A dark server room with illuminated server racks
AI

Apate says its 200,000 AI “victims” are harvesting scam crypto wallets at scale

The Australian firm claims it extracts wallet addresses “by the hundreds and by the thousands” for an unnamed blockchain-analysis client.

By Marcus Hale6 min read

Australian anti-scam firm Apate says it runs nearly 200,000 AI “victim” personas across calls and messaging apps to bait fraudsters and collect intelligence. The crypto-specific pitch is earlier identification of scam wallet addresses before victims broadcast transactions.

Key Takeaways

  • Apate says it operates almost 200,000 AI “victim” personas that can hold phone conversations and chat across social media and messaging platforms.
  • WhatsApp and Telegram are used as honeypot channels to engage scammers long enough to collect indicators, scripts, and tactics.
  • The firm says it extracts scammer crypto wallet addresses “by the hundreds and by the thousands” for an unnamed blockchain-analysis client to identify wallets and methods before funds move.
  • A six-week engagement up to the end of 2025 is cited at 600,000 scam calls handled for Australian telco TPG, with “more than five hundred days” of scammer time wasted and an estimated “somewhere around thirteen million dollars being saved.”

Apate’s 200,000 AI “Victims” and the Pitch: Intelligence Before Funds Move

Apate is positioning scam-baiting as infrastructure, not a campaign. The company says it maintains a stable of almost 200,000 AI characters designed to play the role of gullible victims across phone calls, social media, and messaging apps.

Founder Dali Kaafar describes throughput in operational terms. “I can tell you that we’re basically servicing, as we call them, hundreds of thousands of calls a day, and pretty much hundreds of thousands of conversations on the other channels,” he said.

The trader-relevant hook is not the theater of wasting time. It is the claim that these conversations can be mined for identifiers that can be acted on before money moves, especially when the scam’s conversion step is a crypto transfer to a fresh address.

The Numbers Apate Points To: 600,000 Calls for TPG and a KPI for Scammer Rage

Apate’s cleanest proof point in the packet is a telco engagement with TPG in Australia. Kaafar said that in the six weeks up to the end of 2025, Apate’s bots engaged in 600,000 scam calls for that single telco.

He framed the output in two metrics. “Essentially, we wasted more than five hundred days of scammers’ time,” Kaafar said. He added, “That roughly equates to somewhere around thirteen million dollars being saved.” Those savings and time-wasted figures are presented as his rough equivalence, not as independently audited results.

Apate also tracks an internal KPI that is more revealing than it looks. “I think we’re the only company in the world that is actually keeping as part of their KPIs the number of F-words that scammers are dropping at them,” Kaafar said. It is a crude proxy for one thing that matters operationally: whether the bot is keeping the scammer engaged long enough to surface payment instructions, escalation paths, and the next account.

The company says it started with 120 personas and scaled to 197,000, with accents, vocal tics, and human filler sounds. “We spent a lot of time refining and building these AI bots that sound exactly like you and I and our neighbors,” Kaafar said. Training data came from “hundreds and hundreds” of hours of recorded conversations between human scam baiters and scammers.

Crypto Angle: Wallet Address Harvesting for an Unnamed Blockchain-Analysis Client

Apate’s crypto claim is explicit and still incomplete. Kaafar said the firm works for “one of the leaders in blockchain analysis,” but did not name the client. That missing identity matters because it is the difference between a niche data feed and something that could propagate into exchange risk controls and mainstream labeling.

The mechanism is straightforward. The bots are deployed on WhatsApp and Telegram as honeypots, pulling scammers into extended conversations where the scammer eventually provides a destination for funds. In crypto cases, that destination is often a wallet address, sometimes paired with chain preferences, stablecoin instructions, and timing pressure.

Kaafar described the extraction volume in plain terms. “These bots, as they engage across different conversations, extract new crypto wallet addresses by the hundreds and by the thousands,” he said. The value proposition is lead time. “It’s data and intelligence that is coming literally before their damage happens.”

That is the part that would matter to exchanges, compliance teams, and on-chain analysts. If a wallet can be labeled and clustered before it receives meaningful victim inflows, the first big deposits become easier to intercept, freeze, or route into enhanced review. It also changes the economics for scammers, who rely on fresh addresses and fast rotation to stay ahead of blacklists.

Apate also claims its bots uncovered a marketplace for brokers soliciting verified bank accounts in India, offering commissions of up to 5% paid in USDT on scam proceeds routed through those accounts. The month is given as “July,” but the year is not specified in the packet. The second-order point is clear even without the year: stablecoins can function as internal payroll rails for scam ecosystems, paying intermediaries who source bank access and off-ramp capacity.

Signals to Monitor as Scammers Adopt AI: Where the Arms Race Shows Up On-Chain

Apate says scammers are adopting AI quickly. The firm’s research suggests about 20% to 30% of scam text conversations already employ AI, and Kaafar argues scamming is a $1.24 trillion business, implying the budget exists to scale compute-heavy operations. The packet does not provide a study or methodology for that $1.24 trillion figure, so it should be treated as an assertion.

If scammers are iterating faster, defenders need collection points with throughput. Telegram and WhatsApp honeypots are logical places to harvest new deposit addresses and payment instructions, because that is where the conversion step is negotiated.

There are four practical signals that would validate whether this is becoming a meaningful on-chain input.

First, whether any major blockchain-analysis firm publicly confirms, or is credibly linked to, using honeypot-derived wallet intelligence from Apate-style operations.

Second, whether new scam-wallet clusters and fresh deposit addresses start getting flagged before large victim inflows hit. That is the test of the “before damage happens” claim.

Third, follow-on disclosures that clarify the year of the “July” India marketplace discovery and whether the up-to-5% USDT commission rail can be tied to identifiable on-chain cash-out patterns.

Fourth, updated measurement from Apate on the share of AI-assisted scam texts. If that 20%–30% estimate rises, expect faster wallet rotation and more frequent changes in payment rails.

My Take: Treat This as a New Data Source Claim—Useful if It Produces Actionable Wallet Clusters

The threshold that matters is not 200,000 personas. It is whether the wallet addresses extracted “by the hundreds and by the thousands” arrive with enough context to cluster early and propagate into real controls, like exchange deposit screening and analyst labeling, before the first big victim transactions land.

If a major blockchain-analysis shop is actually ingesting this feed, the edge is time. If the client stays unnamed and the output stays anecdotal, this reads more like a scale story than a market-structure shift. The development matters in practical terms only if it consistently turns off-chain scam conversations into on-chain wallet clusters early enough to change where funds can safely move.

Sources