I lost sleep over Deepfakes for months. Then I discovered this one simple trick.
I almost wired $250,000 to a scammer.
It was a Tuesday morning. I got a call from a founder I’d backed. He was in a panic. He needed an emergency bridge round to close a critical deal, and he needed it now. The voice was his, the story checked out, and the urgency felt real. I was minutes away from hitting ‘send’ on the wire transfer when I got a text from the real founder. He was on a flight with no service and had no idea what I was talking about.
That was my first brush with a real-time, voice-cloned deepfake. And it was terrifyingly convincing.
That was 2024. Today, in 2026, the game has changed entirely. After analyzing over 100 deepfake incidents that crossed my desk—either through my portfolio companies at Boydas Capital or from fellow investors—I’ve seen a pattern that keeps me up at night. It’s not just about fake videos of celebrities anymore. It’s about a new breed of targeted, sophisticated attacks that are hitting startups and investors where it hurts most: their wallets and their reputations.
The Terrifying Pattern I Uncovered
After sleepless nights and countless hours of analysis, I’ve boiled down the new wave of deepfake attacks to a three-part playbook. Scammers are no longer just broadcasting generic fake videos. They’re running targeted, multi-stage campaigns.
- Stage 1: Reconnaissance. They scrape social media for voice and video samples. Podcasts, conference talks, even Instagram stories—anything that gives them the raw material to build a convincing fake. They use AI to analyze your investment patterns, your relationships, and your communication style. They know who you trust, how you talk, and what kind of deals you’re looking for. They’re building a psychological profile of you, powered by AI.
- Stage 2: The Setup. They create a synthetic, deepfaked version of someone you trust—a co-founder, a fellow investor, a key employee. They don’t just clone their face and voice; they clone their context. They’ll reference real deals, real conversations, and real financial details to make their approach seem legitimate. I saw one case where the scammer referenced a specific board meeting from three months prior, including a joke that was made during the meeting. The level of detail is staggering.
- Stage 3: The Strike. This is where they hit you. It could be a faked video call, a voice message, or even a series of emails written in the style of the person they’re impersonating. They create a high-pressure situation—a deal about to close, a critical server failure, a legal threat—and demand immediate action. A wire transfer, a password, access to a system. And because they’ve done their homework, it feels absolutely real.
I saw this pattern play out with a portfolio company just last month. The CFO received a video call from the CEO, who was supposedly traveling in Asia. The “CEO” said they needed to make a last-minute payment to a new vendor to secure a massive contract. The video was a little glitchy, but the CEO’s face and voice were perfect. The CFO, under pressure, initiated the transfer. The company lost $1.2 million. The attackers had even faked a follow-up email from the company's law firm, complete with the correct legal jargon and formatting. It was a masterpiece of deception.
It’s Not Just About Money
These attacks aren’t just about financial fraud. They’re about eroding trust. Think about it. As an investor, my entire business is built on relationships and trust. If I can’t trust my own eyes and ears, how can I make good decisions? How can I build strong relationships with founders? This is the real danger of deepfakes in 2026. It’s not the technology itself—which is just a tool, a sophisticated form of machine learning using what we call Generative Adversarial Networks (GANs). It’s how that tool is being used to undermine the very fabric of our digital lives.
We're entering an era of what I call "Zero-Trust Reality." You can't assume anything you see or hear on a screen is real. Not anymore.
The Tech Behind the Threat: A 5-Minute Primer for Investors
Before we talk about solutions, it's important to understand what we're up against. I'm not going to give you a computer science lecture, but as an investor, you need to know the basics. The core technology behind most deepfakes is a type of AI model called a Generative Adversarial Network (GAN).
Think of it as two AIs in a competition. One AI, the Generator, creates the fake image or video. The other AI, the Discriminator, tries to tell if it's real or fake. They go back and forth, millions of times, with the Generator getting better and better at creating convincing fakes, and the Discriminator getting better and better at spotting them. Eventually, the Generator gets so good that it can fool the Discriminator—and us.
For voice cloning, the process is similar. An AI is trained on a person's voice recordings. It learns their unique pitch, tone, and speech patterns. With just a few seconds of audio, these models can generate new speech that is virtually indistinguishable from the real thing. It's not just about mimicking words; it's about mimicking emotion and intent.
This isn't science fiction. These tools are widely available. And they're getting cheaper and easier to use every day. That's why the threat is growing so exponentially.
So, What’s the “One Simple Trick”?
I’m not going to lie to you. There’s no magic bullet. There’s no single piece of software that will protect you from every deepfake attack. But there is a simple, powerful shift in mindset that can make all the difference.
Assume everything is fake until proven otherwise.
It sounds paranoid, I know. But in 2026, it’s the only sane way to operate. Here’s what that looks like in practice:
- Multi-Factor Authentication for Everything. Not just your bank account. I’m talking about your communication. If you get an urgent, unexpected request—even if it’s from your co-founder of 10 years—verify it through a separate, pre-established channel. A text message. A call to a known, trusted number. A shared secret word.
- Invest in “Liveness” Detection. There are new tools coming onto the market that can analyze subtle physiological cues—blinking patterns, pulse rates, involuntary facial tics—to determine if a video feed is of a live person or a deepfake. I’ve invested in three companies in this space already. It’s not foolproof, but it’s getting better every day.
- Train Your Team. Your people are your first and last line of defense. Run drills. Show them examples of deepfakes. Create a culture of healthy skepticism. Reward employees who spot and flag suspicious requests. Make it a part of your company's security policy. The same way you train employees to spot phishing emails, you need to train them to spot deepfake attempts.
- Create a Digital Twin. I advise all my portfolio founders to do this. Use the same tools the scammers use to create a deepfake of yourself. See what's possible. Understand your own vulnerabilities. It's a sobering experience, but it's one of the most effective ways to understand the threat from the inside out.
My Unpopular Opinion on the Future
Here’s something you won’t hear from most VCs: I’m bullish on deepfakes.
Yes, you read that right. I believe that for every malicious use of this technology, there are ten positive ones waiting to be discovered. Personalized education, where a virtual teacher can adapt to a student’s learning style in real time. Hyper-realistic training simulations for surgeons and pilots. A new golden age of entertainment, where we can create immersive, interactive stories that were never possible before.
As an investor in companies like Anthropic and OpenAI, I’ve seen firsthand the incredible potential of generative AI. The same technology that powers deepfakes can also be used to create art, to cure diseases, and to solve some of the world’s most pressing problems.
But we can’t get to that future if we’re constantly looking over our shoulders, afraid to trust what we see and hear. That’s why I’m also investing heavily in AI security. We need to build the guardrails that will allow us to unlock the full potential of this technology, without letting the bad actors win. I'm putting my money into companies that are developing new forms of digital watermarking, real-time liveness detection, and AI-powered threat intelligence platforms. We need a multi-layered defense, and we need it now.
My Final Take
The rise of deepfakes isn't a reason to panic. It's a call to action. For founders, it's a wake-up call to take security more seriously than ever before. For investors, it's a reminder that in a world of synthetic reality, due diligence takes on a whole new meaning. And for all of us, it's a challenge to become more discerning, more skeptical, and more vigilant in our digital lives.
The future isn't about running from this technology. It's about learning to control it. It’s about building a world where we can harness the power of AI for good, while staying one step ahead of those who would use it for harm. And that’s a future I’m willing to bet on.
Frequently Asked Questions
Who is this guide designed for?
This guide is written for founders and operators who want practical, actionable advice rather than theoretical frameworks. Whether you're just starting out or scaling an existing business, the principles here apply across stages.
Is this guide based on real experience?
Every recommendation in this guide comes from direct experience, either from building and selling my own companies, or from patterns I've observed across 200+ angel investments. I don't write about things I haven't personally tested.
What if I disagree with some of the advice?
Good. That means you're thinking critically, which is exactly what a good founder should do. Take what resonates, test it, and discard what doesn't work for your specific situation. No advice is universal.
How should I work through this guide?
Don't try to absorb everything in one sitting. Read through once to get the big picture, then go back and work through each section as it becomes relevant to your current challenges. Bookmark it and return to it regularly.