The post How an AI Wiz Used ChatGPT to Turn the Tables on a Scammer appeared on BitcoinEthereumNews.com. In brief A Delhi IT worker claims he used ChatGPT to build a fake payment site that captured a scammer’s location and photo during an “army transfer” fraud attempt. The Reddit post went viral after the scammer allegedly panicked and begged for mercy once confronted with his own data. Other Reddit users replicated the technique and confirmed the AI-generated code could work, underscoring how generative tools are reshaping DIY scambaiting. When a message popped up on his phone from a number claiming to be from a former college contact, a Delhi-based information technology professional was initially intrigued. The sender, posing as an Indian Administrative Service officer, claimed a friend in the paramilitary forces was being transferred and needed to liquidate high-end furniture and appliances “dirt cheap.” It was a classic “army transfer” fraud, a pervasive digital grift in India. But instead of blocking the number or falling victim to the scheme, the target claims that he decided to turn the tables using the very technology often accused of aiding cybercriminals: artificial intelligence. Scamming a scammer According to a detailed account posted on Reddit, the user, known by the handle u/RailfanHS, used OpenAI’s ChatGPT to “vibe code” a tracking website. The trap successfully harvested the scammer’s location and a photograph of his face, leading to a dramatic digital confrontation where the fraudster reportedly begged for mercy. While the identity of the Reddit user could not be independently verified, and the specific individual remains anonymous, the technical method described in the post has been scrutinized and validated by the platform’s community of developers and AI enthusiasts. The incident highlights a growing trend of “scambaiting”—vigilante justice where tech-savvy people bait fraudsters to waste their time or expose their operations—evolving with the aid of generative AI.  The encounter, which was widely publicized in… The post How an AI Wiz Used ChatGPT to Turn the Tables on a Scammer appeared on BitcoinEthereumNews.com. In brief A Delhi IT worker claims he used ChatGPT to build a fake payment site that captured a scammer’s location and photo during an “army transfer” fraud attempt. The Reddit post went viral after the scammer allegedly panicked and begged for mercy once confronted with his own data. Other Reddit users replicated the technique and confirmed the AI-generated code could work, underscoring how generative tools are reshaping DIY scambaiting. When a message popped up on his phone from a number claiming to be from a former college contact, a Delhi-based information technology professional was initially intrigued. The sender, posing as an Indian Administrative Service officer, claimed a friend in the paramilitary forces was being transferred and needed to liquidate high-end furniture and appliances “dirt cheap.” It was a classic “army transfer” fraud, a pervasive digital grift in India. But instead of blocking the number or falling victim to the scheme, the target claims that he decided to turn the tables using the very technology often accused of aiding cybercriminals: artificial intelligence. Scamming a scammer According to a detailed account posted on Reddit, the user, known by the handle u/RailfanHS, used OpenAI’s ChatGPT to “vibe code” a tracking website. The trap successfully harvested the scammer’s location and a photograph of his face, leading to a dramatic digital confrontation where the fraudster reportedly begged for mercy. While the identity of the Reddit user could not be independently verified, and the specific individual remains anonymous, the technical method described in the post has been scrutinized and validated by the platform’s community of developers and AI enthusiasts. The incident highlights a growing trend of “scambaiting”—vigilante justice where tech-savvy people bait fraudsters to waste their time or expose their operations—evolving with the aid of generative AI.  The encounter, which was widely publicized in…

How an AI Wiz Used ChatGPT to Turn the Tables on a Scammer

2025/12/05 08:27

In brief

  • A Delhi IT worker claims he used ChatGPT to build a fake payment site that captured a scammer’s location and photo during an “army transfer” fraud attempt.
  • The Reddit post went viral after the scammer allegedly panicked and begged for mercy once confronted with his own data.
  • Other Reddit users replicated the technique and confirmed the AI-generated code could work, underscoring how generative tools are reshaping DIY scambaiting.

When a message popped up on his phone from a number claiming to be from a former college contact, a Delhi-based information technology professional was initially intrigued. The sender, posing as an Indian Administrative Service officer, claimed a friend in the paramilitary forces was being transferred and needed to liquidate high-end furniture and appliances “dirt cheap.”

It was a classic “army transfer” fraud, a pervasive digital grift in India. But instead of blocking the number or falling victim to the scheme, the target claims that he decided to turn the tables using the very technology often accused of aiding cybercriminals: artificial intelligence.

Scamming a scammer

According to a detailed account posted on Reddit, the user, known by the handle u/RailfanHS, used OpenAI’s ChatGPT to “vibe code” a tracking website. The trap successfully harvested the scammer’s location and a photograph of his face, leading to a dramatic digital confrontation where the fraudster reportedly begged for mercy.

While the identity of the Reddit user could not be independently verified, and the specific individual remains anonymous, the technical method described in the post has been scrutinized and validated by the platform’s community of developers and AI enthusiasts.

The incident highlights a growing trend of “scambaiting”—vigilante justice where tech-savvy people bait fraudsters to waste their time or expose their operations—evolving with the aid of generative AI.

The encounter, which was widely publicized in India, began with a familiar script. The scammer sent photos of goods and a QR code, demanding an upfront payment. Feigning technical difficulties with the scan, u/RailfanHS turned to ChatGPT.

He fed the AI chatbot a prompt to generate a functional webpage designed to mimic a payment portal. The code, described as an “80-line PHP webpage,” was secretly designed to capture the visitor’s GPS coordinates, IP address, and a front-camera snapshot.

The tracking mechanism relied in part on social engineering as much as a software exploit. To circumvent browser security features that typically block silent camera access, the user told the scammer he needed to upload the QR code to the link to “expedite the payment process.” When the scammer visited the site and clicked a button to upload the image, the browser prompted him to allow camera and location access—permissions he unwittingly granted in his haste to secure the funds.

Image: RailfanHS on Reddit

“Driven by greed, haste, and completely trusting the appearance of a transaction portal, he clicked the link,” u/RailfanHS wrote in the thread on the r/delhi subreddit. “I instantly received his live GPS coordinates, his IP address, and, most satisfyingly, a clear, front-camera snapshot of him sitting.”

The retaliation was swift. The IT professional sent the harvested data back to the scammer. The effect, according to the post, was immediate panic. The fraudster’s phone lines flooded the user with calls, followed by messages pleading for forgiveness and promising to abandon his life of crime.

“He was now pleading, insisting he would abandon this line of work entirely and desperately asking for another chance,” RailfanHS wrote. “Needless to say, he would very well be scamming someone the very next hour, but boy the satisfaction of stealing from a thief is crazy.”

Redditors verify the approach

While dramatic tales of internet justice often invite skepticism, the technical underpinnings of this sting were verified by other users in the thread. A user with the handle u/BumbleB3333 reported successfully replicating the “dummy HTML webpage” using ChatGPT. They noted that while the AI has guardrails against creating malicious code for silent surveillance, it readily generates code for legitimate-looking sites that request user permissions—which is exactly how the scammer was trapped.

“I was able to make a sort of a dummy HTML webpage with ChatGPT. It does capture geolocation when an image is uploaded after asking for permission,” u/BumbleB3333 commented, confirming the plausibility of the hack. Another user, u/STOP_DOWNVOTING, claimed to have generated an “ethical version” of the code that could be modified to function similarly.

The original poster, who identified himself in the comments as an AI product manager, acknowledged that he had to use specific prompts to bypass some of ChatGPT’s safety restrictions. “I’m sort of used to bypassing these guardrails with right prompts,” he noted, adding that he hosted the script on a virtual private server.

Cybersecurity experts caution that while such “hack-backs” are satisfying, they operate in a legal grey area and can carry risks. Still, it’s pretty tempting—and makes for a satisfying spectator sport.

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.

Source: https://decrypt.co/350935/how-ai-wiz-used-chatgpt-turn-tables-scammer

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Suspected $243M Crypto Hacker Arrested After Major Breakthrough in Global Heist

Suspected $243M Crypto Hacker Arrested After Major Breakthrough in Global Heist

Major breakthrough in $243M crypto heist as suspect arrested! $18.58M in crypto seized, linked to suspected hacker’s wallet. Dubai villa raid leads to possible arrest of crypto thief. A major breakthrough in the investigation into the $243 million crypto theft has emerged, as blockchain investigator ZachXBT claims that a British hacker, suspected of orchestrating one of the largest individual thefts in crypto history, may have been arrested. On December 5, ZachXBT revealed in a Telegram post that Danny (also known as Meech or Danish Zulfiqar Khan), the primary suspect behind the attack, was likely apprehended by law enforcement. ZachXBT pointed to a significant find: approximately $18.58 million worth of crypto currently sitting in an Ethereum wallet linked to the suspect. The investigator claimed that several addresses connected to Zulfiqar had consolidated funds to this address, mirroring patterns previously seen in law enforcement seizures. This discovery has raised suspicions that authorities may have closed in on the hacker. Moreover, ZachXBT mentioned that Zulfiqar was last known to be in Dubai, where it is alleged that a villa was raided, and multiple individuals associated with the hacker were arrested. He also noted that several contacts of Zulfiqar had gone silent in recent days, adding to the growing belief that law enforcement had made a major move against the hacker. However, no official statements from Dubai Police or UAE regulators have confirmed the arrest, and local media reports remain silent on the matter. Also Read: Song Chi-hyung: The Visionary Behind Upbit and the Future of Blockchain Innovation The $243 Million Genesis Creditor Heist: How the Attack Unfolded The arrest of Zulfiqar may be linked to one of the largest known individual crypto heists. In September 2024, ZachXBT uncovered that three attackers were involved in stealing 4,064 BTC (valued at $243 million at the time) from a Genesis creditor. The attack was carried out using sophisticated social engineering tactics. The hackers impersonated Google support to trick the victim into resetting two-factor authentication on their Gemini account, giving them access to the victim’s private keys. From there, they drained the wallet, moving the stolen BTC through a complex network of exchanges and swap services. ZachXBT previously identified the suspects by their online handles, “Greavys,” “Wiz,” and “Box,” later tying them to individuals Malone Lam, Veer Chetal, and Jeandiel Serrano. The U.S. Department of Justice later charged two of the suspects with orchestrating a $230 million crypto scam involving the theft. Further court documents revealed that the criminals had used a mix of SIM swaps, social engineering, and even physical burglaries to carry out the theft, spending millions on luxury items like cars and travel. ZachXBT’s tracking work has played a key role in uncovering several related thefts, including a $2 million scam in which Chetal was involved while out on bond. The news of Zulfiqar’s potential arrest could mark a significant turning point in the investigation, although full details are yet to emerge. Also Read: Kevin O’Leary Warns: Only Bitcoin and Ethereum Will Survive Crypto’s Reality Check! The post Suspected $243M Crypto Hacker Arrested After Major Breakthrough in Global Heist appeared first on 36Crypto.
Share
Coinstats2025/12/06 18:27