How fake KYC passes sybil checks
The fake KYC supply chain
Fake identity for sybil attacks is a product with a price list. Stolen document scans trade in bulk, complete with selfies that match the document photo. The premium tier is synthetic: AI-generated faces printed onto forged documents, or real documents with the photo swapped by a skilled editor. Prices fall every year as the tooling gets better.
How it defeats automated checks
Document verification checks the document: is the format right, do the security features scan, does the photo match the selfie. A good forgery passes all three because the checks cannot distinguish a skilled fake from a real document photographed badly. Liveness checks were supposed to fix the selfie half, but attackers adapted with deepfake video and 3D masks that pass the commodity liveness SDKs.
Detection that actually works
The checks that catch fake KYC look beyond the document. Behavioral biometrics during the verification session, how the user holds the phone, how they respond to prompts, are much harder to fake at scale than a document photo. Cross-referencing the identity against independent sources, device history, payment rails, on-chain history, catches the cases where the document is real but stolen.
The cost tradeoff
Every layer of verification costs conversion. Real users abandon flows that feel like a border crossing, and the strictest KYC in the world is worthless if nobody completes it. The tradeoff has to be explicit: high-value allowlists justify intrusive verification, while low-stakes community access does not.
Does manual review catch what automation misses?
Sometimes, but it does not scale and reviewers get fooled by good forgeries too. Use manual review for edge cases, not as the primary defense.
Are AI-generated faces detectable?
The crude ones are. The good ones pass most automated checks, which is why detection moved to behavior and correlation signals.