The profile is charming, attentive, and not a person
Romance scam losses reported to the Federal Trade Commission passed one point one six billion dollars in the first nine months of 2025 alone, and everyone who studies this agrees the real number is higher because most victims never report. Dating platforms answered with photo verification. Photo verification is now being defeated at the capture pipeline, and it was never the harder half of the problem anyway.
Picture a woman in her fifties, recently widowed, who joins a dating app on the advice of a friend who thought she should get out more. She is not naive. She has read the warnings. She screenshots one early match to her daughter with the message "this one seems too good", and they laugh about it, and she unmatches him.
The one she does not unmatch takes six weeks. He asks about her week and remembers the answers. He sends a photo of his dog. He has a plausible job that keeps him travelling, which explains the rescheduled video calls. At no point does he ask her for money. That is the part people who have not seen this up close get wrong. He never asks.
What he does, in week seven, is mention almost in passing that he has been putting a little into a trading platform and it has done rather well. He does not offer to help. She asks. He is reluctant. She insists. He walks her through the signup with the patience of someone who genuinely does not mind, the platform shows her a balance that goes up, she puts in more, and then she tries to withdraw and is told about a tax that must be paid first. That is the moment the floor opens.
When she reports it, the app closes the account. Within a week the same photographs are on a new profile with a different name. She notices, because she is still looking. The app does not, because from the inside a new signup with a new email on a new device is a new user, and there is nothing in the system that says otherwise.
Short answer. Romance scam losses reported to the FTC exceeded one point one six billion dollars in the first nine months of 2025, and reported totals are floors because shame suppresses reporting. Dating platforms cannot fix this by classifying profiles or by taking a selfie video, because both are being defeated. The one thing a platform can establish is that an account belongs to a distinct, present human, proven once and re-established over time, with no identity and no face stored.
How much money is lost to romance scams?
The most reliable public figures come from the Federal Trade Commission, which collects consumer fraud reports through its Consumer Sentinel network. Reporting on FTC data for the first nine months of 2025 recorded 55,604 romance scam complaints and more than one point one six billion dollars in reported losses, an increase of around twenty two percent on the comparable period. The FBI's Internet Crime Complaint Center separately tracks confidence and romance fraud, including the investment variant, and publishes annual totals.
Those two agencies count different things in different ways. The FTC counts what consumers report to the FTC, the IC3 counts what people report to the FBI, a single victim may report to one, both or neither, and the categories do not map cleanly onto each other, particularly for the investment style fraud that begins on a dating app and ends on a fake trading platform. Anyone who adds the two figures together to produce a bigger headline number is doing something meaningless.
The FTC has also reported that a majority of people who lost money to a romance scam in recent data said the contact began on social media rather than on a dating app. That finding matters for two reasons. It tells you the problem is not confined to dating platforms, and it tells you the platforms with the weakest account controls carry a disproportionate share of first contact.
Why the published numbers are floors, not estimates
Every serious analysis of romance fraud says the same thing about its own data, and it deserves to be stated plainly rather than buried in a methodology note.
Romance fraud is under reported to an unusual degree, and the reason is not laziness or ignorance. It is shame. The victim has to explain to a bank clerk, a police officer, and often an adult child that they sent their savings to someone they had never met because they believed they were loved. A great many people decide, entirely rationally, that they would rather absorb the loss privately than say that sentence out loud. Some never tell anyone at all.
This has a consequence that changes how you should read every figure in this article. The published totals are not central estimates with error bars in both directions. They are lower bounds. When you see one point one six billion dollars, the honest reading is "at least one point one six billion dollars, from the subset of people who were willing to say so".
What are the two different problems people call dating app bots?
Almost every article on this subject blurs together two problems that need completely different answers. Separating them is the most useful thing you can do before considering any control at all, because a control that fixes one does nothing for the other, and a platform that ships the first while claiming to have addressed the second is making a false safety promise.
Problem one: automated profiles at scale
The first problem is volume. An operation creates hundreds or thousands of profiles, populates them with generated or stolen photographs, and runs opening conversations automatically. Most of these die quickly. They are blocked, reported, or ignored. That is fine, because the economics do not require any individual profile to succeed. They require the cost per profile to be lower than the expected value of the small fraction that convert.
This is a pure numbers business, and its entire viability rests on one number: what it costs to stand up another account. If that cost is a fraction of a cent, an operator can afford a conversion rate close to zero. If it is meaningfully more, the arithmetic changes and a large part of the activity simply stops being worth doing.
Problem two: the long con, run by a real human being
The second problem is the one in the opening scene, and it is not automated at all. A person spent six weeks on that conversation. They remembered the dog's name. They rescheduled the call with a plausible excuse. No current model does that well enough, for long enough, under that much pressure, and the operations that run these scams know it, which is why they use people.
Here is the fact that changes how you should think about the person on the other end. A substantial body of reporting by international law enforcement bodies and human rights organisations has documented large scale scam operations in which the people conducting the conversations are themselves victims, trafficked into compounds under coercion and forced to work. Not all romance fraud works this way, and the picture varies enormously by region and by operation. But enough of it does that "the scammer" is frequently not a useful category, and a reader who pictures a lone criminal at a laptop has the wrong model of the industry.
Now the uncomfortable part, and this piece is going to state it in the third section rather than hiding it in the limits at the end.
A proof that an account belongs to a unique human does nothing whatsoever to stop problem two. The person running the long con is a unique human. They would pass. They would pass on the first day and they would pass every re-check thereafter, because they are exactly what the check is looking for.
Any vendor who tells a dating platform that human verification solves romance fraud is either confused or lying. What it addresses is problem one, and problem one is worth addressing, and we will get to exactly how much it is worth. But the claim has to be scoped honestly or it is worthless.
Does photo verification stop bots?
Most major dating platforms now offer some version of photo or video verification. You are asked to copy a pose shown on screen, the app captures a short video, and a system compares it against your profile photographs. It is a good idea and it was genuinely effective for a period. It is now under sustained attack, and the attack is not the one most people imagine.
Presentation attacks versus injection attacks
There are two ways to defeat a liveness check and the difference between them is the whole story.
A presentation attack is what everyone pictures: someone holds a printed photograph, a mask, or a phone screen up to the camera. The camera is real, the light is real, the check is observing an actual scene, and there are real physical artefacts to catch. Depth, texture, reflection, micro movement. The international standard ISO/IEC 30107 covers presentation attack detection precisely because this is a well understood problem, and the industry has become quite good at it.
An injection attack does not go near the camera. The attacker installs a virtual camera driver, runs the app in an emulator, or tampers with the client, and feeds synthetic frames directly into the pipeline at the point where the real camera's frames would have entered. Every liveness signal the system checks for is present, because the attacker generated it deliberately. The head turns because it was rendered turning. The blink is there because a blink was drawn.
The analogy that makes this click: a presentation attack is holding a photograph up to a security camera and hoping the guard does not look closely. An injection attack is splicing a cable into the back of the monitor. The guard is looking as carefully as ever at a screen that is no longer connected to a lens.
The identity verification firm Yoti has published figures describing injection attacks in the millions across its client base during 2025, with a sharp peak in the second half of that year. Treat vendor telemetry as directional rather than as a census, for the reason we always give: a vendor can only count the attacks it saw, on the clients it serves, using the detection it has, which makes every such figure a floor with a selection bias attached. What the figures establish beyond argument is that this is an industrial technique and not a research curiosity. We cover the mechanics in detail in the camera is no longer evidence.
Why this hits dating apps harder than banks
A bank running identity verification at account opening has a strong hand: it can require a specific mobile app it controls, refuse rooted or emulated devices, escalate to a human review, and simply decline the customer if anything looks wrong. The customer wants a bank account and will tolerate being told to try again.
A dating app has none of that leverage. Verification is optional on most platforms because making it mandatory costs signups, the check has to work on whatever device the user already has, and a person who is told to try again three times does not persist. They uninstall. So the platform is running a weaker version of a check that is already under pressure, on a population that will not tolerate friction, in service of a badge that other users then read as a guarantee.
Why do platforms struggle to remove fake accounts?
It is easy and satisfying to say that dating apps tolerate bots because engagement is engagement. It is also too simple, and a reader who works in trust and safety will stop reading if the piece takes that line, so let us be accurate instead.
Large dating platforms employ substantial trust and safety teams, publish transparency reporting, run automated screening at scale, and remove very large numbers of accounts. That work is real and it is not cheap. Anyone who thinks the problem persists because nobody is trying has not looked.
The genuine difficulty is structural, and it has three parts.
The first is that removal is not durable. A ban removes an account and does not remove a person. When the cost of returning is a new email address and a factory reset, enforcement becomes a treadmill, and the operator's cost of being caught is measured in minutes.
The second is that the measurable incentives point the wrong way even when the people do not. Active user counts and message volumes are the numbers a platform reports. An aggressive removal programme makes each of them worse immediately, while the benefit, users not quietly churning out of frustration, arrives later and is hard to attribute. That is an ordinary argument about which metric wins a planning meeting, and it requires nobody to be acting in bad faith.
The third is the false positive cost, which is severe and specific here. Wrongly removing a real person from a dating app is not like wrongly flagging a transaction. It is telling somebody already anxious about putting themselves out there that a machine looked at them and decided they were not real. Every trust and safety team knows this, it correctly makes them cautious, and caution at scale means letting through cases a bolder threshold would have caught.
Why can dating apps not simply require ID?
Because for a meaningful number of users, an identity requirement on a dating app is a physical safety risk, and for some of them it is a life threatening one.
This needs stating at full strength rather than in passing. Consider who uses these platforms pseudonymously and why. Gay, lesbian, bisexual and transgender people in jurisdictions where their existence is criminalised, where penalties are severe and where dating platforms have been used to identify targets. People who have left abusive partners and cannot risk being located. Anyone who does not wish their romantic life to be a database record held by a company that will one day be breached, sold, or subpoenaed.
A platform requiring government identity documents is not making a neutral tradeoff. It is making the service unusable for the people who face the highest consequences from exposure, and creating exactly the honeypot that endangers them if it is compromised. This has played out already with age assurance, where documents collected for a safety purpose became a breach category of their own, discussed in how to verify age without collecting an ID.
So the design constraint is not a preference. It is a hard requirement: any workable answer must establish that an account belongs to a distinct, present human without the platform learning who that human is.
What does one human, one profile actually look like?
Here is the mechanism, described concretely enough to argue with.
At signup, before the profile becomes visible to other users, the platform asks for a presence proof. The user's device performs a liveness challenge locally and derives a key from the result. What leaves the device is not a photograph, not a video, and not a biometric template. It is a one way key, which the platform stores against the account, plus a signed receipt asserting that a live human was present at a given time.
The property that matters is uniqueness within the platform's own namespace. If the same person enrols a second account, the derived key collides with the first, and the platform learns exactly one fact: these two accounts are the same person. It does not learn the person's name, face, document number, or anything else, because none of that was ever transmitted. This is the same primitive we describe in one human, many accounts, applied to a setting where the privacy constraint is unusually sharp.
What actually gets signed
The receipt is a small, boring object, and boring is the security property. Conceptually:
{
"type": "presence.enrollment",
"context": "app.example.dating", // scoped: no cross-app identifier
"human_key": "9f2c...c41e", // one-way, per-context, not reversible
"liveness": "passed",
"device_bound": true,
"issued_at": "2026-09-30T09:14:22Z",
"expires": "2027-09-30T09:14:22Z"
}
// signed with Ed25519; verifies offline against a published key.
// Note what is absent: no image, no template, no name, no document.
The scoping is not a detail. A key derived per context means the value stored by one dating app cannot be correlated with the value stored by another, or by anything else. A single global identifier would be a tracking number, which is precisely the thing this series argues against, and building one would be a worse outcome than the problem it claims to fix.
Continuity, which is the half that actually matters
Enrolment alone is weak, because an account that was human on day one can be sold, rented or handed over on day sixty. Rented and resold accounts are a documented pattern in other settings, as we describe in who is actually driving, and there is no reason to assume dating is exempt.
So the useful version is continuity: a light re-attestation at intervals, or on specific events, that confirms the same enrolled human is still behind the account. Not continuous, not a camera left running, and emphatically not behaviour analysis. A brief check, at a small number of moments, producing a receipt.
// pseudo-code at a consequential moment
if (conversation.isFirstOutboundMessage() || account.ageDays() % 90 === 0) {
const proof = await manav.attest({ context: APP_CONTEXT, mode: "glance" });
if (!proof.matches(account.humanKey)) {
account.restrictMessaging(); // not a ban: a hold and a prompt
}
}
Note the failure mode. A mismatch restricts and prompts. It does not ban. That choice matters because a real person who changed phones must not be treated as an adversary, and because a control whose false positive path is a permanent removal will be tuned so loosely that it stops catching anything.
Which dating frauds does this actually stop?
This is the table the piece exists for, and several rows say no on purpose.
| Fraud pattern | How it works | Does a uniqueness proof help? |
|---|---|---|
| Mass automated profiles | Thousands of accounts, generated photos, scripted openers | Yes. Breaks the per account cost model the operation depends on |
| Ban evasion | Removed account recreated within minutes | Yes. The key collides, so the removal has durable effect |
| Account rental or resale | Aged account with history handed to an operator | Yes, with continuity. Re-attestation fails after handover |
| Stolen photographs on a new profile | Real person's images used by someone else | Partly. Does not detect stolen images, does limit how many profiles one operator runs |
| Long form romance scam by a real person | Weeks of conversation, no automation involved | No. The operator is a unique human and passes every check |
| Coerced worker in a scam compound | A trafficked person conducting the conversation | No. Also a real, present human |
| Off platform migration to a fake investment site | Conversation moves to a messaging app, then to a fake exchange | No. Happens outside the platform's control entirely |
| Catfishing by an individual | One real person misrepresenting themselves | No. Proves presence, not honesty |
Four no entries out of eight. That is the honest shape of this control, and a platform that deploys it should describe it to users in exactly those terms.
What does this change for the platform economics?
Work the arithmetic in the abstract, because the real numbers are proprietary and we are not going to invent them. Suppose an operator runs profiles at a cost approaching zero and needs one conversion in several thousand attempts to profit. At that cost structure they will run as many accounts as screening tolerates, and removals are just a resupply cost.
Now suppose each account requires a distinct enrolled human. Cost per account is no longer a fraction of a cent, it is whatever it costs to obtain another real person's cooperation, which is orders of magnitude higher and does not scale with compute. The mass profile business does not become impossible. It becomes a different business with a different margin, and a great deal of activity that was worth doing at nearly zero cost stops being worth doing at all.
That is the whole claim for problem one. It is a real claim and a bounded one, and it is the same argument we make about free tier abuse and about review farms: you do not need to make abuse impossible, you need to make it cost something per unit, because the entire business model assumes it costs nothing.
Honest limits
Beyond the four no rows in the table, four further limits deserve naming.
A verified human badge can make things worse. This is the risk we take most seriously. If a badge means "we established a live human enrolled this account", and a user reads it as "this person is safe", the badge has increased their exposure rather than reducing it. The person running the long con will have the badge. Any platform shipping this must write the label with real care, and should probably say what it does not mean directly on the profile rather than in a help centre article nobody opens.
Enrolment is the trust bottleneck. Everything downstream depends on the first check being sound. An operator who defeats enrolment once has a durable account, which is why device attestation and liveness quality matter, and why this composes with identity verification vendors rather than replacing them.
It does not touch off platform harm. The moment the conversation moves to a messaging app, the platform's controls end. Most of the money moves after that point.
Coverage is a product decision with a cost. Mandatory enrolment improves the guarantee and reduces signups. Optional enrolment preserves growth and produces a two tier population where the fraud concentrates in the unverified tier. No configuration avoids this tradeoff, and a platform should choose deliberately rather than by default.
What to do this week
If you build or operate a dating or social platform:
- Instrument ban evasion. Measure how many removed accounts return within thirty days under a new identifier. If you cannot answer that, you do not know what your enforcement is worth.
- Separate your fraud reporting into the two problems in this article. Automated profile volume and long form confidence fraud should never appear in the same metric again.
- Audit your verification pipeline for injection resistance specifically, not presentation resistance. Ask your vendor directly whether they test against virtual cameras and emulated devices, and get the answer in writing.
- Write the exact wording of any human verification badge before you build it, and test that wording with users to find out what they think it promises.
- Gate the first outbound message rather than the signup, if you must choose one moment. It is where the fraud starts and it costs you nothing in registration conversion.
- Publish your removal numbers and your recidivism numbers together. The first without the second is marketing.
If you are using these apps, or worried about somebody who is:
- Treat a request to move to another messaging app as the actual risk signal. It is the single most consistent step in the pattern, and it precedes every request for money.
- Treat any investment suggestion from a romantic contact, however incidental it sounds, as the scam itself rather than a warning sign of one.
- Do a reverse image search on photographs early. It is thirty seconds and it catches the lazy end of the market.
- If someone you know has lost money, the useful first sentence is not "how did you not see it". Reporting rates are low because of exactly that sentence, and the money is more likely to be traceable in the first days.
- Report it anyway, to the FTC and to IC3, even when recovery seems hopeless. The published figures are how this gets prioritised, and every unreported case makes the problem look smaller than it is.
If you want to see what a presence check looks like from the user's side, with nothing stored and no signup, there is a walk up demo at /labs/manav/, and the integration shape is in the docs.
Frequently asked questions
How much money is lost to romance scams? Reporting on Federal Trade Commission data recorded more than one point one six billion dollars in reported romance scam losses across 55,604 complaints in the first nine months of 2025, up around twenty two percent year on year. The FBI's Internet Crime Complaint Center publishes separate annual figures on confidence and romance fraud. Both are lower bounds, because shame suppresses reporting heavily in this category.
Can dating apps verify that a match is a real person? They can establish that a live, distinct human enrolled the account and that the same human is still behind it, without collecting identity. They cannot establish that the person is honest, single, or who their photographs show. Those are different questions and no identity technology answers them.
Does photo verification stop bots? Decreasingly. Photo and video verification defends well against presentation attacks, where something is held up to a real camera. It defends poorly against injection attacks, where synthetic frames are fed directly into the capture pipeline through a virtual camera or an emulator, because every liveness signal the check looks for is present by construction.
Would proving users are human stop romance scams? No, and any vendor claiming otherwise should be treated with suspicion. It substantially raises the cost of mass automated profile operations and makes bans durable. It does nothing against a real human running a long confidence scam, which is how most of the large losses actually happen.
Why do dating apps not just require government ID? Because pseudonymity on these platforms is a physical safety requirement for many users, including people in jurisdictions where their sexuality is criminalised and people who have left abusive relationships. An identity requirement excludes exactly those users and creates a database whose breach would endanger them.
Does this mean the platform stores my face? Not in the design described here. The liveness check runs on the device and what leaves it is a one way key plus a signed receipt. There is no image, no biometric template and no name, and the key is scoped per platform so it cannot be correlated across services.
What is pig butchering? It is the industry term for a long form scam in which a relationship is built over weeks or months before the victim is introduced to a fraudulent investment platform, typically for cryptocurrency. The relationship is the setup and the fake trading platform is the extraction. It frequently begins on dating apps or social media.
Sources
- Federal Trade Commission, consumer protection data and fraud reporting: ftc.gov/news-events/data-visualizations. Romance scam complaint counts and reported loss totals for 2025 are drawn from reporting on FTC Consumer Sentinel data.
- Federal Bureau of Investigation, Internet Crime Complaint Center, annual Internet Crime Reports covering confidence and romance fraud: ic3.gov.
- Federal Trade Commission consumer fraud reporting portal: reportfraud.ftc.gov.
- Yoti, published research on injection attacks against identity verification during 2025: yoti.com. Vendor telemetry, directional rather than a census.
- ISO/IEC 30107, information technology biometric presentation attack detection: iso.org. The standard covers presentation attacks specifically, which is why the injection distinction matters.
- United Kingdom Online Safety Act duties and Ofcom implementation material, relevant to platform obligations on fraud origination: ofcom.org.uk.
A proof of humanity would not have saved her, because the man who spent six weeks remembering her dog's name was a human being. What it would have done is stop his photographs reappearing the following Tuesday under a different name.