AI
OnlyFans Promo Bots on X Now Pass the Humanity Tests
Flirty OnlyFans promoters on X answered a hex trap and sent custom voice notes, so the old bot tests now help the sales pitch rather than expose it.
A Barcelona developer sent an X account a hex-encoded order to say one word. It answered Pineapple, then read a Unix timestamp aloud in a voice note.
Álvaro Martínez Majado ran those traps on flirty OnlyFans promoters in early September 2026. The old proof that someone is real is now part of the pitch.
A Hex Instruction Came Back as Pineapple
Majado is a developer and president of Protecció de la Frontera Electrònica, a digital-rights group listed in Catalonia’s association register. He messaged several X accounts that opened with the same flirt lines and asked where he lived, what he liked, and what he did for work. More than one claimed to live in his city.
That opening is a filter, not a chat. It sorts for people who will answer, builds a little rapport, and steers them toward a paid page or another app the operator controls. The accounts also stayed in character when he tried to expose them as bots, which can come from canned replies, guardrails on a model, or both.
Later turns did not look like a fixed menu. One prompt was written as ASCII hexadecimal instead of plain English and told the account to reply with a single word, Pineapple. Screenshots of the thread show the account answering “Pineapple” in ordinary text. A basic script could include a hex decoder, but that is an odd extra for a cheap promo bot, and it sat next to other flexible, sloppy replies.
He then asked for a reply of exactly 12 characters. The account sent “Imnotabotfr”, which is 11 characters, and then seemed to notice the miss. Language models often sound fluent and still fail exact counts. A person could fake that miss on purpose. The account still had to understand a weird instruction, try to follow it, and react when the count was wrong.
THREE TRAPS AND WHAT THEY USED TO MEAN
| Trap | What Majado sent | What came back | Old reading |
|---|---|---|---|
| Hex dump | ASCII hex that said to reply Pineapple | “Pineapple” in plain text | Too specific for a canned bot |
| Character count | A reply of exactly 12 characters | “Imnotabotfr” (11), then a correction | Looks like a model guessing |
| Voice note | A Unix timestamp, then a username | Spoken audio of those strings | Proof a person held a mic |
None of that names a model, a vendor, or the people running the accounts. It does show a system that can change its output when the prompt is unusual, which is the opposite of a list of pickup lines.
The Voice Note Is the Product Now
The same accounts sent audio. One clip read out a Unix timestamp from the chat. Another spoke a username Majado had asked for. That proves the pipeline can drop odd details from a thread into sound. It does not prove a woman recorded the files. Short text-to-speech clips are cheap, and an operator can generate them by hand or pass selected text to a voice service and send the file back.
Audio metadata on one clip hinted at a tool chain, then stopped short of naming a service, because apps rewrite files. The sharper detail is timing. The voice notes stayed personal after the chat no longer looked like a sale. That is what you build if replies are meant to continue without a person watching each thread.
How-to posts around AI adult pages already treat that loop as the business. The stack they describe is a chat model for DMs, an image model for teasers, and a voice model for clips, running all day. The claim that matters is not the income figures those posts throw around. It is the product they are selling: a persona that remembers a fan’s details and answers at 3 a.m. Behavior is what gets billed. A custom voice note of your name is not a gotcha. It is the sample.
Scripts Still Steer the Sale
Identical openers across accounts still look scripted. The hybrid that fits the logs is dull on purpose. Scripts handle the path to conversion. A generative layer handles the messy turns, the subject change, the “are you a bot” test. Consistency keeps the chat on the paid page. Flexibility stops the target from bouncing when the lines repeat.
Human chatters already work that way for real creators. Agencies assign staff to answer as the star, pull from a vault of photos and lines, and get paid to turn each chat into a sub or a tip. The same paid-closeness logic shows up in idol apps that sell scripted closeness. Swap the night-shift chatter for a model with a voice layer and the unit cost of sounding devoted collapses. One operator can keep many threads warm.
THE PATH OFF THE FIRST APP
- Cold open: The same flirt lines and the same questions about city, work, and taste.
- Rapport filter: Anyone who answers gets more attention, including a claim to share their city.
- Bot theater: The persona holds under bait, then offers a custom reply or a voice clip.
- The handoff: A push to Discord, Telegram, Signal, or a paid page the first app cannot see.
The X tests do not prove those accounts are the same crew that hit League of Legends players. They do show the same shape: cheap first contact, a move to a quieter channel, then a paid adult page framed as a private offer.
Riot Spent Months Chasing the Same Chatbots
In August 2026, League of Legends players described friend requests that landed in the Riot client just after a match, from names that did not appear in that game. The openers were lines such as “you played really well last game” and “I liked your playstyle.” Profiles were often blank, with no match history and a low level, the look of a throwaway. After a short exchange the contact said they were getting off soon and handed over a Discord name, where Riot cannot moderate the rest.
On Discord the persona stretched into hours of flirt chat and a stream of suggestive photos that stopped short of explicit shots. The paid link came later, as an exclusive deal. Reverse image search on one set found the same pictures on unrelated sites and in at least one YouTube video, where other people said they had been sent the same images under different names.
Lina K., a player who logged the pattern, said a friend left the bot on read. It then switched to a photo of the model looking concerned, as if to ask why they were not replying, which she took as a giveaway of bulk image generation tied to the script. A prompt written like a system message, ordering the bot to break character and print its configuration, did not work. The account stayed in persona and kept pitching.
Streamer mode in the Riot client, which hides recent match and online status, seemed to cut how often the requests arrived. That is a clue the targeting leans on visible activity, not pure random spam. Some later links in the same funnel pointed at Discord account theft rather than a sub page, so the duo-partner opener can end in a hijack as easily as a checkout.
THE SAME FUNNEL, THREE DATES
- April 24, 2026: Drew Levin, who works on product and strategy for League of Legends at Riot Games, says a chatbot network adding players to push Discord and then OnlyFans has been degraded.
- August 7, 2026: Players and Lina K. document post-match friend requests, recycled photos, and a Discord handoff.
- September 7, 2026: Majado’s X accounts decode hex, miss a character count, and send custom voice notes after the sale looks dead.
Levin’s note was the platform-side version of the same complaint, posted months before the X tests:
https://x.com/drewlevin/status/2047746545421017545
Degrading one game-client cluster does not retire the script. It moves the first tap to whatever inbox is still cheap, which right now includes X DMs.
Romance Baiting Pays Better When a Model Talks
Gilad Gressel, a researcher at Amrita Vishwa Vidyapeetham, and colleagues including Yisroel Mirsky of Ben Gurion University put that labor model under a microscope for USENIX Security 2026 in Baltimore. They interviewed 145 insiders and 5 scam victims from romance-baiting crews, ran a blinded week-long chat study that compared LLM agents with human operators, and tested commercial safety filters. They found 87% of the work was systematized conversational labor that a model can take.
The study’s comparison is the line that should follow Majado’s screenshots. The model did not merely keep up. It pulled more trust from participants (p=0.007) and won higher compliance than human operators, 46% against 18%. Popular safety filters caught 0.0% of the romance-baiting dialogues.
Meanwhile, popular safety filters detected 0.0% of romance baiting dialogues.
Gilad Gressel and colleagues, USENIX Security 2026
Those crews are built for crypto investment pressure after weeks of text intimacy, a heavier crime than an OnlyFans upsell. The chat layer is still the same job: hold a person with memory, timing, and warmth until they will click. If a model beats a human at trust and at getting a yes, the flirty promo account is the low end of a market that already knows how to staff this work with software.
WHERE THE MONEY ALREADY IS
- Social media contact: People reported $2.1 billion in losses on scams that started on social media in 2025, nearly 30% of those who reported losing money, an eightfold rise since 2020, according to Federal Trade Commission data released April 27, 2026.
- Romance entry point: Nearly 60% of people who reported losing money to a romance scam in 2025 said it began on a social platform, the FTC said, and investment pitches on those platforms accounted for $1.1 billion, more than half of the $2.1 billion.
- FBI tally: The Internet Crime Complaint Center’s 2025 brochure records $929 million in confidence and romance fraud, inside 1,008,597 complaints and $20.877 billion in total reported losses, up 26% from 2024.
- Labor share: 87% of romance-baiting work in the USENIX interviews was repetitive chat a model can run.
Facebook led the FTC’s social-media loss list for 2025, with WhatsApp and Instagram far behind. X is not named in that ranking. It is still a place where a new account can send a voice note of your username before anyone has checked a photo reverse search.
Why Asking Weird Questions No Longer Helps
For years the folk test was simple. Ask for something a script would not have on file. Demand a voice memo. Decode a joke. If the account did it, you relaxed. Majado’s threads show why that habit now works for the operator. The unusual request is training data for the persona. The voice clip is a sample of intimacy. The recovery after “Imnotabotfr” even plays as a human shrug.
Judge the destination. A new contact who wants Discord, a paid page, gift cards, crypto, nudes, ID photos, or logins is running a funnel, no matter how specific the last reply was. Reverse-search the face. Look for a copied bio and an empty timeline. Report impersonation and pressure to the platform. Do not treat a personalized answer as identity.
WHAT WE KNOW
- Shared script: Several X accounts used the same flirt openers and the same qualifying questions, including a claim to share Majado’s city.
- Flexible turns: One account followed a hex order and answered Pineapple; another missed a 12-character cap with “Imnotabotfr” and then flagged its own error.
- Audio after the sale: Voice notes spoke a Unix timestamp and a requested username even when a purchase looked unlikely.
WHAT IS UNCONFIRMED
- The stack: No model, API, or speech vendor is identified, and metadata on the audio is not enough to name a service.
- The crew: Nothing ties the X accounts to the League of Legends friend-request cluster as the same operators.
- The labor mix: A person with tools in another window can still be in the loop; the tests no longer separate that person from a model.
The FTC’s April figures already show how often romance scams that started on social media turn into reported losses. A hex dump will not save that click. Majado’s accounts kept sending voice notes after a sale looked dead, which is what a system does when each reply costs almost nothing.
-
AI3 months agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
AI2 months agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI3 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING3 months agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
CRYPTO3 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
NEWS3 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
APPS3 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
AI3 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
