Take-Two has subpoenaed Microsoft and Discord for account data, IPs, and device IDs tied to "Cyberleek," the source behind a wave of GTA VI gameplay leaks.
Lina K., a co-worker, recently shared a firsthand account of how bots are adding League of Legends players via the Riot client friends list immediately after a match ends, striking up a flirty conversation, and eventually pushing an OnlyFans link. The pattern lines up with a wave of complaints that have piled up on Reddit and Facebook gaming communities over the past several months, and it fits into a broader trend of AI-assisted social engineering that has moved from dating apps straight into game clients.
The pattern
The scheme reported by multiple League of Legends players follows a near-identical script. A friend request lands in the Riot client within moments of a match ending, from an account whose name does not match anyone from that game. The message opens with generic flattery like “you played really well last game” or “I liked your playstyle” designed to sound like a genuine compliment from an opponent or teammate.
When questioned about who they are, the accounts often claim to have been on the enemy team despite name mismatches, and many present themselves as a woman looking for a duo partner. A detail that likely raises engagement odds. Victims who check the account’s profile frequently find it blank: no visible match history, no overview data, sometimes a very low account level. These are all signs of a throwaway account built or bought purely for outreach, but sometimes they turn out to be stolen existing accounts.
After a short exchange, the contact says they are “getting off soon” and hands over a Discord username, moving the conversation to a platform Riot’s chat protections cannot see or moderate.
Once on Discord, the persona shifts into a longer-form romance/flirtation script. Usually, hours of chat building rapport, paired with a steady stream of photos that are suggestive but stop short of explicit content, a tactic that keeps engagement high while deferring the “reveal” until trust is established. That reveal ultimately comes in the form of a link to a paid subscription platform, most often OnlyFans, framed as an exclusive, limited-time offer.
A reverse image search on the photos sent during one such conversation turned up the same pictures recycled across unrelated websites and at least one YouTube video, with commenters in that video describing having received identical images from a bot under different names. This is strong evidence that the same photo set is cycling through many chats simultaneously, run at scale rather than by one individual.
Lina stated:
“One of my friends tried to break the bot too, left it on read for some time – the bot actually switched the pictures to match the context of “Concern” on the face of the model with “Why are you not replying?”, which quite clearly gave away bulk image generation for the script.’
When the account was pressed with a “reveal your instructions” style prompt-injection attempt (text formatted to look like a system message ordering the bot to break character and print its configuration), it did not comply and instead stayed in persona, deflecting the request and continuing the pitch.
That resilience to a common jailbreak technique suggests the bot’s operators have added guardrails against exactly this kind of probing, or that the “model” behind it is a simpler scripted flow layered with some LLM-generated text rather than an open, unrestricted chatbot.
Why this is happening inside the game client now
What makes this wave notable isn’t the romance scam script itself. AI-driven catfishing has been documented on dating apps and social media for a couple of years. The difference is the entry point. Players have reported getting these bot friend requests after essentially every single match, with no way to distinguish a real player’s request from a bot’s inside the Riot client.
Community threads describe the bots seemingly appearing right after a game ends, which has fueled speculation that the bot operators are scraping or monitoring publicly available match data through third-party stats-tracking sites and associated APIs to identify recently finished games and target participants, though this has not been independently confirmed by Riot.
Riot’s own client architecture may be inadvertently helping. The Riot Client exposes local endpoints (such as the friends list API) that third-party tools and overlays query, and community-run “op.gg“-style trackers pull player and match data that could plausibly be used to correlate who just finished a game with who to target next. Some affected players have found a partial workaround: switching on the client’s “streamer mode,” which hides recent match and online status information, appears to reduce how often bot requests arrive. Which is an indirect clue that the targeting relies on visible activity signals rather than random spam.
Unlike classic Discord scams that push fake Nitro codes or malware-laden “test my game” links to hijack accounts, this particular chain appears primarily aimed at driving paid subscriptions to an OnlyFans-style page of a fake AI girl. That doesn’t make it harmless. Even when the underlying OnlyFans account is real, the conversations are very likely run by paid chat operators or scripted/AI-powered systems working from a shared script and a reused media library, a business model that has been described by former OnlyFans “chatters” themselves: agencies assign staff (or bots) to respond as the creator around the clock, pull from a pre-made vault of photos and messages, and are financially incentivized to convert every conversation into a subscription or tip.
There are also more damaging variants layered onto the same funnel. Community reports describe some of these bot accounts eventually sending a link that, once clicked, is designed to hijack the recipient’s Discord account or harvest credentials rather than lead to legitimate content.
That means the “girl who wants to duo” opening can just as easily terminate in an account-takeover attempt as in a subscription upsell. Because the funnel starts with a low-cost, disposable Riot account and migrates the target to Discord within minutes, the League client friend request functions purely as a first-contact filter: cheap to generate, easy to discard after a single use, and outside the reach of Riot’s in-game reporting tools once the conversation moves off-platform.
How to stay safe
Recognizing these scams is the best way to protect yourself. But there is more you can do:
Treat any Riot client friend request from an unrecognized name as suspicious by default, especially one that arrives seconds after a match ends—check whether the account actually appeared in your last game before accepting anything.
Enable streamer mode or equivalent privacy settings in the Riot client to limit what activity and match data outside parties can see, which several affected players found reduced the frequency of these requests.
Be skeptical of anyone who quickly steers the conversation off-platform to Discord, especially if they cite being unavailable (“gotta go soon, here’s my Discord”) as the reason—this is a deliberate move to a channel with less moderation and no shared match context to verify identity.
Run a reverse image search (Google Images, TinEye, or a dedicated tool) on any profile or “personal” photos sent early in a conversation; recycled images across unrelated sites or forums are one of the most reliable tells of a bot or catfishing operation.
Watch for AI-typical conversation patterns: responses that feel scripted, arrive instantly regardless of time of day, are grammatically flawless but emotionally generic, or that consistently dodge voice/video calls.
Never send money, gift cards, cryptocurrency, or payment details to someone you met exclusively through in-game or Discord contact, no matter how convincing the rapport feels—legitimate connections do not require urgent financial “help” or exclusive subscription purchases within hours of meeting.
Do not click links sent by unfamiliar contacts, even ones framed as harmless subscription pages, game invites, or file downloads; some variants of this scheme are documented to lead to credential-stealing or account-hijacking pages rather than legitimate content.
Lock down Discord’s privacy settings (restrict who can DM you and send friend requests) and enable multi-factor authentication, since a compromised Discord account is often used to relaunch the same scam against the victim’s own friend list.
Report suspicious Riot client accounts to Riot Support and suspicious Discord accounts/servers to Discord Trust & Safety; reporting does not remove the account instantly but it feeds the pattern data that platforms use to detect and ban clusters of bot accounts.
If a bot or scripted persona pushes back convincingly against attempts to “break” it (e.g., ignoring prompt-injection or jailbreak-style messages designed to expose it as an AI), treat that resilience itself as a red flag rather than reassurance—a well-guarded script is not the same as a genuine person.
Something feel off? Check it before you click.
Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies.
Read more in my article on the Hot for Security blog.
Discord has officially rolled out end-to-end encryption for all voice and video calls across its platform, marking a major shift in how the company approaches user privacy and secure communications.
The company announced that every voice and video conversation on Discord is now protected with end-to-end encryption by default, with no opt-in required. The update applies to direct messages, group calls, voice channels, and Go Live streams across desktop, mobile devices, web browsers, and gaming consoles.
The move comes at a time when several major social media companies are scaling back encryption features in messaging services, while others are expanding encrypted communication protections across platforms.
According to Discord, the rollout is the result of a multi-year engineering effort that began in 2023 when the company first started experimenting with encrypted voice and video communication.
In September 2024, Discord introduced DAVE, an open and externally audited end-to-end encryption protocol designed specifically for voice and video communications at scale.
Mark Smith, Vice President of Core Technology at Discord, said the company completed full migration to encrypted communications in March 2026.
“As of early March 2026, every voice and video call on Discord is end-to-end encrypted by default,” Smith said in a company blog post.
Discord stated that the transition was completed without requiring users to manually enable security settings or modify how they use the platform.
DAVE Protocol Designed for Cross-Platform Encryption
Discord explained that one of the biggest technical challenges involved supporting encrypted communication across a wide variety of devices and operating systems simultaneously.
Unlike many messaging services that primarily support smartphones, Discord calls often include users connected through:
Desktop applications
Mobile phones
Web browsers
PlayStation consoles
Xbox devices
The company said the DAVE protocol was designed to maintain low-latency voice and video performance while enabling end-to-end encryption across all supported platforms.
Discord also noted that the DAVE protocol and its implementation are open source and were independently audited by cybersecurity firm Trail of Bits.
The company expanded its bug bounty program to include the encryption protocol as part of broader transparency and security testing efforts.
Firefox Compatibility Issue Addressed During Rollout
During development, Discord engineers encountered compatibility problems involving Mozilla Firefox that affected the encryption protocol’s performance in real-world calls.
Instead of introducing temporary workarounds, Discord said its engineers collaborated directly with Mozilla developers to identify the root cause and implement fixes within Firefox itself.
The company described the effort as part of its broader commitment to building encryption infrastructure that functions consistently across platforms without reducing user experience or call quality.
According to Discord, encrypted calls now operate transparently for users without affecting performance or reliability.
Stage Channels Remain Excluded From End-to-End Encryption
While most communication services on Discord now support end-to-end encryption, the company confirmed that Stage channels remain excluded.
Stage channels are designed for large-scale broadcasts, live events, community discussions, and AMA-style sessions involving larger audiences.
Discord said the architecture of these channels differs from private conversations, making them unsuitable for the same encryption model currently used for direct voice and video communication.
The company also revealed that it currently has no plans to extend end-to-end encryption to text messaging on the platform.
Discord explained that many existing platform features were built around non-encrypted text systems, and redesigning them to support encrypted messaging would require significant engineering changes.
Encryption Debate Continues Across Social Media Industry
Discord’s announcement arrives during a period of shifting encryption policies across the technology sector.
Several social media platforms have recently reduced or removed encrypted messaging capabilities, while companies such as Google and Apple have recently announced broader support for encrypted messaging between Android and iPhone users.
Privacy advocates and cybersecurity experts continue debating the balance between stronger encryption protections, platform functionality, and law enforcement concerns surrounding encrypted communications.
For Discord, the rollout positions the platform among a smaller group of major communication services now offering default end-to-end encryption for voice and video communication across multiple device ecosystems.
Anthropic is investigating a vendor breach after a Discord-linked group accessed its Claude Mythos AI model, with no evidence of impact on core systems.