A network of 1,140 accounts on X appeared to use ChatGPT to write posts promoting cryptocurrency websites. The researchers who uncovered it called the network Fox8, after cryptocurrency sites connected to the accounts. Its discovery offers a concrete example of how generative AI can help scale online scams—and how a visible clue can make a campaign easier to find.
A network built to draw clicks
Researchers at Indiana University Bloomington discovered Fox8 on X, the social network formerly known as Twitter. Many accounts appeared to use ChatGPT both to create posts and to reply to one another. The content was designed to encourage people to follow links to sites promoting cryptocurrency.
That pattern matters because a large group of accounts can make promotional messages appear active and popular. If a social media system responds to engagement by showing a post to more people, activity from other bot accounts could help extend its reach. Filippo Menczer, an Indiana University Bloomington professor involved in the research, said the activity could mislead both users and the platform.
The messages were not all obviously crude. Researchers said the network posted convincing material promoting the sites, even though the way it used ChatGPT left a recognizable trace. That combination—plausible posts and a detectable clue—makes Fox8 useful for understanding both the promise and the limits of identifying AI-assisted campaigns.
A chatbot phrase exposed the accounts
The researchers began by searching X for the phrase “As an AI language model …”. ChatGPT sometimes uses that wording when responding to prompts on sensitive subjects. After finding accounts that used it, the team manually reviewed them to identify those that appeared to be bots.
The method worked because Fox8’s operators left clues in public posts. Menczer said the network was noticed because its activity was sloppy. The same clue may not appear in a better-run operation, so finding one network this way does not reveal how common AI-assisted botnets are.
Micah Musser, a researcher who has studied the potential for AI-driven disinformation, said the discovery could be only an early example. The account network showed a relatively simple way to use a chatbot, while more sophisticated campaigns could be harder to notice. Researchers cannot infer how many such operations exist from Fox8 alone.
Why generated text can be hard to judge
Large language models generate text in response to prompts. ChatGPT and similar systems are trained using large amounts of data, much of it scraped from the web, along with computing power and feedback from human testers. They can produce fluent responses across many topics, but they can also generate hateful or biased material and make things up.
That fluency can complicate efforts to distinguish automated writing from human writing. William Wang, a professor at the University of California, Santa Barbara, said automatically generated spam webpages are becoming harder for people to recognize. His lab developed a way to distinguish ChatGPT-generated text from human writing, but Wang said it is expensive to deploy because it uses OpenAI’s API. He also described detection as a cat-and-mouse problem, as the underlying AI continues to improve.
For people encountering cryptocurrency promotions, polished writing alone does not establish that a message is trustworthy. Fox8’s posts could sound convincing while still directing readers toward sites promoting crypto. The researchers’ findings show why the context around a message—including who is posting and how accounts interact—can matter alongside the text itself.
Detection depends on access and response
Researchers have warned about the potential for large language models to support disinformation, but the article describes few concrete examples of misuse at scale. Fox8 was a documented case, and its operators’ visible mistake gave researchers a way to identify it. A botnet configured more carefully could be harder to spot and might be more effective at manipulating social media recommendation systems.
Studying these networks also depends on researchers being able to examine platform activity. Menczer said malicious bots appeared to have become more common on X after Elon Musk took over what was then Twitter, despite his promise to eradicate them. The article also reports that a steep increase in the cost of API access made research more difficult.
After Menczer and Kai-Cheng Yang published their paper in July, someone at X apparently took down the Fox8 botnet. The research group had previously alerted Twitter about new findings on the platform, but Menczer said it no longer did so with X because the company was not responsive and lacked staff. The episode leaves a practical challenge: researchers need to spot suspicious networks, while platforms need to be able to act on what they find.