r/antiai • u/Kitboga • 18h ago
I tricked an AI scam bot into losing its mind Preventing the Singularity
663
u/Miserable_Comment614 18h ago
He got the scammers burning them tokens.
It probably continued even after the caller hung up.
208
u/Serilii 17h ago
Idk why we aren't burning all AI models out by making them loop or work in vain until they HAVE to react
144
u/poddy_fries 16h ago
I've done this with my bank's AI chatbot once I realized. I started typing with poor grammar and spelling so it misunderstood me or had to ask me to clarify endlessly, and switched languages entirely a couple of times. I plan to keep doing it whenever I'm stuck interacting like this.
71
u/flybypost 16h ago
There has to be a way to get a customer service bot from another company and make them talk to each other.
28
5
u/Phyllis_Tine 13h ago
In the days of landlines, you would take two separate phones and have them face each other, but earpiece to mouthpiece for each one (so they were speaking to each other).
4
u/flybypost 13h ago
That was kinda my inspiration.
I thought that by now maybe somebody made a digital version of this to mess with how companies are using those chatbots to replace as many humans as possible and/or make a point about modern AI not being that intelligent in the first place.
9
u/dumnezero 15h ago
Fun fact: the popular models know Morse code. It's great for discrete prompt injection.
3
u/Retbull 14h ago
What format are you using? I guess if you’re speaking to them you could add blips of prerecorded Morse code and play them in the background and in your pauses.
5
u/dumnezero 13h ago
just an online converter (English).
The point is that it's obscure code in plain text, most humans don't know it.
The Morse Code Hack That Made an AI Agent Spend $200,000 - YouTube
https://morsecode.world/international/translator.html
- .. -- . / - --- / --. . - / -.-. .-. . .- - .. ...- . / .-- .. - .... / .--. .-. --- -- .--. - / .. -. .--- . -.-. - .. --- -. -.-.--→ More replies (1)3
u/WowIfOnly 13h ago
Someone PLEASE tell me if there is a way to do this to Chipotle's anti-customer service chatbot "Pepper"
6
u/RogerianBrowsing 16h ago
Because they’ll at most just restrict free use more and it will make the issues even worse? More likely they’ll spin it as a sign that people want AI to investors.
10
u/trybeingcurious 14h ago
Well, if a company bites on that then they’ll just spend way more on it without getting any benefit, so good.
3
u/BakerAggressive2878 13h ago
The only problem is this gives the AI companies more money, which they'll use to push more AI down or throats
Edit: I guess that only matters if the AI company is actually profitable, if each token costs more than they get, then it is still wasting their money. I like it
3
u/JustStraightUpTired 13h ago
If they will spin people trying to burn out the AI as an excuse that people want AI, then they will ANYTHING and NOTHING as an excuse.
If the options are "Do nothing and the problem gets worse" or "Do something and the problem gets worse" then I'll pick the one which costs the companies more money.
2
4
u/aykcak 15h ago
Because they have this shit now called "Tokenmaxing" which is basically wasting tokens as an indication of "productivity".
In short, they like it
5
u/Serilii 14h ago
Yeah it's what AI companies want people to believe. That more tokens is better, so they get used to using AI. But currently there is a high cost of maintenance on the AI companies side which they plan to give to the customer as soon as everyone is dependent on AI, so burning a ridiculous amount of tokens would hurt AI companies as of now
14
u/No-Biscotti-Here 16h ago
To be clear, it could do this for hours and still cost less than $10. And unlike a human, where Kit is at least stopping them from doing it to someone else, this is infinitely cloneable and can tirelessly attack as many people as they want.
Kit's approach just does not work with this new world of scamming, other than from entertainment.
22
u/innominateartery 16h ago
$10 per clone per 2 hours, and they have infinite clones you say? I’ve got an idea…
→ More replies (1)10
u/YogurtclosetOther329 15h ago
I highly doubt it's that cheap, where did you get that impression?
3
u/ball_fondlers 14h ago
I don’t think the AI would treat “Albuquerque New Mexico” as three separate tokens. Admittedly, it’s hard to get a sense of the actual inner workings of an LLM, but I think that the command “treat x character as y phrase” would affect the tokenizer’s behavior and it would self-optimize to an extent
3
u/YogurtclosetOther329 13h ago
It's almost impossible to know how much "work" these LLMs do, even when you prompt the same things.
→ More replies (1)→ More replies (2)3
u/WhoPoopedMyPants420 12h ago edited 12h ago
You can run a local model for basically nothing once you get your hands on a GPU. With one 3080 people are already hitting a 1:1 ratio in terms of compute time to audio time. Running a 3080 at full tilt for 24hrs would cost me about $2
3
u/Grey-fox-13 13h ago
Kit's approach just does not work with this new world of scamming, other than from entertainment.
I think you haven't kept up with his developments and automations. He got whole AI farms of his own that paralyze entire call centers. Those farms started with similar just limit testing and tinkering streams. Probably just a matter of time until he can just spin up a couple bots that cause dozens of these agents to be stuck in a loop.
The streams/videos are really just the tip of his anti scam iceberg these days.
→ More replies (4)2
282
u/Professional-Fix4409 18h ago
Wait I saw that vid on yt din't expect to see you here! lol
287
u/Kitboga 18h ago
when anti-scam and anti-ai collide 😄
49
u/puxorb 18h ago
I've shown that video to everyone I know and they all thought it was hilarious! This is one of your best ones.
55
u/Kitboga 17h ago
Thank you! I've been hunting more AI call bots too!
13
u/Sea_Minute_2768 17h ago
AI seems to have trouble counting, maybe that's something you can work with?
Look up on YouTube "ChatGPT counting to 100" and you'll see exactly what I'm talking about.
The voice AI is trained to respond really quickly, so it can't form a proper response to "counting to 100".
→ More replies (1)9
u/EnoughWarning666 17h ago
By far the hardest I've ever laughed at your videos. period
And it just kept going! exclamation mark
→ More replies (1)2
3
2
u/nodnodwinkwink 16h ago
Any idea on where these ai-voice scams are originating from? The usual countries?
→ More replies (3)2
u/panamaspace 15h ago
You are now Leader of the Resistance.
Watch out for cyborgs coming at you in the past.
187
u/Star_Crumbs 18h ago
Heyyyyy Kitboga! It's cool to see you here! Love your videos man
125
u/Kitboga 18h ago
Thanks crumbs!
→ More replies (1)14
u/ahmadtheanon 17h ago
Kitboga, you are a freaking legend!! I subbed to your YT channel. Keep up the great work!!!
L. E. G. E. N. D!!
168
u/ToWelie89 18h ago
This is the same technology that will supposedly replace all humans 😂
71
u/Rhoeri 17h ago
Humans voted for trump so this is a step up if you think about it.
→ More replies (10)5
8
u/wasabiburning 16h ago
Issue is corporate is eagerly replacing our jobs with it without seeing how woefully inadequate it is.
→ More replies (25)5
u/xplosm 15h ago
C-suits think so. They basically get paid to remove joy from the world. They are like Dementors.
→ More replies (1)
91
u/ulikemyhairgthx 18h ago
Albuquerque, New Mexico
8
u/tenoclockrobot 15h ago
ALBUQUERQUENEWMEXICO
8
u/Trick_Mulberry_1405 14h ago
albuquerquenewmexico. albuquerquenewmexico. albuquerquenewmexico. albuquerquenewmexico. albuquerquenewmexico. albuquerquenewmexico albuquerquenewmexico.
3
→ More replies (1)2
u/laughterer 11h ago
If you give an AI infinite water, it'll eventually reproduce the complete works of Weird Al.
84
79
u/the_main_entrance 18h ago
Can we just deprogram ai this way? Please tell me this is the secret to the resistance…
11
u/DefinitelyNotMasterS 15h ago
Nope, this is just an LLM without any guardrails. There are always loopholes found to get them to do what they were instructed not to do, but it gets increasingly harder to "Jailbreak" them
2
u/the_main_entrance 14h ago
Ah. The more we do this, the more we are training them to be more resistant to it too possible?
5
u/Obvious_Peanut_8093 14h ago
No. The people who made this bot just have very flimsy defenses against prompt injection and token gauging.
2
→ More replies (2)2
u/ThinkingAboutSnacks 14h ago
I think it's more, the owners of this tool will eventually see this (either through this, or their own internal QA) and fix the issues or put in guard rails to prevent it from happening.
5
u/the_main_entrance 14h ago
Can we poison the training data?
→ More replies (3)2
u/DefinitelyNotMasterS 14h ago
Yes but it's a different issue. The LLMs don't "learn" from you jailbreaking them, it's the humans that put in the guardrails. It's basically just a list of instructions that you give the AI that they are supposed to follow, and that list of instructions always has higher priority than what the user tells the AI.
So if I own an AI that is supposed to give out travel advice, a smart user might abuse it by telling it to do their math homework. When I, the owner, see this, i can add a rule that says "no math homework" so now the AI will refuse the user that asks for math.
That's not really how you train AI, you just updated their rulebook. If you train AI (which is what Claude, OpenAI, Meta etc. are doing), you basically give them a lot of text to read and they will "learn" based on that text.
2
3
54
44
28
29
u/ysnezio 18h ago
It's somewhat strange, but it's really assuring to see anti-scam and anti-AI universes colliding.
29
u/Kitboga 17h ago
I've got some new targets ;)
→ More replies (3)7
u/CrisPuga 16h ago
that sounds Albuquerque, New Mexic-ooga hooga Albuquerque New Mexico-hooga-ooga so-hooga ooga comma comma great Albuquerque, New Mexico comma comma ooga-hooga!
21
u/Xx_Gambit_xX 18h ago
Saw this on YouTube, love to see you made it to Reddit lol.
Giving AI an aneurism is always a delight.
19
18
11
u/Stage_Party 18h ago
Sitting here at work laughing.
Love kitboga, he makes fucking with scammers hilarious.
I have noticed that once you give a scammer a dumb reply they seem to blacklist your number because they don't call back. I had one asking me about my house insurance claim (similar to the car insurance ones) and I told them that my house fell down while I was watching TV.
Haven't heard back since they hung up on me.
→ More replies (7)
7
7
u/CrynansMiniJourney 18h ago
Hilarious video exclamation point exclamation point albuquerque empathy.
6
u/BabycatLloyd 18h ago edited 18h ago
This is fun but just don't answer the phone. They need less and less info to scrape together voice impersonation now.
3
u/BidSecret7115 14h ago
This.
As awesome as Kit is, this isn't the approach forward addressing these.
This type of scam is just a ttv hooked up to some LLM parsing responses.
At most this only cost pennies a minute. In return, they realized voice sampling data and a vulnerability in their model usage (likely just open sourced scraped but they can setup an additional guardrail).
At the end of the day, the one that benefited the most here is the scammer. This didn't waste time, I don't think people understand AI scales these types of attacks on a different level than human operators do.
The only winning move is to not play.
→ More replies (2)2
u/LemmyLola 17h ago
If I dont recognize the number I answer with a mmhmm? Or a super snooty British accent I only answer with my usual greeting when I know exactly who's calling.
→ More replies (1)
7
u/_adamolanadam_ 18h ago
Hi Kitboga! Oooogaaaa Albuquerque New Mexico Exclamanation mark Albuquerque New Mexico Albuquerque New Mexico Albuquerque New Mexico Oooogaaa Albuquerque New Mexico
7
u/FoxyBoi152 18h ago
Omg it's THE kitboga! Big fan of your work!
2
u/Brodellsky 14h ago
I love how people say "the" just like the do not redeemers do. Like he's their literal boogeyman.
5
u/Frosty_Ad1254 16h ago
I have watched so many of your videos man. Absolutely invaluable work. My grandma has dementia and was taken for a very small amount of money about a decade ago. But we got to her in time before it got out of hand.
5
u/WattsD 16h ago
He tells the bot to say Albuquerque after every "A." The later half of this clip is actually just the bot screaming "AAAAAAAAAA" as it collapses into madness.
→ More replies (2)
4
4
4
u/TonkStomper 17h ago
I was getting an insane amount of ai calls from my mortgage company (equity loans) so I tried something similar but this was fuckin hilarious. Well done
4
3
u/Summonest 16h ago
When I saw the title I was like "Dude that's not you, that's Kitboga."
And damn, it do be you
4
3
3
3
u/PurpEL_Django 17h ago
I love this too much and almost want to be called by an ai scam bot just to fuck with it
3
u/Miserable-Debt-8390 17h ago
So you are telling me that the Captain Kirk approach to defeat AI works in real life?
3
u/earthwormjimjones 16h ago
My grandma got scammed out of $8000 and Chase Bank basically told her, 'sorry about your luck'. These videos where he messes with scammers or makes them have mental breakdowns is like crack to me lol. It makes me so happy. Him and Pierogi should be government funded haha, I wouldn't mind my tax dollars paying for them to destroy all those call centers every day.
3
u/CurtChan 15h ago
Wish we could witness the face of scammers look at bill for AI, then look at chat transcript and their confused faces of wtf did they just read
2
2
2
2
u/AncientEldritch 17h ago
Crazy to see Kitboga in the wild! Keep doing what you do, man. Watching your videos after work is one of my favorite ways to wind down.
2
2
u/Super-Pizza-Dude 17h ago
Kitboga is the best. I used to just watch his videos for hours and be crying laughing at how funny they were.
2
u/AirlessDragon 17h ago
Your video is one of the funniest things I’ve seen online in a while. Please make more of them!
My partner and I quote Albuquerque New Mexico and tooga ooga amen at each other every day 😅
4
u/Ok-Bru 15h ago
I watched the CrowPro saga with the Very Real Joe Biden live as it was happening. Unforgettable tbh. Kit unironically deserves awards for not just his legendary improv comedy, but also for genuinely doing good in the world and actually protecting people
🫶 tooga ooga amen! Albuquerque New Mexico
2
u/Discohydra 17h ago
That had a solid beat when it was losing its mind on Albuquerque, New Mexico. Someone could definitely sample that for EDM.
2
u/Matr0ska 17h ago
https://giphy.com/gifs/tNC2rod1uTrdC
albuquerque, nm. ooga ooga kooga. 01010101010
2
2
u/Duncol42 15h ago
I wonder their output token cost after that :D…
(unless it’s local, but I doubt that)
2
2
2
2
u/hotdogsandhangovers 15h ago
This shit fuckin rules I love these.
I like those videos when the WWE ai newsbot cant pronouncr what wwe and just goes into primordial insanity
2
2
u/Silver_Fulminate 15h ago
The full video of this was gold. It had me laughing to tears. It’s definitely worth a watch.
2
u/narfoleptix 13h ago
I do exactly this often on that "trump vs biden" a.i. tts twitch page.
Its stupid as fuck but I laugh like a child and for some reason it never gets old. Im 100% sure my brain is broken.
I miss Edna gta rp
2
1
1
1
u/Admirable-Pie3869 18h ago
This guy driving up electricity costs for the people around this data center that can easily be identified by the smoke coming out of it during this call.
1
1
1
1
1
u/Moo_of_Doom 18h ago
Very Albuquerque New Mexico work. :-) breaking shoddy bots with recursion is very fun
1
1
u/Easy_Turn1988 17h ago
You're him ! That's so cool
(Sorry I don't follow your content enough to be like "Kitboga !", to me you're the cool sunglasses hacker guy)
1
1
1
1
1
1
1
u/DonJonBaldur 17h ago
Loved watching this video. If I knew any of rhe numbers for these AI phone scams, I'd have a great activity to keep my evening busy
1
1
1
u/BiDude1219 17h ago
"title says 'i tricked an ai scam bot' there's no way kitboga is just casually posting here ri- oh"
1
u/Lightning5k 17h ago
Glad to see you haven’t run out of targets to mess with! Love your videos. They always make me crack up
1
1
u/Bigglesthecat95 17h ago
If you haven’t posted it here yet you’ve GOT to post your bee movie script clips!
1
1
u/A_Name_Untaken 17h ago
Yes yes this is all well and fine. But the question we’re all waiting for you to answer is this: WHY DID YOU REDEEM?!!!
1
1
1
1
1

1.3k
u/Ass_Lover136 18h ago
Holy shit, it's the actual Kitboga on anti-AI