According to a recent report by 404 Media, malicious actors have discovered a method to inject AI-generated music onto the official profiles of legitimate artists across Spotify and various other streaming services. The scheme exploits a significant gap in digital distribution channels, allowing scammers to attach their fabricated tracks directly to an existing artist’s catalog.
The process is remarkably straightforward. Fraudsters utilize generative AI tools such as Suno or Udio to produce low-quality songs, often referred to as “slop,” and generate matching album artwork. They then register with a digital distribution service—which allows artists to upload music to platforms like Spotify, Apple Music, Tidal, and Amazon Music—and falsely claim affiliation with the target artist. Because neither the distributor nor the streaming platform effectively verifies these claims, the fake releases are published immediately.
The financial and reputational damage is twofold. Not only does the scammer collect royalties that should belong to the original creator, but the association with the fraudulent content can also tarnish the artist’s brand. 404 Media confirmed the ease of the exploit by testing it in just five minutes, targeting the Brooklyn band Lathe of Heaven. A quote from the outlet highlighted the vulnerability: “It is shockingly easy to post AI generated music under the name of real artists on Spotify… You can do it to small bands, dead artists, even Taylor Swift.”— Emanuel Maiberg
Vocalist of Lathe of Heaven expressed deep frustration regarding the incident, stating, “Being able to enjoy the process of creating something and putting it out into the world knowing it is distinctly a product of our own hands is essentially one of the last driving forces behind making music. The fact that someone could ruin our reputation by dropping this cringe garbage under our name is insanely disheartening.”— Lathe of Heaven
Smaller and deceased artists are particularly vulnerable, as they often lack the large teams used by major stars to monitor their catalogs. Spotify acknowledged this issue to 404 Media, noting that “profiles that aren’t actively managed can be especially vulnerable.” Meanwhile, the musical group Odette Child reported finding over 300 AI-generated impostor tracks since July, featuring impersonations of Taylor Swift, deceased jazz musicians, and other celebrities.
While the loophole predates the current AI boom, the scalability has increased dramatically. With estimates suggesting approximately 50,000 AI-generated songs are uploaded to Spotify daily, the volume of abuse has skyrocketed. In March, Spotify announced a limited beta feature allowing musicians to review releases before they go live, but critics argue progress is too slow. Odette Child stated, “We can just see very clearly that they are not interested in the best possible solution to this problem. We need some sort of infrastructure that can protect us.”
In response, Spotify emphasized that protecting artist identity remains a top priority and that they are collaborating with distributors to block fraudulent submissions at the source. The company has also implemented a verification badge for non-AI tracks and introduced spam filters targeting mass uploads, duplicates, and artificially short tracks. Amazon Music issued a similar statement, affirming its commitment to refining enforcement through advanced detection technologies and ongoing dialogue with rights holders.
Leave a Reply