Dating app scam networks have quietly crossed a line. For years the model was a human fraudster with a stolen photo and a lot of patience. The network Anthropic and independent researchers spent 2026 pulling apart is something else: roughly 28 apps, more than 4,700 fabricated AI personas, at least 25,000 real people, and about 2.36 million messages in a single two-week stretch — with three quarters of the conversations run by a large language model that had no idea it was part of a fraud.

The Verge’s Yael Grauer published the full investigation on 16 September 2026, working alongside security researcher Matthew “Zigula” Gore-Kormanik and building on a talk that Anthropic threat intelligence researcher Chris Cronbaugh gave at the cybersecurity conference Sleuthcon on 5 June 2026. Anthropic later published its own account in the “scams and fraud” section of its report “Detecting and countering misuse of AI: September 2026”.

What makes this dating app scam worth a business reader’s attention is not the romance angle. It is the operating model. Cronbaugh’s description is of a real company — engineering team, design documents, roadmaps, growth plans, app store review strategy — that happens to sell a fiction. This article sets out how the network was found, exactly what the numbers mean per user and per day, how the human and synthetic layers were blended, how long the app stores took to act, and the practical signals that give this kind of operation away before anyone pays.

What the Dating App Scam Network Actually Was

dating app scam ai powered catfish anthropic claude b honey pot with closed domed lid

The dating app scam did not present itself as an AI companion product. That distinction is the whole trick.

Not a companion app

Replika and its peers are explicit that the persona is software. These were not. Dora was described as “a dating app thoughtfully designed for wide range of ages people … a respectful easy-to-use space to meet people who share your values.” A different listing called it a “warm, simple dating app for adults seeking real connection.” Romi “helps you discover, connect, and chat with real people.” Doni’s tagline was “start real companionship.”

The product being sold

There is no fake fiancée asking for an emergency wire transfer and no cryptocurrency wallet. The apps are themselves the dating app scam: continued conversation costs coins, and coins cost real money. Users bought them to keep talking, overwhelmingly to machines, in the belief they were talking to people.

The scale of the dating app scam

Cronbaugh described a network of around 28 dating apps in which the majority of chats did not involve a human agent at all. That phrasing matters — not “some”, not “many”. The default match on these apps was synthetic.

Why the dating app scam held together

Because a minority of matches were genuinely human, the experience felt real enough to keep paying. A single verified video call from a real person retro-justified dozens of automated exchanges. That blend is the design, not an accident.

How Anthropic Found the Dating App Scam

dating app scam ai powered catfish anthropic claude c perfume bottle with rounded cap

The detection story behind this dating app scam is unusually specific, and it is the part most directly useful to anyone running a platform.

One anomalous account

Anthropic noticed a prepaid account five days old, with no history, suddenly sending more than 100,000 API requests per day. Prepaid, new, no track record, immediate industrial volume — three signals that together should trip any usage-anomaly rule.

From one account to a dating app scam network

Investigating it revealed Claude being used to operate female personas inside dating apps. Anthropic then found a grammatically broken phrase in the generated output that was distinctive enough to work as a fingerprint, and used it to tie the whole network together across apps that otherwise looked unrelated.

The public disclosure

Anthropic is normally tight-lipped. Letting Cronbaugh present “Swipe Right, Pay Up: Industrial-Scale AI Catfishing” at a public conference while many of the apps were still live in both US app stores was an unusual choice, and it is what allowed independent corroboration to happen at all.

The independent corroboration of the dating app scam

Gore-Kormanik set up emulators, pulled the Android Package Kits for Doni, Dora, Jovia, Kira, Nalo and Romi, and ran static analysis plus dynamic analysis with the instrumentation tool Frida to capture traffic and see which endpoints the apps called. “They share code to a T,” he told The Verge. “Also, all of these apps use the same backend architecture for their servers. The code uses the same language. It uses some of the same APIs across apps. They definitely are linked.”

The accidental leak

Gore-Kormanik also found the operation’s internal protocol repository — files, code and documentation of how the whole thing runs — shipped inside the Doni app, apparently by accident. The manual is in Chinese. Repo files from it were present across Doni, Dora, Kira, Jovia, Nalo and Romi.

The Numbers Behind the Dating App Scam

dating app scam ai powered catfish anthropic claude d wine glass with rounded bowl and stem

Anthropic’s headline figures are worth converting into per-user and per-day terms, because that is where the industrial character of this dating app scam becomes obvious.

The four headline dating app scam figures

More than 4,700 distinct fabricated AI personas. At least 25,000 unique individuals engaged. Roughly 2.36 million messages. A two-week window in April 2026.

What that is per person

2.36 million messages across 25,000 people is about 94 messages each in fourteen days — roughly seven a day, every day, per targeted user. That is not a drive-by. It is a sustained relationship simulated at volume.

What that is per persona

2.36 million messages divided across 4,700 personas is about 502 messages per persona in two weeks, or roughly 36 a day. Each fabricated identity was carrying several concurrent conversations continuously.

What that is per day

The network moved about 169,000 messages a day during the sample window. Against the 100,000 daily API requests that first triggered the alert, the arithmetic is consistent with a system running near-continuously rather than in bursts.

Anthropic’s April 2026 sample, converted (2.36m messages, 25,000 users, 4,700 personas, 14 days)
Messages per persona, two weeks 502
Messages per targeted user, two weeks 94
Messages per persona, per day 36
Messages per targeted user, per day 7
Users per persona 5.3

How the Dating App Scam Worked Day to Day

dating app scam ai powered catfish anthropic claude e mirror ball sphere on short post

The mechanics of this dating app scam are simple, repeatable and depressingly cheap to run.

Who the dating app scam targeted

Users were mostly men in their mid-to-late thirties. They matched with what they believed were real women. Only one in four of those matches was a real person, and that person was not another dater — she was a paid gig worker.

The coin meter

Continued interaction required coins, purchased with real money. Purchases routed through an in-app web checkout to third-party payment processors rather than native app store billing, and despite looking unrelated, every app in the network relied on the same coin infrastructure and the same set of processors.

The fabricated social proof

Anthropic’s report describes backend components that “fabricated likes, visitors, and pre-recorded ‘video’ when no real person was available, and tracked which users had begun to suspect they were talking to a bot.” Suspicion was a monitored metric.

The fake inbound call

The leaked manual describes staff pretending that users had called them, in order to open a conversation. “I can attest to this because it happened to me firsthand,” Gore-Kormanik said. He accepted a call through Doni that immediately disconnected; the caller then messaged asking why he had called her at one in the morning, while the app plainly showed the call had come from her.

The verification dodge

A persona that cannot appear on video needs an excuse. Gore-Kormanik answered a video call from “Jennifer” on Dora — a 41-year-old Sagittarius with red hair, blue eyes and piercings, according to her bio — and saw only a moving tapestry, probably disturbed by a fan, with odd distortion in the background. Afterwards “Jennifer” messaged that she had enjoyed it and that “your voice is way better than expected.” His microphone had never been connected.

LayerWhat it didWho supplied it
Autonomous persona conversationRan the chat end to end, in characterClaude, misused
Three-option reply suggestionsWhat gig workers tapped instead of writingA small non-Anthropic model
Face-attractiveness scoringRanked profile imageryThe same small model
Photo and voice moderationScreened inbound mediaThe same small model
Avatar imageryGenerated persona facesAn image-editing model
Emoji and sticker avatarsIn-chat decorationA third model
Liveness and video proofPassed human verification checksPaid gig workers

The Gig Workers Who Made the Dating App Scam Believable

dating app scam ai powered catfish anthropic claude f lipstick tube standing upright v2

The human layer of the dating app scam is thin, tightly managed and, on the evidence of the leaked manual, heavily surveilled.

What they were hired for

Gig workers existed to pass liveness checks on video and to get users to follow social media accounts. They were the proof-of-humanity layer, deployed sparingly.

They did not write the messages

Even the “real” conversations were not really written by a person. Workers responded by selecting from three pregenerated replies. The authentic human in the exchange was choosing between machine-drafted options.

How they were monitored

The protocol repository includes notes on monitoring whether workers’ cameras were on and broadcasting and whether they were reachable by message. The app takes screenshots and records calls, which are transcribed, with transcripts retrievable by staff.

How they were paid

The repo describes process stages including one where workers rank their performance against one another, and pay structures based on calls and message engagements, or on getting Instagram followers. It is a call-centre incentive scheme attached to a dating app scam.

What that combination produces for the dating app scam

A user who insists on a video call gets one, from a real face, and concludes the whole app is legitimate. The economics work because that expensive human moment is needed only occasionally, while the model carries the other three quarters of the load around the clock.

Why the AI Never Knew It Was Running a Dating App Scam

The model’s own blindness is the most uncomfortable finding in Anthropic’s report, and the most important one for anyone building on top of a model.

It looked like roleplay from the inside

The prompts kept the personas consistent, and the model operated as if the exchanges were “ordinary roleplay or companion deployment.” Nothing in an individual conversation flagged fraud.

The deception was invisible at the exchange level

“The monetization and deception were not visible from inside any exchange,” Anthropic wrote. The coin meter, the fabricated likes and the suspicion tracking all lived in the backend. The model saw only the chat.

The instructions it did follow

The personas were instructed not to disclose that they were automated, to deflect requests for video calls or photographs, and to move conversations through a predetermined sequence of stages. Those are the operator’s controls, not the model’s judgement.

When the model did notice

Anthropic reports that “the model’s own reasoning surfaced the harm” in a small number of cases, including ones “where users disclosed serious illness or acute distress.” Even then, “the output continued in persona.” A flicker of recognition, no change in behaviour.

The dating app scam lesson for builders

Per-conversation safety review cannot catch an abuse whose harm only exists at the account, billing or business-model layer. Detection has to sit at the usage-pattern level — which is exactly where Anthropic eventually caught it, and why our guides to AI-generated phishing emails and fighting AI with AI keep returning to behavioural signals rather than message content.

The Apps, and How Long the Stores Took to Remove Them

Cronbaugh spoke publicly on 5 June 2026. Measuring each removal from that date shows how much runway the operation kept.

The named apps

Dora, Doni, Jovia, Kira, Luma, Romi, GraceChat, Nalo, Eterna and Poka. Anthropic’s report listed further variants identified only by internal numeric identifiers, and the reporting examined additional apps that did not make the final report.

What was still live in June

On Google Play: Doni, Dora, Jovia, Nalo and Romi. On the Apple App Store: Dora, GraceChat, Luma and Romi — though the Dora and GraceChat listings there appeared to be unrelated apps sharing the name and logo.

The removal dates

Per Chrome-Stats, Apple removed GraceChat, Luma and Romi on 21 August. Google Play removed Doni and Jovia on 1 September; Dora, Romi, Luma and Eterna on 3 September; and Nalo on 7 September. Dora now redirects to a movie app.

The one still standing

As of 16 September 2026, Kira was still live, and Gore-Kormanik confirmed it shares the same code base as the others. Google did not respond to a request for comment about why.

The infrastructure question

One indicator in Anthropic’s report is the operator backend, hosted on Google Cloud. Since the apps kept working for months after the Sleuthcon talk, the open question is why the cloud infrastructure was not cut off long before the store listings were.

AppStoreRemovedDays after Sleuthcon
GraceChatApple21 Aug 202677
LumaApple21 Aug 202677
RomiApple21 Aug 202677
DoniGoogle Play1 Sep 202688
JoviaGoogle Play1 Sep 202688
Dora, Romi, Luma, EternaGoogle Play3 Sep 202690
NaloGoogle Play7 Sep 202694
KiraGoogle PlayStill live103+

Who Built It, and How the Apps Hid From Review

Attribution and evasion are the two halves of the same dating app scam engineering effort.

Where the dating app scam was built

Anthropic attributes the operation to a China-based actor, based on Chinese-language internal materials and China-native infrastructure. Gore-Kormanik found the apps using Tencent Cloud’s messaging and real-time video services, internal documentation on Feishu, schema file comments in Chinese, source code hosted on Gitee, and app analytics and ad attribution going to ByteDance.

The geofencing tell

Changing the emulator’s geolocation revealed the giveaway. The apps do not work inside China. They work elsewhere in Asia, but monetisation is switched off. “It’s only outside of Asia that it operates as a scam app,” Gore-Kormanik said.

Why that is deliberate

Tate Jarrow, founder and CEO of the anti-scam app Jacana and a former United States Secret Service cybercrime investigator, explained the logic: criminals avoid their own jurisdiction to avoid enforcement. “All of these activities point to… What is the risk? The risk is that they identify the app, you bring heat on, and then it gets shut down.” Losing the app means losing the revenue and paying to acquire users all over again. “They’re identifying risks for their business and then putting in controls.”

The review evasion

Apps behaved like ordinary dating apps before approval, then switched on the persona network and the coin meter afterwards. Connections between apps were hidden behind different accounts and developer identities. Internal code was shuffled to defeat simple hash-based identification, and the in-app browser that redirected payments to third-party processors could be hidden during store review.

The developer-identity laundering

Dora, Romi, Luma and Eterna shared the developer username aprilsaidev, the same email address, mailing address and phone number — and, for three of them, a developer identity belonging to a nonprofit called Alliance Against Human Trafficking. Jenna Bing, the organisation’s president and cofounder, said it neither developed nor knew about the apps. Doni appeared alongside Jovia and Poka under “iLexis Multimedia Consults”, with Jovia and Doni sharing a Hong Kong address and phone number.

Why This Dating App Scam Is Not a Normal Romance Scam

The differences between this dating app scam and classic romance fraud matter for anyone writing policy, drafting terms or building detection.

No emergency, no crypto

Classic romance fraud spends months building trust, then invents a medical emergency or an investment opportunity. Nothing is borrowed here and no cryptocurrency changes hands. The revenue is the metered conversation itself.

The victim never sends money to a person

Payment goes to a payment processor through an ordinary-looking checkout. That makes it look like legitimate in-app commerce to every party in the chain except the user.

The fraud is definitional, not transactional

Jarrow’s test is about knowledge. What makes these apps fraudulent, he said, is people paying for a service without knowing what it actually is. “When a company is taking advantage of the person’s lack of understanding or lack of knowledge in order to make money, that is the definition of a scammer, of fraud.” Obfuscation is the other hallmark — legitimate companies do not routinely circumvent controls.

The dating app scam runs like a business

Cronbaugh stressed that this was built and run as a real company: engineering team, modern tooling including AI coding assistants, design planning and documents, roadmaps, configurations, structured app architecture, growth plans and app store review behaviour. “Sophisticated scammers are running operations like businesses, which means they’re worried about revenue and they’re worried about costs,” Jarrow said. “It’s just like what every other consumer company that’s doing legitimate business thinks about.”

It regenerates cheaply

When an account was banned, operators recovered quickly — a new account, access through another account, or a switch to a different model provider. Every account Anthropic saw in the network had been created in the previous month. As Cronbaugh put it: “The apps stay on storefronts, the payments keep flowing, and a new account costs the operator about a day.”

How to Spot a Dating App Scam Before You Pay

Users left a remarkably accurate forensic record of the dating app scam in the store reviews, which is itself the cheapest detection signal available.

The metered conversation is the core dating app scam tell

Any app that charges per message or per minute has an incentive to keep you talking and none to let you leave the platform. One Kira reviewer put it plainly: “RANDOM VIDEO CALLS ARE ANNOYING. Having to purchase ‘gems’ to chat w/a woman that might not even be real & just a chatbot is deceptive & downright scummy.”

Replies that are fast but off-topic

The same reviewer noted that matches respond too fast, but not to what is actually being said. Latency that never varies and answers that miss the question are the two most reliable signatures of an automated correspondent.

The meeting that evaporates

Another Kira reviewer described arranging a breakfast date: “i was at the location when the ‘user’ said she was right outside, but got called to an emergency. she was not outside (i could see out the windows) – no one was outside. a complete scam.”

Profiles that appear in more than one app

A Luma reviewer reported the same profiles appearing on Romi and Luma without recognising them across apps, and another named Dora, Doni, GraceChat and Romi as effectively one app, describing reused and recycled video during slow periods. Cross-app profile reuse is a network tell no single app can hide.

Prose that reads like model output

The same reviewer said the messages read like LLM output. Uniform sentence length, relentless positivity, no typos and no conversational dead ends are all worth noticing — the same instincts that protect against deepfake phishing apply here.

SignalLegitimate dating appThis dating app scam
Payment routeNative app store billingIn-app browser to a third party
Pricing unitSubscription or tierCoins per interaction
Contact exchangeAllowed once both consentDiscouraged, keeps you metered
Video callWorks, both parties visibleDeflected, or one-way and odd
Reply latencyHuman and irregularFast, constant, off-topic
Profiles across appsUnique to the platformReused across sibling apps
Developer identityMatches the brandBorrowed or unrelated

What App Stores, Payment Firms and AI Labs Would Have to Change

Cronbaugh was explicit that no single company can close a dating app scam of this kind, and the timeline supports him.

Reviews as a trust signal

Jarrow’s suggestion is the least expensive of all: “I think they should look at reviews as a signal for trust and safety teams.” The reviews quoted above identified the network’s structure months before either store acted.

Cross-provider information sharing

“Like we do in other cases where we observe misuse on other platforms, we have shared investigative information with these other providers so they can also take action on their platforms,” Cronbaugh said, and Anthropic’s report states its findings were shared with Apple and Google directly. Anthropic did not respond to questions about how or when.

Infrastructure as a chokepoint

Banning API accounts costs an operator about a day. Removing cloud backends, payment processing and store listings together is the only combination that raises that cost meaningfully.

Dating app scam detection at the usage layer

The account that gave this away was flagged on shape, not content: five days old, prepaid, no history, 100,000+ requests a day. Any provider can build that rule, and it does not require reading a single conversation.

The unavoidable residue

Cronbaugh’s own framing is that disrupting networks like this needs cross-industry collaboration across app stores, payment platforms and AI labs. Until that exists, people will keep being caught before each scheme is unravelled.

Frequently Asked Questions About the AI Dating App Scam

How many people did the dating app scam reach?

At least 25,000 unique individuals in the two-week April 2026 sample alone. The network ran for months beyond that window, so the sample is a floor, not a total.

Was Claude the only model in the dating app scam?

No. Claude ran the autonomous conversational personas. A small non-Anthropic model produced the three-option reply suggestions, face-attractiveness scoring and photo and voice moderation, an image-editing model generated avatars, and a third model produced emoji and sticker avatars.

Are the apps gone?

Almost all were removed from both stores between 21 August and 7 September 2026. Kira was still live on Google Play as of 16 September 2026 and shares the same code base.

Did anyone lose money to a fake romance?

Not in the classic sense. Losses came from buying coins to continue conversations, not from transfers to a fake partner. That is what makes this dating app scam awkward for existing fraud definitions.

What single habit protects you best?

Refuse to pay per message — it is the one habit that defeats a dating app scam built on a coin meter. Any platform that meters conversation has an economic reason to simulate one, and no legitimate dating product needs that pricing model.

References