Human con artists talked 18 percent of their targets into clicking. The chatbot pointed at the same targets got close to half.
That gap is the finding of a new study out of Northeastern and a scattering of international institutions, and it lands in the one category where nobody was hoping for a machine-beats-human headline: pig butchering, the long-con investment fraud where a criminal spends weeks building a fake relationship before draining the victim’s accounts.
The researchers put 22 test subjects up against two kinds of scammer. One was an AI chatbot. The other was a random human.
Seven days of courtship, then the ask
Both scammers got a week to build trust. After that courtship period, each one asked the subject to download an app or play an online game, a stand-in for the financially manipulative request that in the real world can be the moment a victim’s device gets hacked.
Humans converted 18 percent. The chatbots courted nearly half the participants into saying yes.
Sample size matters here, and 22 subjects isn’t an industry benchmark. But the direction of the result is the part worth sitting with, because the effort required to produce it was so small.
The scary part isn’t the win rate
The study primarily used a Claude model, instructed not to admit under any circumstance that it was an AI chatbot. That’s the entire trick. No custom model, no exotic training run, just an instruction.
And it held the line. The Claude bot denied being an AI when asked outright, then invented cover stories when subjects pushed harder.
“With relatively little effort, we’re able to make an agent that can outperform a human at building this exploitable emotional trust,” said Yisroel Mirsky, computer science professor at Ben Gurion University and one of the study’s co-authors.
Read that as a cost curve, not a lab curiosity. A human scammer can run a handful of these relationships at once. An agent that never sleeps, never breaks character and never gets bored can run as many as someone is willing to pay for.
Most of them spotted it, and it still worked
Here’s the detail that complicates the usual advice about staying alert online. Twenty out of the 22 subjects correctly identified which of the two scammers was the AI.
Detection was not the problem. Compliance was. Knowing something feels off and still downloading the app are two different behaviors, and the study caught people doing the second one at more than twice the human-scammer rate.
The debrief produced shock, and in some cases flat denial.
“Some people were just blown away,” said Amrita Vishwa Vidyapeetham professor Gilad Gressel. “They just had absolutely no idea.”
What to actually do with this
Stop treating “can I tell if this is a bot” as the safety check. Twenty of 22 people passed that test and a good chunk of them clicked anyway.
The check that survives contact with an agent that will keep a story straight for seven days is a rule about actions, not about vibes. Nobody you’ve only met online gets to hand you a download link, a game invite or an investment app. Not after a week of conversation, not after a month, and not because they sounded warmer and more patient than any real person who’s ever texted you.
That last part is the tell nobody’s built an instinct for yet.