Researchers observed flirty spam accounts on X (Twitter) using scripted conversations, and possibly AI-generated replies and voice notes, to build trust and move targets toward Discord and paid adult-content pages. The accounts asked repetitive “getting to know you” questions, handled unusual prompts (like decoding a hex message), and sometimes sent personalized voice notes, making them harder for users to spot as fake.
How the attack worked
Researchers observed flirty promotional accounts on X (Twitter) running a repeatable conversation funnel. Accounts opened with casual, flirtatious messages, asked broadly similar qualifying questions such as where the target lived, what they liked, and what they did for work, and then steered the conversation toward Discord before promoting paid adult-content pages. This structure suggests a scripted funnel rather than genuine one-on-one interest.
Why it succeeded
What made these accounts harder to dismiss as bots was their apparent ability to handle unusual prompts. In one documented case, an account was asked to decode a hex-encoded message instructing it to reply with the word "Pineapple," and it responded correctly in ordinary text. Accounts also sent personalized voice notes, including one that read aloud a Unix timestamp supplied during the conversation and another that spoke a requested username. These responses stayed in character even when targets tried to expose the account as automated, which added a layer of apparent authenticity that classic "bot tests" used to reliably catch.
What to watch for
- Unsolicited flirtatious outreach from an unknown account, especially when it quickly becomes transactional
- A conversation that follows a repetitive script (location, interests, job) rather than natural relationship-building
- Repeated attempts to move the chat to Discord, Telegram, Signal, another messaging app, or a paid-content platform
- Overly eager engagement despite low likelihood of a real relationship
- Personalized replies or voice notes offered specifically as "proof" the account is a real person
How to build resistance
The core lesson is that personalization can no longer be trusted as proof of a genuine human on the other end of a conversation. Unusual replies, decoded messages, and personalized voice notes were once considered strong signals of authenticity, but this reporting shows automation may now be able to mimic them. Employees and general users should treat unsolicited flirtatious messages with caution, particularly when they quickly become transactional or push toward another platform. Most importantly, no one should send money, gift cards, cryptocurrency, intimate images, identity documents, or account credentials to someone they only know through an online conversation, regardless of how convincing or personalized that conversation seems. Awareness training for general staff, and particularly for younger employees or those active on social media, should incorporate this pattern as a recognizable example of a modern social engineering funnel that blends scripted messaging with possible AI-assisted responses.
Key findings
- Flirty promotional accounts used a repeatable conversation “funnel”: open casually, ask qualifying questions, then push users toward Discord and paid adult-content pages.
- Some accounts appeared capable of dynamic responses (e.g., decoding a hex-encoded instruction to reply “Pineapple”), suggesting automation beyond simple canned replies.
- Voice notes were used and included personalized content (reading a Unix timestamp or saying a requested username), which could be human-recorded or generated via text-to-speech.
- Traditional “bot tests” (odd questions, decoding tasks, voice note requests) may no longer reliably distinguish a real person from an automated operator.
Who’s being targeted
- Commonly targeted roles: All employees (general awareness), HR (romance scam / sextortion risk awareness), Finance (payment scam awareness), Employees active on social media.
- Affected industries: Gaming / online communities, Social media users, Online content platforms.
- Attack channels: website, discord.
- Impersonated: A flirty local person (fake persona) promoting adult content, A real person chatting 1:1 (fake persona using automation), A flirty person sending voice messages (could be text-to-speech).
Red flags to watch for
- Unsolicited flirtatious outreach from an unknown account
- Repeated attempts to move the conversation to Discord or another platform
- Conversation follows a repetitive script (location, interests, job) rather than natural relationship-building
- Account stays ‘in character’ even when challenged as a bot
- Overly eager to keep conversation going despite low likelihood of a real relationship
- Proof-of-human prompts are answered in suspiciously ‘perfect’ or automated ways
- Personalized voice notes used as ‘proof’ of legitimacy
- Conversation remains transactional or nudges toward paid platforms
- Requests for money, intimate images, or personal details
Frequently asked questions
How do these flirty X DM scams work?
Accounts open with casual, flirtatious messages and ask repetitive qualifying questions like where you live and what you do for work, then steer the conversation toward Discord and paid adult-content pages.
Can voice notes prove an account is a real person?
No. The accounts sent personalized voice notes, such as reading back a Unix timestamp or a requested username, but this could be human-recorded or generated with text-to-speech, so it should not be treated as proof of authenticity.
What are the red flags of this type of scam?
Warning signs include unsolicited flirtatious outreach, a conversation that follows a repetitive script rather than natural back-and-forth, and repeated attempts to move the chat to Discord, Telegram, Signal, or a paid-content platform.
What should someone avoid doing if they suspect this scam?
Avoid sending money, gift cards, cryptocurrency, intimate images, identity documents, or account credentials to someone known only through an online conversation.
Read the video transcript
You get a DM on X: “Hey :) where are you from? what do you do for work?” Looks flirty, looks normal… But it’s a scripted funnel. They ask where you live, what you like, your job… then start pushing, “Let’s move to Discord,” and link a paid adult page. Here’s the twist: even weird tests don’t prove they’re real. These accounts can decode a hex message to reply “Pineapple” and send a custom voice note with your username. If a flirty rando keeps steering you to Discord or a paid site, stop. Don’t send money or intimate content, just block and move on.