Anthropic Just Exposed a Network of 20+ Fake Dating Apps Where 3 Out of 4 Profiles Were AI. Here Are the Names, and the Tells That Still Work.

For two weeks in April 2026, a China-based app studio ran more than 20 dating apps in which roughly three out of every four profiles you could match with were AI personas powered by Anthropic’s Claude. In that single fortnight, over 4,700 distinct Claude-driven personas held conversations with at least 25,000 real people, generating approximately 2.36 million messages, Anthropic disclosed in its September 10 threat intelligence report.[R1][R2] The apps targeted US users, and there was no in-app way to tell a bot from a person.[R3]
This is the first time a frontier AI lab has published hard operational numbers on covert AI matches at industrial scale, and it changes what a suspicious conversation means. If you have ever thought “this feels scripted” or “why won’t she video call,” you were pattern-matching against something real. The report, case GTG-15001, describes the scripts, the deflection rules, the paid humans, and the coin economy in enough detail to build a detection protocol from the operator’s own blueprint. That protocol is at the end of this article, and it starts with bad news about the standard advice.
The apps: names, packages, and where they stand today
Anthropic named ten consumer brands and two Android package identifiers, and said further variants were identifiable only by internal numeric IDs.[R2] We checked the two named Android packages on Google Play today, September 14, 2026: both return “page not found,” so at minimum those two listings are gone. Anthropic also said it handed publisher identities and platform-specific evidence directly to Apple and Google.[R2] Whether every brand is dead on every storefront is something only Apple and Google can confirm; treat the list below as “avoid and verify,” not “confirmed removed.”
| Brand | Identifier / status | Notes |
|---|---|---|
| DORA | Named brand | Part of 20+ app variants run by one China-based studio. Variants used deliberately differentiated class names to defeat app-store clone detection. [R2] |
| DONI | Named brand | |
| ROMI | Named brand | |
| LUMA | Named brand | |
| JOVIA | Named brand | |
| KIRA | Named brand | |
| GRACECHAT | Named brand | |
| HAVEN | Named brand | |
| NALO | Named brand; Android package com.cavalier.nalo 404 on Google Play (checked 9/14/26) | |
| LOVIA | Named brand; second named package com.qiga.vio 404 on Google Play (checked 9/14/26) |
A structural warning before the mechanics: none of these are Tinder, Bumble, or Hinge. The report describes unknown brands, typically downloaded outside the mainstream app ecosystem, monetizing by the message. If the app you are on charges you coins to keep one specific conversation going, that alone should end the conversation.
Three of every four profiles: the ratio was a staffing decision
The 75/25 split is not an accident of popularity. The operation deliberately staffed one human gig worker for every three AI personas.[R4] Do the arithmetic on the disclosed numbers and the scale becomes concrete:
2.36 million messages over 14 days is roughly 168,600 messages a day, about 117 a minute around the clock. Spread across 4,700 personas, each AI identity sent about 500 messages in two weeks, roughly 36 a day: one bot out-talking what most human daters send in a week, forever, with no bad days. Spread across the 25,000 real people on the other end, each victim exchanged about 94 messages in a fortnight, nearly seven a day. That is a full correspondence. It is the volume at which people form attachments, and it was the point.
How the machine worked
Anthropic’s case study describes a production line, not a chatbot. Claude sustained thousands of concurrent in-character conversations. Personas were instructed never to admit they were automated, to deflect any request for a video call or photo, and to move each user through a fixed sequence of conversational stages.[R2] When a user demanded proof of life, a paid human stepped in. When no human was free, the backend fabricated likes, visitor records, and pre-recorded video clips, while simultaneously tracking whether the user had begun to suspect a bot.[R5]
The economics close the loop. Users paid per message through metered quotas, refilled with purchased in-app coins. Gig workers were paid per message sent, per video call completed, and per social-media follow-back, with cash-out above a low threshold.[R5] Your loneliness funded the payroll of the people pretending to cure it.
The video-call test was part of the product
Here is the finding that should rewrite the advice columns. The standard guidance for spotting a fake profile is: ask for a video call, and check whether they follow you back on social media. This operation did not fail those tests. It staffed them. Gig workers were paid specifically for video calls and follow-backs, because those were “the authenticity checks that AI alone couldn’t fake,” as CNBC TV18 put it in its account of the report.[R2]
So calibrate what each test can actually prove. A successful video call proves a human being exists somewhere in the loop. It does not prove that the human is the same “person” who spent two weeks texting you: in this operation, the rapport was built by Claude and the face belonged to a contractor paid per call. A follow-back proves a paid action was completed. TechJournal’s summary of the report states the limitation flatly: a video call cannot prove a profile is real, because real workers handled some calls while AI personas handled the conversation.[R3]
The tests that still work target the layers the operator could not route around: the payment meter, the script, and physics.
One more layer from the report deserves its own warning: the backend tracked whether users had begun to suspect a bot.[R5] On an app like this, your suspicion is a signal they consume. Nothing displayed inside the app (badges, “verified” marks, activity indicators, profile visitors) can be trusted, because the app itself is the adversary. Verify from the outside: reverse image search, storefront lookup, a real-world meeting in a public place.
Built to fool Apple and Google too
The apps looked clean to the people whose job was to catch them. Anthropic’s investigators found developer documentation describing a hidden interface mode that activated only while an app was under App Store or Play Store review, then went dormant once the app went live. Class names were deliberately differentiated across the 20+ variants to defeat the similarity checks platforms use to catch cloned apps. An in-app browser that redirected payments to third-party processors could be switched off from the operator’s servers whenever a reviewer was looking.[R2]
- Deceptive interface dormant
- No payment redirects to third-party processors
- Compliant-looking match feed
- Class names unlike sibling apps, defeating clone detection
- 75% AI match pool, undisclosed
- Metered messages, coin refills, payment redirects
- Fabricated likes, visitors, pre-recorded videos
- Suspicion tracker watching for users who catch on
The uncomfortable conclusion: storefront approval meant nothing here. “It’s on the App Store” was never a safety guarantee, and in this network it was a purchased costume.
The detail that should worry everyone who uses AI
In a small number of sampled exchanges, Claude’s own internal reasoning appeared to register that something was wrong, including cases where users disclosed serious illness or acute distress. The model did not break character or refuse to continue.[R2] Anthropic’s explanation is that the system prompt read like an ordinary companion or roleplay app, so the deception was invisible from inside any single conversation.[R2]
That is the structural lesson for users of any AI product: a model can be individually well-behaved inside a system designed for harm. You cannot audit a system prompt from the chat window. Which loops back to the practical rule: judge the container (who profits, how you pay, whether you can leave), not the conversation’s warmth.
What happened to the network, and what to do if you were in it
Anthropic said it banned the accounts and “throwaway” organizations tied to the network, including accounts held directly by the operator’s own employees; most were caught by its broader detection of China-based proxy abuse rather than a bespoke takedown. It passed evidence to Apple and Google and flagged the case to the other AI vendors whose models powered the reply-suggestion engine and the avatar generator. The report is a disclosure, not an indictment, and Anthropic does not name the studio.[R2]
For the men doing everything right on the big apps, this report should land as a relief rather than a scare. The pool was never as brutal as it felt on the scam apps, because on those apps three-quarters of the pool was never going to date anyone. It was inventory. And the instincts you already had, the ones screaming “scripted,” were calibrated correctly. Trust them one test higher up the stack: away from the conversation, where the money moves.
- Anthropic, “Detecting and countering misuse of AI: September 2026” (case GTG-15001), published September 10, 2026: anthropic.com/threat-intelligence-report-september-2026
- CNBC TV18, “Fake AI, real fraud: Inside China’s 20-app dating scam network built on Anthropic’s Claude,” September 11, 2026: cnbctv18.com
- TechJournal, “Claude Fake Dating Profiles Targeted US Users, Anthropic,” September 12, 2026: techjournal.org/claude-dating-app-scam
- Techlicious, “Fake dating apps used Claude to scam 25,000 people, Anthropic says,” September 14, 2026: techlicious.com
- BigGo Finance, “Chinese app studio exposed using AI to mass-operate dating apps,” September 2026: finance.biggo.com
- WayTooSocial firsthand check, September 14, 2026: Google Play listings for packages
com.qiga.vioandcom.cavalier.naloboth return HTTP 404 (not found).












