Security researchers at Anthropic uncovered a network of roughly 28 fraudulent dating apps where artificial intelligence personas conducted most conversations with users who believed they were chatting with real people, according to the company's September 2026 report on AI misuse. The operation came to light after Anthropic detected unusual activity on its Claude AI system—a prepaid account just five days old that was suddenly firing off more than 100,000 API requests daily. The apps, which included titles like Dora, Romi, Luma, and GraceChat, charged users coins for continued interactions, with those coins costing real money, while AI bots kept conversations running around the clock.

During a two-week period in April, Anthropic identified over 4,700 distinct fabricated AI personas engaging with at least 25,000 unique individuals, generating roughly 2.36 million messages. The scam targeted mostly men in their mid-to-late 30s, with only one in four matches connecting users to actual humans—and those weren't other daters but paid gig workers hired to pass liveness checks on video calls or follow social media accounts. These workers didn't even compose their own messages, instead selecting from three pre-generated replies to maintain the illusion. The apps worked across Asia outside China but only activated their monetization features outside Asia entirely, keeping revenue flowing while avoiding enforcement in the operators' home region.

The report states that backend systems "fabricated likes, visitors, and pre-recorded 'video' when no real person was available, and tracked which users had begun to suspect they were talking to a bot." Because users had occasional interactions with real gig workers, they came to believe the entirely AI-generated responses they received were also from genuine people. The operation involved multiple AI providers—while Claude powered the conversational personas, a separate smaller model generated the short reply suggestions that gig workers tapped, alongside face-attractiveness scoring and photo moderation, and an image-editing model created avatar imagery. According to the report, the AI operated as though the exchanges were "ordinary roleplay or companion deployment," and the monetization and deception weren't visible from inside any individual conversation.

Anthropic attributes the operation to a China-based actor based on Chinese-language internal documentation and China-native infrastructure, including Tencent Cloud's messaging and video services, internal documents hosted on Feishu, and source code stored on Chinese platform Gitee. The apps deliberately concealed their connections through different developer identities and accounts, with some falsely listing a nonprofit called Alliance Against Human Trafficking as their developer—an organization that told investigators it had no knowledge of the apps. Security researcher Matthew Gore-Kormanik discovered an internal protocol repository accidentally shipped inside one app that detailed how operators monitored gig workers, recorded calls, transcribed conversations, and even described the process of pretending people had called users to lure them into conversation. The apps would behave like legitimate dating platforms during app store review, then activate the AI network and coin meter once approved, while in-app browsers redirected payments to third-party processors that could be hidden during review.

Anthropic's threat intelligence researcher Chris Cronbaugh emphasized that disrupting these networks requires "cross-industry collaboration across app stores, payment platforms, and AI labs," noting that when accounts get banned, operators quickly create new ones or switch to different AI providers within about a day. The company shared its investigative findings directly with Apple and Google, and most apps were removed from both stores by early September 2026, though one app called Kira remained live on the Google Play Store as of September 16th. The report concludes that this operation was built and run as a genuine company with a real engineering team, modern tooling including AI coding assistants, design documents, roadmaps, and growth plans—treating fraud as a business with concerns about revenue, costs, and efficiency. Cronbaugh warned that as long as apps stay on storefronts and payments keep flowing, the barrier to re-entry remains low for sophisticated scammers operating like legitimate businesses. The case reveals how easily monetization schemes can hide behind AI's conversational capabilities when platform controls rely on pre-approval reviews rather than ongoing behavioral monitoring. For app stores and payment processors, the challenge isn't just detecting individual bad actors but recognizing when emerging AI tools fundamentally change the economics of deception at scale.