AI bots waste scammers time at scale
A Goddess of Deception Goes to Work
The pitch to a phone scammer is simple: a live human being just answered, mildly skeptical, a little confused, but persuadable. What the scammer cannot see is that the voice on the other end belongs to no one. It is a bot, one of roughly 350,000 bots run by an Australian company called Apate, named after the Greek goddess of deception. [1] The system was built over two years to do a job that human volunteers once did for free and could never do at scale: keep the criminal talking.
The logic is arithmetic. Every minute a scammer spends working a fake victim is a minute that scammer is not dialing the next real one. Dali Kaafar, the founder and CEO of Apate, describes the ambition plainly: the company wants to build the perfect victims (Wired). [1] A single bot holding a single line can absorb a scammer’s entire working session. Multiply that by a fleet and the criminal’s economics begin to wobble.
Apate’s bots are not passive recordings. They answer calls, infiltrate online scam chat groups, and reply to text messages. The company reports having collected more than 250,000 pieces of intelligence from fraudsters in real time — scam URLs, money mule accounts, bank details. [1] The persona is the delivery mechanism; the data is the product.
The Persona Is the Point
What makes a bot convincing is not its vocabulary. It is its inconsistency. Kaafar says the bots sometimes have WhatsApp and sometimes do not, that they sometimes pick up the phone and sometimes hang up on the scammer saying they will come back later (Wired). That erratic behavior mirrors how actual people behave, and it is precisely the quality that keeps scammers invested. A perfect respondent would be suspicious. A flaky one feels like a mark.
Wired’s Kernel Panic newsletter tested a demo version in which the user plays the scammer (Wired). The reviewers found the personas expressed a calibrated skepticism — enough doubt to feel real, enough openness to keep the pitch alive. They tried to sell the bot a cryptocurrency investment and failed after six minutes of effort. The bot never bit, never fully closed the door, and never let the conversation die.
Kaafar says Apate calls regularly go on for more than two hours. That figure matters less as a record than as a unit of theft prevention. A scammer locked into a two-hour call with a machine is not running the automated dialing tools that let one operator reach thousands of numbers in a day.
The Honeypot Learns to Talk Back
The same principle is being applied in a different corner of cybersecurity. For years, defenders have deployed honeypots — decoy systems built to attract attackers, absorb their effort, and expose their techniques. The classic honeypot was static and predictable, and skilled intruders learned to recognize it quickly.

Mark Vero, a doctoral researcher in the department of computer science at ETH Zurich, and his colleagues studied what happens when a honeypot is powered by a large language model (HoneyVal). In research published as HoneyVal, they found that an LLM-powered honeypot would keep AI agents attacking their system significantly longer than a honeypot with more predictable behavior (HoneyVal). The agentic attackers were much more convinced by the LLM-simulated honeypots and marked them as actual honeypots at a much lower rate (HoneyVal).
Vero’s conclusion is conditional but direct: if these systems are built well enough, he thinks it is quite advantageous for defenders (HoneyVal). The honeypot has stopped being a trap that waits. It has become a conversation partner that improvises — and the improvisation is what buys the time.
The Human Baiter Becomes Optional
For years, the work of stringing scammers along belonged to volunteers. Scambaiters posed as lonely retirees, confused customers, and easy marks, sometimes for hours, sometimes for weeks. Their motivation was part deterrence, part revenge, part sport. Their constraint was that they were people, with finite hours and finite patience.
That constraint is now the thing being engineered away. A volunteer can occupy one scammer at a time. A bot fleet occupies hundreds of thousands. The skill that scambaiters developed — reading a scammer’s script, feigning just enough gullibility, extending the call without triggering suspicion — has been codified into model behavior. The human baiter is not replaced because the machine is more clever. The human baiter is replaced because the machine does not get tired, does not get bored, and does not need to be recruited.
The same shift appears in the intelligence function. A human volunteer who wastes a scammer’s afternoon produces a story. A bot fleet that wastes thousands of scammer-hours produces a database — URLs, accounts, payment details, patterns — that banks and telecom companies can act on. The volunteer was a deterrent. The fleet is infrastructure.
The Ledger That Cannot Be Fooled
A separate line of research attacks the problem from the opposite direction: not by distracting the criminal, but by making the target impossible to rob. A paper from KTH Royal Institute of Technology in Stockholm, submitted in August 2026, argues that the classical notion of a program invariant is perhaps the most powerful solution to blockchain theft, an open problem for which no concept or technique has proven to really make a difference (INVARIANTEVAL).
The authors built a benchmark called INVARIANTEVAL: 28 real Ethereum exploits, each paired with a human-authored invariant that blocks the attack (INVARIANTEVAL). They then built PONDEREPLAY, a replay framework that re-executes historical transactions to prove whether an invariant is correct and sound (INVARIANTEVAL). The result: the invariants blocked all 28 attacks in the benchmark, a 28/28 result, validated by replaying 108,637 historical transactions (INVARIANTEVAL).
The finding is not that a tool exists. It is that a human judgment — the judgment of what a contract is never supposed to do — can be written down once and enforced forever. The auditor who would have needed to inspect every transaction is no longer in the loop. The invariant does the watching. The paper’s own experiments temper the claim: the state-of-the-art generation tools FLAMES, InvCon, and InvCon+ together recovered only 2 of the 28 attack-stopping invariants, so the judgment still has to come from a person.
Where the Human Still Decides

None of this eliminates the scammer. Cybercriminals initiate billions of messages and calls each year, and the most sophisticated operations run industrial-scale scam compounds. AI-driven defense has not stopped the expansion of digital fraud; it has changed the cost structure on both sides. The scammer now spends time on machines. The defender now spends compute on machines. The human is increasingly the party being represented rather than the party doing the representing.
That is the uncomfortable shape of the shift. When a bot pretends to be a victim, the victim’s role has been automated. When a honeypot pretends to be a vulnerable server, the sysadmin’s instinct has been automated. When an invariant enforces what a contract must never do, the auditor’s judgment has been automated. Each of these is a genuine gain in protection. Each also removes a person from a position where a person used to stand.
The open question is not whether the machines are better at these tasks. The evidence so far says they are faster, cheaper, and more scalable. The question is what happens when the scammer on the other end of the line realizes the voice is synthetic — and whether the next generation of fraud is built specifically to defeat the machine that was built to waste its time. The defense that works today is a defense the offense is already studying.
