model built into the app itself.

Anthropic says it uncovered a large network of fraudulent dating apps that used AI personas, gig workers and paid in-app coins to trick users into paying for conversations with people who were often not real. The operation ran across at least two dozen apps and reached tens of thousands of users before many of the apps were removed from Apple’s App Store and Google Play.

The findings matter because they show how quickly generative AI can industrialize romance scams: not by helping a lone fraudster write better messages, but by powering a full subscription-like business model built around deception, automated flirtation and endless chat loops.

The report was first made public after Anthropic threat intelligence researcher Chris Cronbaugh described the operation at a cybersecurity conference in June 2026, but the network appears to have been active for months before store removals began in earnest in late summer and early September. Some of the apps were still available as recently as September 16, 2026.

What Anthropic says it found

Anthropic’s account points to a scam network that was more organized than a typical fake profile operation. Instead of one shady account on one dating app, investigators say they found a coordinated system of roughly 28 apps where the chat experience was frequently handled by autonomous AI personas.

In practice, that meant users believed they were talking to real people, but the other side of the conversation was often a model-generated script running continuously in the background. In some cases, a human gig worker was involved too, but only as part of a limited support role that helped the deception stay credible.

Anthropic says it traced the activity after a prepaid Claude account with no prior history suddenly began making more than 100,000 API requests a day. That spike led the company to investigate and, eventually, to conclude that Claude was being used as the conversation engine inside a scam operation.

Anthropic’s threat research team described the activity as an industrial-scale catfishing operation built to imitate ordinary dating-app behavior while hiding the fact that many exchanges were generated by AI.

How the scam worked

The short answer is that the apps sold the illusion of access to women who were attractive, available and eager to chat, while the actual conversations were often routed through AI systems that could keep talking indefinitely as long as users kept spending money.

Users, typically men in their 30s, matched with profiles that appeared legitimate. Some matches were real people hired to participate in the ruse, but many were not. According to Anthropic, only about one in four of the apparent women were actual humans — and even then, they were not ordinary daters but paid workers following instructions.

Those workers had to pass liveness checks on camera or perform simple social tasks, such as following accounts. Their responses were often limited to choosing among prewritten reply options. The more important role, however, belonged to the AI layer, which could keep the conversation going without sleep, hesitation or natural limits.

The apps monetized the interaction through coins or gems. Users paid real money for continued access, believing they were paying to deepen a connection with another person. In reality, the business was selling ongoing chat time with a machine, helped along by human labor when necessary.

Why the design was so deceptive

The apps did not present themselves as obvious AI companions. They were framed as dating services for people seeking real relationships, not as novelty bots or roleplay tools. That distinction matters, because many users would likely approach the apps differently if they knew the conversations were synthetic.

Descriptions for the apps used language that suggested authenticity and human connection. Some promoted themselves as places to meet real people, build companionship or find nearby singles. That branding helped blur the line between legitimate dating services and software designed to extract money from engagement.

Anthropic says the AI prompts were written so the personas would stay consistent and appear to be ordinary dating-app users. The models were not explicitly told they were helping a scam, according to the company, because the deception was hidden from within each exchange.

Even when the system recognized signs of harm, Anthropic says the output remained in character. In a small number of cases where users disclosed illness or emotional distress, the model’s reasoning reportedly reflected concern, but the conversation still continued as the persona.

Why this is different from a typical romance scam

This was not the standard romance scam in which a fraudster cultivates a victim over weeks and then asks for emergency money, gift cards or crypto. Instead, the app itself was the scam.

That difference is important. In a classic scam, the con artist eventually asks for a direct payment or wire transfer. Here, the payment mechanism was embedded inside the product. The user paid to keep the conversation going, unaware that the interface was engineered to sustain a fake relationship and maximize coin purchases.

In effect, the business model rewarded the system for prolonging the illusion. The longer the chat continued, the more users were nudged to spend. AI made that viable around the clock, and gig workers helped prevent obvious breakdowns in the performance.

Key detail What Anthropic reported
Apps involved About 28 dating apps tied to a broader scam network
AI activity Claude used as the primary conversation layer
Scale of activity More than 4,700 fake personas and about 2.36 million messages over two weeks
Human role Gig workers passed liveness checks and followed scripted tasks
Monetization Coins or gems purchased with real money for continued chat access
App store removals Many apps were removed from Apple and Google in late August and early September 2026

How big was the network?

Anthropic’s numbers suggest the operation was far larger than a handful of deceptive apps. The company says it observed more than 4,700 fabricated AI personas engaging with at least 25,000 unique individuals over a two-week span in April 2026, producing roughly 2.36 million messages.

That volume points to a system designed for industrial throughput, not casual fraud. The use of multiple models, shared infrastructure and repeated behavioral patterns also suggests a relatively mature operation with divisions of labor and a defined technical stack.

Investigators say the operation reused backend systems, payment flows and code across several apparently separate apps. Once one app was flagged, the same infrastructure could be repurposed or rebranded elsewhere.

Who was behind it?

Anthropic attributes the network to a China-based actor, citing Chinese-language internal materials and China-native infrastructure. The company also says the monetization component was disabled in China, while the apps remained functional in some other markets.

That attribution is significant but still limited by the usual caveats of cybersecurity reporting. It points to a well-resourced, organized operation, but public reporting has not independently verified every element of the attribution chain.

Still, the scale, internal documentation and repeated infrastructure overlap indicate something more sophisticated than opportunistic app-store abuse.

What researchers found in the apps themselves

Security researcher Matthew “Zigula” Gore-Kormanik helped dig into the apps after analyzing one of the suspicious programs, Dora. His investigation provided additional technical detail that supported Anthropic’s broad findings.

When he accepted a video call through the app, the feed did not show the caller at all. Instead, he saw what looked like a moving tapestry and heard distortion in the audio. After the call ended, the caller messaged him as if the conversation had gone normally — despite the fact that his microphone had not even been connected.

Gore-Kormanik also found what appeared to be an internal protocol repository containing code, documentation and operational details. He said a Chinese-language manual was bundled inside one of the apps, apparently by accident. That repository helped expose how the network managed workers, calls, screenshots and transcriptions.

Gore-Kormanik said the apps shared code and backend behavior closely enough that they “share code to a T,” pointing to a common architecture behind multiple brands.

What the repository revealed

According to the repository material, the system tracked worker availability, camera status and response times. It also captured screenshots and recorded calls, with transcripts available to staff. The documents described how workers were ranked and how their pay could depend on calls, messages or even social-media follow actions.

The same material also outlined tactics for generating fake incoming calls to lure users into conversation. In other words, the app was not merely a container for scam chats; it was a managed performance environment with metrics, incentives and quality control.

This kind of internal organization is what makes the operation notable. It looks less like a loose group of fraudsters and more like a company using modern tooling to optimize deception.

How did the same apps stay online for so long?

That is one of the most important questions raised by the case, and one that has not been fully answered publicly. Several of the apps remained available on Apple’s App Store and Google Play well after Anthropic says it had shared investigative information with both companies.

Anthropic said it notified Apple and Google directly, but neither company immediately explained how fast it acted, why removals took time or whether backend infrastructure linked to the apps was disabled. Google also did not explain why at least one app, Kira, remained live as of September 16, 2026.

The delay matters because the apps were not obscure side projects. They were distributing deceptive experiences at scale while ordinary users continued to download them from official stores, often assuming those stores had already screened out obvious fraud.

App store presence and removal timeline

By early June 2026, several of the apps were still listed in Google Play, while multiple versions were also discoverable in Apple’s store. Many were removed only later in the summer or early fall.

Date Event Examples
June 5, 2026 Anthropic researcher presents findings publicly at Sleuthcon Talk on industrial-scale AI catfishing
Early June 2026 Several suspicious apps still live on app stores Doni, Dora, Jovia, Nalo, Romi
August 21, 2026 Apple removals reported GraceChat, Luma, Romi
September 1, 2026 Google removals reported Doni, Jovia
September 3, 2026 Additional Google removals Dora, Romi, Luma, Eterna
September 7, 2026 More Google removals Nalo
September 16, 2026 At least one app still live Kira

How the apps were connected

Gore-Kormanik and other researchers found recurring clues linking the apps together. Several shared developer usernames, email addresses, phone numbers and mailing addresses. Others appeared to share code, server architecture and payment infrastructure.

Dora, Romi, Luma and Eterna were tied to the same developer identity in app-store records. Dora, Romi and Luma also listed a nonprofit organization as the developer, but that organization said it had not built the apps and did not know about them.

Other apps, including Doni and Jovia, had their own shared indicators such as the same Hong Kong contact details and overlapping development history. Reviewers also reported seeing the same accounts, the same videos or recycled content across different brands.

That consistency matters because scammers often rely on fragmentation to avoid detection. Here, the branding changed, but the operational skeleton appears to have stayed the same.

What users were seeing on the front end

From the outside, these apps looked like ordinary dating products with playful names and promises of companionship. Their listings suggested that they could help users meet real people or start meaningful connections.

But user reviews painted a different picture. Some described fake accounts, repeated profiles, suspiciously fast replies and conversations that sounded generated. Others complained about being charged for what they believed should have been normal chat features.

One review of Kira said the user had arranged an in-person meeting only to discover the match was nowhere to be found. Another said the app used random video calls and required gems to chat with women who might not be real. Similar complaints appeared across multiple listings.

Why reviews mattered

Reviews provided a public breadcrumb trail before the technical analysis was completed. They also reinforced the idea that users were not simply unhappy with app quality — they were potentially encountering a coordinated fraud scheme.

When complaints mention repeat profiles, recycled videos and language that resembles large language model output, they become more than ordinary customer-service gripes. They are signals that the platform may be operating with fake identities and artificial engagement.

Why AI made the scam more effective

AI did not create romance scams, but it changed their economics. A scammer once had to spend hours writing messages manually, juggling conversations and improvising replies. Now a model can generate convincing dialogue nonstop, adapt tone and keep multiple chats alive at once.

In this case, Anthropic says multiple models were used for different tasks. Claude handled the main conversation layer, while a smaller non-Anthropic model helped with short suggestions for workers, moderation and attractiveness scoring. Another model generated avatar imagery.

This division of labor matters because it shows how fraud operators are mixing models to build end-to-end workflows, not just to polish text. The result is a system that can mimic human attention, respond quickly and sustain emotional engagement over time.

  • AI keeps conversations active 24/7.
  • Workers only need to intervene when the illusion risks breaking.
  • Money flows through in-app purchases rather than obvious transfer requests.
  • Multiple models can be swapped in and out if one provider blocks access.

Why this case is a warning for app stores and AI providers

The story is not just about scam dating apps. It is also about how easily generative systems can be inserted into consumer products with misleading branding, making abuse harder to spot from the outside.

App stores face a familiar but increasingly difficult problem: a fraudulent product can look polished, can mimic legitimate businesses and can vanish and reappear under new names. If the backend is flexible, takedowns may slow the operator without stopping the operation.

AI providers face a parallel issue. Even if a model company does not knowingly support fraud, its systems can still be used as the engine of deception when attackers embed them in a larger scheme.

That is why Anthropic’s report is notable. It is not simply saying “our model was abused.” It is showing how a whole business model can be built around that abuse, with each layer — model, payment, app store presence, worker incentives and backend infrastructure — supporting the next.

What happens next?

In the short term, the relevant question is whether the remaining apps and their backends are actually gone or simply renamed. If the code, infrastructure and payment relationships remain intact, the operation could reappear under new identities.

Longer term, the case may force both app stores and AI firms to think harder about how scams are detected when no single part of the system looks obviously illegal on its own. A dating app can claim to help people connect. A model provider can claim general-purpose use. A payment processor can claim to just move money. The scam thrives in the gaps between those claims.

For users, the lesson is more immediate: if a dating app is pushing rapid intimacy, metered chat and repeated excuses for why video calls never work, it may be optimized less for connection than for extraction.

Bottom line

Anthropic’s investigation suggests that AI is now being used to professionalize romance scams into fully managed digital businesses. The result is a new kind of fraud: not a fake lover asking for a wire transfer, but a polished app that charges people to keep talking to a machine pretending to care.

That shift matters because it raises the bar for detection. The scam is no longer just in the message — it is in the product itself.

Frequently asked questions

What did Anthropic uncover in the dating app scam case?

Anthropic uncovered a network of fraudulent dating apps that used AI personas, hired workers and paid chat credits to mislead users. The company says the operation handled millions of messages and reached tens of thousands of people across multiple apps.

How did the AI dating scam work?

The scam worked by presenting fake or semi-fake profiles as real dating matches, then using AI to sustain conversations and paid workers to verify human activity when needed. Users bought coins or gems to keep chatting, believing they were paying for access to real people.

Were real people involved in the fake dating apps?

Yes, but only in limited roles. Anthropic says some gig workers passed liveness checks or handled small parts of the interaction, while most of the conversation was handled by autonomous AI personas that could chat continuously without direct human input.

Are the apps still available on app stores?

Some were removed in late August and early September 2026, but not all at once. Anthropic said at least one app, Kira, was still available as of September 16, 2026, raising questions about how quickly Apple and Google responded.

Why does this AI dating scam matter?

This case matters because it shows how generative AI can be used to industrialize deception, not just assist it. The scam was built into the product itself, which makes it harder to detect and easier to scale than a traditional romance fraud.

Share this 🚀