Vox Trust

Vox Trust › Voice-cloning scams

Voice-cloning scams: how they work and how to protect yourself

Scammers copy the voice of a child, parent or friend from a few seconds of audio taken from social media or messaging apps, then call or send voice messages asking for money in a hurry. Listening is no longer enough to tell a real voice from a cloned one. Here is how the scam works, what to do in the moment, and what technology can change.

How the scam works

  1. The scammer collects a few seconds of the victim's voice: public videos, forwarded voice notes, a short call.
  2. An AI tool generates new sentences with the same timbre and way of speaking.
  3. Then comes the call or voice message: an accident, an arrest, a kidnapping, a lost phone. Always urgent, always secret.
  4. The ask is an immediate transfer, gift cards or crypto, to an account you do not know.

Warning signs

  • An emergency with extreme urgency, and pressure not to hang up.
  • A request for secrecy: "don't tell anyone".
  • Payment to an account in someone else's name, or by gift cards or crypto.
  • A new number, or "my phone broke".

What to do in the moment

  1. Hang up and call back on the number you already have. This is the FTC's core advice.
  2. Agree on a family code word and ask for it before anything else. Pick something odd that is nowhere online.
  3. Ask a question only the real person could answer.
  4. Never pay under pressure. A real emergency survives two minutes of checking.
  5. If you paid, call your bank at once and report it to the police and the FTC (in the US: ReportFraud.ftc.gov).

Why deepfake detectors are not enough

Detectors estimate how likely a voice is to be synthetic. They do well on generators they have seen, but every new generation of AI means retraining, and the answer is always a probability. Instead of proving a voice is fake, you can flip the question: prove the real voice is real.

What Vox Trust changes

Vox Trust is an open protocol that seals a voice at the source: the speaker's device signs the audio with a cryptographic key. The receiver checks, in the browser, whether the seal comes from a key they trust and which seconds were altered.

Where it stands: it works for audio files sent without re-compression (for example as a document). Messaging-app voice notes and phone calls are re-compressed, and the watermark that would carry the seal through them is still research. It is a young project without an outside audit yet: use it alongside a code word, not instead of one.

Try the demo in your browser Compare with other solutions

Sources

Frequently asked questions

Can you recognise a cloned voice by ear?

Not reliably. Current tools copy timbre and intonation very well. The FTC puts it simply: do not trust the voice, confirm through another channel.

How much audio does a scammer need?

A few seconds of speech is enough for many tools, and public videos and voice notes on social media usually provide it.

Does a family code word really work?

Yes. It is simple and defeats the imitation, because the AI copies the voice, not what only your family knows. Choose an odd word that never appears online.

Does Vox Trust stop the scam?

Not on its own yet. It proves that an audio file came from a known key and was not altered, which works today for files sent without re-compression. For voice notes and calls, the part that survives re-compression is still experimental.

Is Vox Trust free?

Yes. It is open source (Apache-2.0), with a public specification and a demo that runs in the browser without sending anything to a server.