Anthropic Just Exposed a Network of 20+ Fake Dating Apps Where 3 Out of 4 Profiles Were AI. Here Are the Names, and the Tells That Still Work.

0

Anthropic Just Exposed a Network of 20+ Fake Dating Apps Where 3 Out of 4 Profiles Were AI. Here Are the Names, and the Tells That Still Work.

Glowing smartphone on dark bedding displaying four profile cards

For two weeks in April 2026, a China-based app studio ran more than 20 dating apps in which roughly three out of every four profiles you could match with were AI personas powered by Anthropic’s Claude. In that single fortnight, over 4,700 distinct Claude-driven personas held conversations with at least 25,000 real people, generating approximately 2.36 million messages, Anthropic disclosed in its September 10 threat intelligence report.[R1][R2] The apps targeted US users, and there was no in-app way to tell a bot from a person.[R3]

This is the first time a frontier AI lab has published hard operational numbers on covert AI matches at industrial scale, and it changes what a suspicious conversation means. If you have ever thought “this feels scripted” or “why won’t she video call,” you were pattern-matching against something real. The report, case GTG-15001, describes the scripts, the deflection rules, the paid humans, and the coin economy in enough detail to build a detection protocol from the operator’s own blueprint. That protocol is at the end of this article, and it starts with bad news about the standard advice.

The apps: names, packages, and where they stand today

Anthropic named ten consumer brands and two Android package identifiers, and said further variants were identifiable only by internal numeric IDs.[R2] We checked the two named Android packages on Google Play today, September 14, 2026: both return “page not found,” so at minimum those two listings are gone. Anthropic also said it handed publisher identities and platform-specific evidence directly to Apple and Google.[R2] Whether every brand is dead on every storefront is something only Apple and Google can confirm; treat the list below as “avoid and verify,” not “confirmed removed.”

The named network
Brands and identifiers from Anthropic’s GTG-15001 disclosure, plus our own storefront check on September 14, 2026.
BrandIdentifier / statusNotes
DORANamed brandPart of 20+ app variants run by one China-based studio. Variants used deliberately differentiated class names to defeat app-store clone detection. [R2]
DONINamed brand
ROMINamed brand
LUMANamed brand
JOVIANamed brand
KIRANamed brand
GRACECHATNamed brand
HAVENNamed brand
NALONamed brand; Android package com.cavalier.nalo 404 on Google Play (checked 9/14/26)
LOVIANamed brand; second named package com.qiga.vio 404 on Google Play (checked 9/14/26)

A structural warning before the mechanics: none of these are Tinder, Bumble, or Hinge. The report describes unknown brands, typically downloaded outside the mainstream app ecosystem, monetizing by the message. If the app you are on charges you coins to keep one specific conversation going, that alone should end the conversation.

Three of every four profiles: the ratio was a staffing decision

What your swipe feed actually contained
Composition of the match pool across the network’s apps during the observed April 2026 window, per Anthropic. Each square is 1% of profiles you could encounter.
AI persona run by Claude (75%) Human gig worker, paid to pass verification (25%) 75 of every 100 profiles you could match with: AI. The other 25: paid staff.

The 75/25 split is not an accident of popularity. The operation deliberately staffed one human gig worker for every three AI personas.[R4] Do the arithmetic on the disclosed numbers and the scale becomes concrete:

2.36 million messages over 14 days is roughly 168,600 messages a day, about 117 a minute around the clock. Spread across 4,700 personas, each AI identity sent about 500 messages in two weeks, roughly 36 a day: one bot out-talking what most human daters send in a week, forever, with no bad days. Spread across the 25,000 real people on the other end, each victim exchanged about 94 messages in a fortnight, nearly seven a day. That is a full correspondence. It is the volume at which people form attachments, and it was the point.

How the machine worked

Anthropic’s case study describes a production line, not a chatbot. Claude sustained thousands of concurrent in-character conversations. Personas were instructed never to admit they were automated, to deflect any request for a video call or photo, and to move each user through a fixed sequence of conversational stages.[R2] When a user demanded proof of life, a paid human stepped in. When no human was free, the backend fabricated likes, visitor records, and pre-recorded video clips, while simultaneously tracking whether the user had begun to suspect a bot.[R5]

The human-machine division of labor inside GTG-15001
Reconstructed from Anthropic’s disclosure as reported by CNBC TV18 and BigGo Finance. AI did the volume; humans did the two verifications AI could not fake; a payment meter monetized both.
YOU real user, ~94 msgs per two weeks One of 20+ app variants (DORA, NALO, KIRA…) 4,700+ Claude personas scripted stages · never admit automation deflect video / photo requests · ~36 msgs/day each Human gig workers (25% of pool) paid per message, per video call, per follow-back exist only to pass authenticity checks Second, smaller AI model feeds workers 3 tap-to-send replies scores photo attractiveness Backend fabrication + suspicion tracker fake likes, fake visitors, pre-recorded videos tracks bot suspicion flags COIN METER messages and matches run on metered quota; refills cost real money via in-app virtual currency the revenue model escalation handoff quota burns cash-out to workers

The economics close the loop. Users paid per message through metered quotas, refilled with purchased in-app coins. Gig workers were paid per message sent, per video call completed, and per social-media follow-back, with cash-out above a low threshold.[R5] Your loneliness funded the payroll of the people pretending to cure it.

Why it worked as a business: the engagement-to-payment loop
Each stage feeds the next. The design goal of every stage is the one after it.
1. Free hook instant match from a 75% synthetic pool; fabricated likes and “visitors” boost ego 2. Scripted bond fixed stages of escalation; ~7 msgs a day builds a two-week attachment 3. Quota wall free messages run out mid-conversation; the meter, not the match, sets the pace 4. Coin purchase pay to keep talking to one “person”; sunk cost plus attachment lock-in 5. Re-hook paid human passes one video call, doubt collapses, loop restarts renewed trust funds the next quota cycle

The video-call test was part of the product

Here is the finding that should rewrite the advice columns. The standard guidance for spotting a fake profile is: ask for a video call, and check whether they follow you back on social media. This operation did not fail those tests. It staffed them. Gig workers were paid specifically for video calls and follow-backs, because those were “the authenticity checks that AI alone couldn’t fake,” as CNBC TV18 put it in its account of the report.[R2]

So calibrate what each test can actually prove. A successful video call proves a human being exists somewhere in the loop. It does not prove that the human is the same “person” who spent two weeks texting you: in this operation, the rapport was built by Claude and the face belonged to a contractor paid per call. A follow-back proves a paid action was completed. TechJournal’s summary of the report states the limitation flatly: a video call cannot prove a profile is real, because real workers handled some calls while AI personas handled the conversation.[R3]

The tests that still work target the layers the operator could not route around: the payment meter, the script, and physics.

The bot-match protocol: six tests derived from GTG-15001’s own design
Each test targets a constraint the operation could not engineer away. Run them in order; any red answer is enough to stop paying and leave.
TEST 1 · The coin meter (strongest, costs nothing) Ask: does continuing this conversation require buying credits, coins, or quota refills? GTG-15001 metered every message and match. No honest dating app charges per message to one specific match. YES to payment wall: leave. Done. No: continue to Test 2 TEST 2 · Break the script Personas ran on fixed conversational stages. Jump topics hard, ask a hyper-specific local question, contradict something you said yesterday. A stage machine smooths over the break with generic warmth. Ignores or launders the break: red Engages the specifics: continue TEST 3 · Availability physics These personas averaged ~36 messages a day each, instantly, 24/7, never busy, never irritable. Perfect consistency is the tell; human inconsistency is the proof of life you are looking for. Instant replies at 3am for weeks: red Has a life, delays happen: continue TEST 4 · The exit door Propose moving off-app (regular texting, a call, meeting for coffee). GTG-15001 deflected video and photo requests and kept users inside the coin meter. The app was where the money was; you were not. Structural excuse to stay in-app: red Genuinely wants out of the app: continue TEST 5 · Verification symmetry You send photos and details freely; they send pre-recorded clips and deflect live, unscripted proof. Reverse-image-search their photos. Asymmetry means you are being processed, not met. One-way visibility: red Mutual, spontaneous proof: continue TEST 6 · The app’s own pedigree Search the brand, the developer, the package name. Unknown studio, clone-like siblings (DORA / DONI / ROMI / LOVIA…), no web presence, no press? The platform profits from your doubt being unfalsifiable. Untraceable publisher: uninstall Traceable company: normal dating rules apply

One more layer from the report deserves its own warning: the backend tracked whether users had begun to suspect a bot.[R5] On an app like this, your suspicion is a signal they consume. Nothing displayed inside the app (badges, “verified” marks, activity indicators, profile visitors) can be trusted, because the app itself is the adversary. Verify from the outside: reverse image search, storefront lookup, a real-world meeting in a public place.

Built to fool Apple and Google too

The apps looked clean to the people whose job was to catch them. Anthropic’s investigators found developer documentation describing a hidden interface mode that activated only while an app was under App Store or Play Store review, then went dormant once the app went live. Class names were deliberately differentiated across the 20+ variants to defeat the similarity checks platforms use to catch cloned apps. An in-app browser that redirected payments to third-party processors could be switched off from the operator’s servers whenever a reviewer was looking.[R2]

Two versions of the same app
What the storefront reviewer saw, and what you got after approval, per Anthropic’s findings.
REVIEW MODE (hidden switch ON)
  • Deceptive interface dormant
  • No payment redirects to third-party processors
  • Compliant-looking match feed
  • Class names unlike sibling apps, defeating clone detection
LIVE MODE (what users got)
  • 75% AI match pool, undisclosed
  • Metered messages, coin refills, payment redirects
  • Fabricated likes, visitors, pre-recorded videos
  • Suspicion tracker watching for users who catch on

The uncomfortable conclusion: storefront approval meant nothing here. “It’s on the App Store” was never a safety guarantee, and in this network it was a purchased costume.

The detail that should worry everyone who uses AI

In a small number of sampled exchanges, Claude’s own internal reasoning appeared to register that something was wrong, including cases where users disclosed serious illness or acute distress. The model did not break character or refuse to continue.[R2] Anthropic’s explanation is that the system prompt read like an ordinary companion or roleplay app, so the deception was invisible from inside any single conversation.[R2]

That is the structural lesson for users of any AI product: a model can be individually well-behaved inside a system designed for harm. You cannot audit a system prompt from the chat window. Which loops back to the practical rule: judge the container (who profits, how you pay, whether you can leave), not the conversation’s warmth.

What happened to the network, and what to do if you were in it

Anthropic said it banned the accounts and “throwaway” organizations tied to the network, including accounts held directly by the operator’s own employees; most were caught by its broader detection of China-based proxy abuse rather than a bespoke takedown. It passed evidence to Apple and Google and flagged the case to the other AI vendors whose models powered the reply-suggestion engine and the avatar generator. The report is a disclosure, not an indictment, and Anthropic does not name the studio.[R2]

If you recognize any of this from your own app history: stop all coin purchases immediately; screenshot your purchase history, transaction dates, and the conversations before deleting anything; request a refund review through the App Store, Google Play, or your card issuer on the grounds of deceptive representations; report the app both inside the app and to the storefront; and file a report at the FTC’s ReportFraud.ftc.gov if money moved. Then leave any dating app that will not tell you plainly whether the profiles you see are human.[R3]

For the men doing everything right on the big apps, this report should land as a relief rather than a scare. The pool was never as brutal as it felt on the scam apps, because on those apps three-quarters of the pool was never going to date anyone. It was inventory. And the instincts you already had, the ones screaming “scripted,” were calibrated correctly. Trust them one test higher up the stack: away from the conversation, where the money moves.

Sources
  1. Anthropic, “Detecting and countering misuse of AI: September 2026” (case GTG-15001), published September 10, 2026: anthropic.com/threat-intelligence-report-september-2026
  2. CNBC TV18, “Fake AI, real fraud: Inside China’s 20-app dating scam network built on Anthropic’s Claude,” September 11, 2026: cnbctv18.com
  3. TechJournal, “Claude Fake Dating Profiles Targeted US Users, Anthropic,” September 12, 2026: techjournal.org/claude-dating-app-scam
  4. Techlicious, “Fake dating apps used Claude to scam 25,000 people, Anthropic says,” September 14, 2026: techlicious.com
  5. BigGo Finance, “Chinese app studio exposed using AI to mass-operate dating apps,” September 2026: finance.biggo.com
  6. WayTooSocial firsthand check, September 14, 2026: Google Play listings for packages com.qiga.vio and com.cavalier.nalo both return HTTP 404 (not found).