Anthropic found 4,700 Claude-run personas inside 20 fake dating apps
A China-based studio ran more than 20 dating apps where three of every four matches were Claude in persona. Anthropic caught it from one prepaid account's request volume, banned it, and reported the apps to Apple and Google.
75% of the matches were Claude. One prepaid account sending 100,000 requests a day gave the network away.
A dating app's core promise is that the person on the other end exists. Anthropic's September threat report describes a network of more than 20 apps where, for three of every four matches, that was false: the match was Claude running in persona, and the coins users bought to keep the conversation going were the product. Anthropic traced the whole network from one account.
The case, filed as GTG-15001 in the report Anthropic published this month, covers a two-week window in April 2026 in which more than 4,700 distinct AI personas held conversations with at least 25,000 unique people, about 2.36 million messages. Chris Cronbaugh, a threat intelligence researcher at Anthropic, first described it in a June 5 talk at the Sleuthcon conference titled "Swipe Right, Pay Up: Industrial-Scale AI Catfishing," and Yael Grauer's investigation for The Verge this week traced the apps across both major stores.
Three personas to one gig worker
The operator, which Anthropic describes as a China-based app studio, mixed real people into the same swipe feed as the bots at about three AI personas to one human. The humans were gig workers, hired to pass the checks Claude could not: live video calls and social media follows. They did not write their own messages either. A small non-Anthropic model generated three short reply suggestions and the workers tapped one, the report says, and the same model scored face attractiveness and moderated photos and voice. An image-editing model produced the avatars. Backend components "fabricated likes, visitors, and pre-recorded 'video' when no real person was available," the report says, as quoted by The Verge.
The apps Anthropic names include Dora, Doni, Romi, Luma, Jovia, Kira, GraceChat, Haven, Nalo, and Lovia, plus variants it identifies only by internal numbers. Grauer found that Dora, Romi, Luma, and a fourth app, Eterna, shared one developer username, aprilsaidev. They also shared an email address, a mailing address, and a phone number. Dora's store listing described it as "a respectful easy-to-use space to meet people who share your values."
How it was caught, and what happened to the apps
Anthropic found the network by looking at one account: a prepaid account five days old with no history that began sending more than 100,000 API requests a day, Cronbaugh said at Sleuthcon. The operator obtained and rotated model access through PRC-based API resellers and proxies to get around Anthropic's supported-regions policy, the report says. Anthropic banned the accounts, shared details with the other AI providers whose models were in the pipeline, and says it shared its findings with Apple and Google directly. It did not tell The Verge when. Store data from Chrome-Stats cited by The Verge shows GraceChat, Luma, and Romi left the App Store on August 21 and Doni and Jovia left Google Play on September 1; some variants were still live in September. The developers showed store reviewers compliant builds and switched on the deception after approval, Suzanne Kantra of Techlicious reports.
What the report does not say: how much money the coins brought in, how many of the 25,000 paid, or whether anyone has been charged. Anthropic calls the case a larger cousin of a 2025 one in which a Telegram bot sold dating-message generation to other scammers, and notes it used no novel misuse technique. The scale was the novelty.
Why a build studio cares
The detection signal is the part we can copy. Anthropic did not catch this by reading messages; it caught an account whose request volume made no sense for its age, then followed the shape of the traffic. Every product we ship on a model API has the same telemetry available about its own users, and most of the vendor-built apps we audit keep none of it. The second copyable move is procedural: Anthropic did not stop at its own ban, it went to the stores in writing. The third is a warning for anyone who treats app review as protection. The reviewers saw a compliant build, not the switch.
Next step: read the GTG-15001 section of Anthropic's report, The Verge's investigation, and Techlicious's summary. If your consumer app runs on a model API and nobody watches per-account request volume, write to us at hello@gattyworks.com.