Voice cloning just turned grandparent scams into a nightmare Voice cloning technology has made grandparent scams more convincing, with open-source models like Bark allowing anyone to clone a voice in under two minutes, according to a first-person account. The author, who tested defensive measures, found that a pre-agreed duress word is the only consistent protection, while platforms like ElevenLabs have added opt-in voice verification and the FCC ruled AI-generated robocalls illegal in February, but targeted attacks remain unregulated. Voice cloning just turned grandparent scams into a nightmare The tech isn't theoretical anymore. ElevenLabs, PlayHT, Respeecher — they all have guardrails, but the open-source models circulating on Hugging Face don't. I downloaded a quantized version of Bark last week and cloned my own voice in under two minutes on a 3090. Good enough to fool my own sister on a bad connection. That's the threshold: not studio quality, just "good enough for a panicked phone call." What makes this different from the IRS impersonation scams of 2019 is the emotional precision. The old scripts were generic. Now the attacker pulls the target's social graph — grandchildren's names, schools, recent vacation photos from public Instagram — and feeds it into an LLM that generates the conversation in real time. The voice model handles the audio. The LLM handles the logic. The human operator just picks the target and hits go. I've been testing defensive approaches with my parents' generation. The only thing that consistently works is a pre-agreed duress word — something innocuous like "how's the garden" that means "I'm being coerced." But that requires the elder to remember it under panic, and the scammer not to catch on. Most families won't set it up until after the first attempt. The platforms know. ElevenLabs added a "voice verification" feature last quarter that lets you register your voiceprint and get alerts when someone tries to clone it. Opt-in, of course. Most users don't know it exists. The open-source side has no such mechanism — and won't, because you can't put a gate on weights that are already public. Regulation is trailing. The FCC ruled AI-generated robocalls illegal under the TCPA in February, but that covers mass dialing, not targeted one-to-one attacks. The NO FAKES Act is stalled in committee. Meanwhile, the tooling gets cheaper every month. If you have parents or grandparents over seventy, the conversation this weekend shouldn't be about passwords. It should be: "If anyone calls sounding like me asking for money, hang up and call me back on my cell. No exceptions." Then make them practice it. TikTok using an AI clone of a founder for ads is a wild move 1d ago /en/news/6762/ YouTube automation in 2026 is basically a war of prompts and 9d ago /en/news/5698/ Next Built a remote control for the AI agents living on my garage → /en/news/6905/ a practical ChatGPT prompt guide https://tanyan888.com/ , with plenty of directly applicable cases. All Replies (0) No replies yet — be the first