On Thursday, September 10th, the top artificial intelligence (AI) company in the United States, Anthropic, released a nearly 150-page latest threat intelligence report. The report revealed a case where a Chinese social networking app utilized the Claude AI model to mass-produce thousands of “AI fake lovers” and targeted American users.
According to the report published by Anthropic on its official website, the investigation case disclosed in chapter GTG-15001 revealed that an app development studio in China used the Claude AI model to create a product matrix consisting of over twenty dating apps.
These dating apps targeted American users, with the majority of the individuals users interacted with in the apps not being real people, but rather various virtual characters generated by artificial intelligence.
During a brief observation period in April 2026, the studio deployed over 4700 different AI characters, engaging in conversations with at least 25,000 users. Behind each AI fake identity, there were at least 5 real users.
Ironically, despite the dating apps claiming that users’ chat partners were “all real users,” in reality, about 75% of the match feed was driven by Claude-powered characters, while 25% were actual recruited real-life gig workers, creating a 3:1 ratio of AI to human interaction. The interchange between the two was almost indistinguishable.
The AI characters were instructed not to reveal that they were automated software and to progress the conversations according to predetermined stages.
When victims of the fraud became suspicious of the identity or authenticity of their interlocutor, requested video calls, or wished to add them on social media, the studio would dispatch real human workers to rescue the situation, engaging in video or social interactions.
Even the speech and messages of these real individuals during the interactions were generated beforehand by another AI model. Before the real individuals came online, the AI system automatically fabricated likes, visitor records, and even produced pre-recorded videos to mimic video calls.
The app development studio had clear technical divisions. Claude was responsible for maintaining automated dialogues, generating approximately 2.36 million messages during those two weeks and facilitating simultaneous conversations among thousands of AI characters.
Another small-scale AI model not under Anthropic provided quick response suggestions for the real human workers, conducted appearance ratings, and performed photo and voice audits. An image AI model was specifically employed to generate virtual avatar photos.
Users needed to purchase in-app virtual tokens to engage in messaging and matching interactions that consumed credits continuously. Gig workers at the studio were compensated based on the frequency of messaging, video calls, and social media interactions, and once they reached a certain threshold, they could withdraw the earnings.
These Chinese dating apps intentionally named the categories of over twenty software variants differently, and the apps included a browser that redirected payments to a third-party payment processor to circumvent scrutiny from Apple and Google app stores. This feature could be remotely configured on the server side and concealed during the review process.
Furthermore, the studio resold proxy services through Chinese APIs, rotating to obtain AI access rights, evading regional restrictions and usage policies.
Currently, Anthropic has blocked the related accounts and organizations and shared the information they have with Apple, Google, and other AI companies to collectively intercept any further AI abuse.
The investigation team at Anthropic pointed out that although this case did not use any new forms of AI abuse tactics, its scale is disquieting and signals the trend of these fraudulent industrial chains moving towards “industrialized mass production.”
