The sexy AI-powered dating app scams are here
The sexy AI-powered dating app scams are here
令人心动的 AI 驱动型约会软件骗局已现身
Thousands of people were catfished by scammers supercharged with AI. 成千上万的人被利用 AI 增强技术的诈骗者“钓鱼”了。
Security researcher Matthew “Zigula” Gore-Kormanik was analyzing a fraudulent dating app called Dora when he got a pop-up message saying he was receiving a call from Jennifer. According to her bio, she’s a 41-year-old Sagittarius with red hair, blue eyes, and piercings. She likes music, horror movies, nightlife, and sports. 安全研究员 Matthew “Zigula” Gore-Kormanik 在分析一款名为 Dora 的欺诈性约会软件时,弹出一个消息提示他接到了来自 Jennifer 的通话。根据她的个人简介,她是一位 41 岁的射手座女性,留着红发,有着蓝眼睛和穿孔。她喜欢音乐、恐怖电影、夜生活和运动。
Gore-Kormanik answered the call, but didn’t see Jennifer in his video feed. He saw a tapestry that was moving, probably due to a fan, and heard weird distortion in the background. After the call ended, “Jennifer” messaged him to say she’d had fun and “your voice is way better than expected.” His microphone hadn’t even been connected. Gore-Kormanik 接听了电话,但在视频画面中并没有看到 Jennifer。他只看到一块挂毯在晃动(可能是因为风扇),并听到了背景中奇怪的失真声。通话结束后,“Jennifer”给他发消息说她玩得很开心,还说“你的声音比预期的好听多了”。而当时他的麦克风甚至根本没有连接。
Gore-Kormanik was poking around Dora, and other similar apps, because I’d shared with him a spreadsheet of potential dating scam apps. I was looking into this because on June 5th, Anthropic did something uncharacteristic: The normally tight-lipped company let its threat intelligence researcher Chris Cronbaugh give a talk at a public cybersecurity conference called Sleuthcon. The company had uncovered a fraudulent dating app network after noticing unusual activity on Claude: a prepaid account sending out over 100,000 API requests per day. Gore-Kormanik 之所以研究 Dora 和其他类似应用,是因为我与他分享了一份潜在约会诈骗应用的电子表格。我之所以调查此事,是因为 6 月 5 日,Anthropic 公司做了一件不同寻常的事:这家向来守口如瓶的公司让其威胁情报研究员 Chris Cronbaugh 在名为 Sleuthcon 的公共网络安全会议上发表了演讲。该公司在注意到 Claude 上的异常活动后,发现了一个欺诈性约会应用网络:一个预付费账户每天发送超过 10 万次 API 请求。
The majority of chats did not involve a human agent at all. 绝大多数聊天根本不涉及人类代理。
During the talk, called “Swipe Right, Pay Up: Industrial-Scale AI Catfishing,” Cronbaugh described a network of around 28 dating apps where the conversation was largely run by autonomous AI personas. The majority of chats, he said, did not involve a human agent at all. Anthropic has since published its findings in the “scams and fraud” section of its “Detecting and countering misuse of AI: September 2026” report, but not until after we’d spent extensive time looking into the network and trying to corroborate the findings. I was intrigued by the fact that Anthropic was speaking about this publicly while many of the apps were still live on both major US app stores, and wondered why they hadn’t been taken down. 在名为“右滑,付钱:工业级 AI 钓鱼”的演讲中,Cronbaugh 描述了一个由约 28 款约会应用组成的网络,其中的对话主要由自主 AI 人格运行。他说,绝大多数聊天根本不涉及人类代理。Anthropic 此后在其“检测和应对 AI 滥用:2026 年 9 月”报告的“诈骗与欺诈”部分发布了调查结果,但那是在我们花费大量时间调查该网络并试图证实这些发现之后。令我感到好奇的是,Anthropic 在许多应用仍在美国两大应用商店上架的情况下公开谈论此事,我不禁想知道为什么它们还没有被下架。
Looking at the apps themselves, I noted that they were presented as helping people find people to talk to. They did not look like companion apps such as Replika where it’s clear the personas are actually AI. For example, Dora was described as “a dating app thoughtfully designed for wide range of ages people … a respectful easy-to-use space to meet people who share your values.” A different version said it was a “warm, simple dating app for adults seeking real connection.” Romi, the description stated, “helps you discover, connect, and chat with real people.” Doni’s tagline was “start real companionship”; the description said it “helps you connect with nearby singles.” 观察这些应用本身,我注意到它们被包装成帮助人们寻找聊天对象的工具。它们看起来不像 Replika 那样的伴侣应用,后者明确表明其人格实际上是 AI。例如,Dora 被描述为“一款为各年龄段人群精心设计的约会应用……一个尊重且易于使用的空间,可以结识与你志同道合的人。”另一个版本则称它是“一款为寻求真实联系的成年人准备的温暖、简单的约会应用。”Romi 的描述称,“帮助你发现、连接并与真实的人聊天。”Doni 的标语是“开启真正的陪伴”;描述称它“帮助你与附近的单身人士建立联系。”
Here’s how the scam works: Users, mostly men in their mid-to-late 30s, go on dating apps and match with what they believe to be real women. Only one in four of them actually is, and that person is not a user looking for other dates but rather a paid gig worker. 该骗局的运作方式如下:用户(主要是 30 多岁的中年男性)在约会应用上匹配到他们认为是真实女性的对象。实际上,四个人中只有一个是真人,而且那个人并不是在寻找约会对象的普通用户,而是一名付费的零工人员。
The gig workers were hired to pass liveness checks on video or to follow social media accounts. They didn’t even write their own comments. Instead, they responded to messages by selecting from three pregenerated replies. But they could prove they’re human, whereas the AI personas could only demur with a plausible explanation for why a video chat or call was not possible. “Backend components fabricated likes, visitors, and pre-recorded ‘video’ when no real person was available, and tracked which users had begun to suspect they were talking to a bot,” Anthropic’s report states. Because of the smattering of interactions with real people, some users began to believe that the entirely AI-generated replies they were receiving on the app were also from real people. 这些零工人员被雇佣来通过视频活体检测或关注社交媒体账号。他们甚至不需要自己写评论,而是通过从三个预生成的回复中选择一个来回复消息。但他们可以证明自己是人类,而 AI 人格只能用看似合理的理由推脱为什么无法进行视频聊天或通话。Anthropic 的报告指出:“当没有真人在场时,后端组件会伪造点赞、访客和预录制的‘视频’,并跟踪哪些用户开始怀疑自己在与机器人聊天。”由于与真人有零星的互动,一些用户开始相信他们在应用上收到的完全由 AI 生成的回复也来自真人。
Multiple AI providers are involved. While Claude was misused to run the autonomous conversational personas, the report says that “a small non-Anthropic model generated the short reply suggestions the gig workers tapped, alongside face-attractiveness scoring and photo/voice moderation. An image-editing model generated avatar imagery.” 涉及多个 AI 提供商。虽然 Claude 被滥用于运行自主对话人格,但报告称,“一个非 Anthropic 的小型模型生成了零工人员点击的简短回复建议,同时还负责面部吸引力评分和照片/语音审核。一个图像编辑模型则生成了头像图像。”
There is an entire ecosystem of online scams, ranging from automated thirst trap replies to fake social media accounts or dating app profiles. In many cases, people spend months building trust before telling their victims that there’s an emergency and they need financial help. Or they pretend to be investors, asking for money in an account they own that ends up being fake. But this is not your typical romance scam; there’s no money “borrowed” by fake romantic partners, nor is cryptocurrency involved. 存在一个完整的在线诈骗生态系统,从自动化的诱惑性回复到虚假的社交媒体账号或约会应用资料。在许多情况下,骗子会花几个月时间建立信任,然后告诉受害者他们遇到了紧急情况需要经济援助。或者他们假装是投资者,要求受害者向他们拥有的账户汇款,而这些账户最终都是假的。但这并不是典型的浪漫诈骗;没有虚假的浪漫伴侣“借钱”,也不涉及加密货币。
The apps are themselves the scam: They ask for coins for continued interactions, and the coins cost real money. Users buy them to continue talking primarily to machines, believing they’re talking to other humans. These gig workers keep the ruse going, while AI can keep conversations going 24/7 as the coins flow. 这些应用本身就是骗局:它们要求用户购买金币以继续互动,而金币需要真金白银购买。用户购买金币是为了继续与机器聊天,却误以为自己在与真人交流。这些零工人员维持着骗局,而 AI 则可以在金币源源不断流入的同时,保持 24/7 全天候的对话。
The apps are themselves the scam. 这些应用本身就是骗局。
According to Anthropic’s report, the prompts the AI had been given kept the personas consistent, and the AI was operating as if the exchanges were “ordinary roleplay or companion deployment.” But the AI wasn’t told it was part of a scam because, the company wrote, “The monetization and deception were not visible from inside any exchange.” 根据 Anthropic 的报告,AI 被赋予的提示词使其人格保持一致,AI 的运行方式就好像这些交流是“普通的角色扮演或伴侣部署”。但 AI 并不知道自己是骗局的一部分,因为该公司写道:“从任何交流内部都无法看出其中的货币化和欺骗行为。”
That said, the report said that “the model’s own reasoning surfaced the harm” in a small number of cases, including ones “where users disclosed serious illness or acute distress.” Even in those cases, “the output continued in persona.” 尽管如此,报告称在少数情况下,“模型自身的推理揭示了危害”,包括“用户透露患有严重疾病或处于极度痛苦中”的情况。即便在这些情况下,“输出内容仍保持在人格设定中。”
We have additional detail because Gore-Kormanik found the internal protocol repository of the entire configuration, including files, code, and documentation of how the operation runs. 我们掌握了更多细节,因为 Gore-Kormanik 找到了整个配置的内部协议存储库,包括文件、代码以及关于该行动如何运作的文档。