惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
博客园 - 【当耐特】
博客园_首页
The GitHub Blog
The GitHub Blog
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
有赞技术团队
有赞技术团队
博客园 - 三生石上(FineUI控件)
D
Docker
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
酷 壳 – CoolShell
酷 壳 – CoolShell
雷峰网
雷峰网
小众软件
小众软件
I
InfoQ
A
About on SuperTechFans
T
The Blog of Author Tim Ferriss
S
SegmentFault 最新的问题
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - Franky

GRAHAM CLULEY

Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man 'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself Google's Gemini lets strangers send messages from your locked Android phone
How one man used 10,000 bots to steal $8,000,000 from mus...
2026-03-25 · via GRAHAM CLULEY

A 54-year-old man has pleaded guilty to defrauding online music streaming platforms out of more than US $8 million, after creating hundreds of thousands of songs with AI, and then using bots to play them billions of times.

Michael Smith, of Cornelius, North Carolina, pleaded guilty in the Southern District of New York to one count of conspiracy to commit wire fraud.

To understand how the fraud was committed, it is helpful to understanding how streaming royalties work. Platforms like Spotify and Apple Music do not pay a fixed rate per stream. Instead they divide a pot of money between all of the artists whose songs have been streamed that month. The more streams your song receives, the larger your slice of the pot.

But that also means that the more 'fake' streams your song receives, the smaller everyone else's royalty cheque. In other words, Smith was not just fraudulently earning money - he was taking it directly out of the pockets of legitimate artists.

Smith's scheme operated at an industrial scale. He created thousands of accounts on music-streaming platforms and used as many as 10,000 bots to cause those accounts to continuously stream the songs.

He spread his automated streams across thousands of songs, in an attempt to avoid detection. And because he needed thousands of songs, he used AI to generate them.

Smith is said to have worked on the scheme with two unnamed accomplices - a music promoter and the CEO of an AI music company - who began providing him with thousands of songs on a weekly basis.

Originally the songs had filenames beginning with random strings of letters and numbers, but when uploading them to streaming platforms Smith would rename them with names like "Zygotes" and "Zyme Bedewing," and claimed they were recorded by made-up artists like "Calorie Event," "Calms Scorching," and "Calypso Xored."

The AI-generated songs were streamed by his bots billions of times, fraudulently earning US $8 million in royalties.

Smith has agreed to pay US $8,091,843.64 in forfeiture, and will be sentenced on July 29, 2026. He faces a maximum sentence of five years in prison.

The case acts as a warning shot to music streaming platforms that AI tools have made it trivially easy to generate passable-sounding music at scale - with every fake stream not just generating illicit income, but actively depriving genuine artists.

Spotify and other streaming platforms do take steps to remove AI-generated content that is attempting to commit fraud, but it is clear that the problem is an ongoing fight - with fraudsters and streaming services battling to knock out the other.