September 3, 2026
How OpenCode Almost Lost $400,000 to a Deepfake CEO Scam
OpenCode, an AI harness provider, recently faced a sophisticated scam attempt that nearly cost the company a six-figure loss. The attack…

By Ezekiel Njuguna
5 min read
OpenCode, an AI harness provider, recently faced a sophisticated scam attempt that nearly cost the company a six-figure loss. The attack combined deepfake technology, a lookalike domain, and a convincing sales process that almost worked. The incident offers a valuable lesson for any business that handles enterprise sales or provides high-value services.
The Setup
Someone signed up for OpenCode's service and requested a sales call. This is normal. Enterprise customers often want to discuss their needs before committing to a large spend. The person on the call claimed to be the CEO of a legitimate company. They appeared knowledgeable about OpenCode's product. They asked specific questions about rate limits, pricing, and integration timelines.
The conversation was convincing enough that OpenCode's sales representative scheduled a follow-up. On that second call, the person confirmed their intent to spend $400,000 over the next year. A six-figure annual contract is the kind of opportunity that moves quickly through the sales process.
The scammer then requested increased rate limits. This is a common request from legitimate enterprise customers. Harness providers often need to raise limits for customers with serious usage needs. The request itself did not raise any alarms.
But something felt off to the sales representative. He could not quite identify the issue. The conversation was smooth. The person looked and sounded right. There was a subtle mismatch that triggered his instinct.
The First Red Flag
The sales representative decided to investigate the company independently. He searched for the CEO on video platforms and found multiple public videos of the real CEO speaking at conferences and in interviews. He compared those videos to the person he had spoken with. The resemblance was striking. The voice was similar. The mannerisms matched.
He almost stopped there. It looked real. It sounded real. The company was legitimate. The CEO was a real person.
But he kept digging.
He looked at the email address the person had been using to communicate with OpenCode. It looked legitimate at first glance. The domain name was very close to the real company's domain. Close enough that a quick scan would not catch the difference. When he examined it carefully, he noticed that the domain had been registered only four days ago.
This is a critical detail. A legitimate company with a real CEO and real business operations would have an established domain. It would have been registered years ago, not days ago. The fresh registration was a clear signal that something was wrong.
The Traffic Pattern That Confirmed It
OpenCode's engineering team started looking at the traffic coming from this potential customer. The usage patterns were bizarre. Requests were coming from foreign IP addresses that made no sense for a US-based company. The volume and timing of the traffic did not match what a legitimate business with a serious use case would generate.
This is where the operation started to unravel. The scammer had done an impressive job on the social engineering side, the convincing calls, the deepfake, the lookalike domain. But they had not put as much effort into the technical side. The traffic from their side looked like what it was: a fake account sending garbage data from random locations around the world.
Testing the Theory
OpenCode's team decided to test the waters. They emailed the person asking for more information about their company and their use case. They wanted to see how the person would respond to a request for additional details.
The response came back quickly with a very specific excuse. The person said they were about to get on a plane and could not provide the information right now. They asked OpenCode to move forward immediately. This is a classic pressure tactic. Scammers want you to act fast before you have time to think or verify anything. The urgency is designed to bypass normal decision-making processes.
At this point, the sales representative was convinced something was wrong. But he had one more thing to check.
The Instagram Message That Broke It Open
He found the real CEO on Instagram and sent a direct message asking if they had been in contact with OpenCode about using their harness service.
The response was immediate and clear. The real CEO had no idea what OpenCode was talking about. They had never spoken to the company. They had never expressed interest in the service. They had never authorized anyone to act on their behalf.
The person the sales representative had been talking to was a deepfake.
Someone had used AI-generated video and audio to impersonate a real CEO. They had created a convincing replica that could hold a sales conversation, answer questions, and appear credible. The deepfake was good enough to pass a first inspection. It was only through a combination of instinct, verification, and a direct message to the real person that OpenCode caught it.
Why This Attack Was So Sophisticated
This was not a typical phishing attempt or a simple email scam. This was a targeted operation that combined multiple techniques.
The first layer was the lookalike domain. The scammer registered a domain that was almost identical to the real company's domain. Four days before they contacted OpenCode. This gave them a credible email address that would pass a casual inspection.
The second layer was the deepfake. They generated video and audio that convincingly impersonated the real CEO. The video was good enough to hold a sales call without raising immediate suspicion. This is not easy to do. It requires access to training data, which means the scammer likely collected public videos of the real CEO and used them to train a model.
The third layer was the sales process itself. The scammer followed the normal pattern of an enterprise sales conversation. They expressed interest, asked questions, confirmed intent, and requested rate limits. They did not rush or appear desperate. They played the part of a serious customer.
The fourth layer was the pressure tactic. When OpenCode asked for more information, they responded with an urgent excuse about travel. This is designed to make you feel like you need to move quickly or risk losing the deal. It works because sales people are trained to close deals, not to stop and verify.
The Cost of Getting This Wrong
OpenCode almost lost $400,000. If the sales representative had not listened to his instinct, if he had not looked deeper, if OpenCode had granted the rate limits and provided the service, the company would have been on the hook for significant infrastructure costs with no legitimate customer on the other end.
The scammer would have run up OpenCode's inference costs using the increased rate limits. The same foreign IP traffic they saw would have continued, but at a much higher volume. And then the invoices would have gone unpaid. The company was fake. The CEO was fake. The payment method was almost certainly fake as well.
OpenCode would have been left with a large unpaid bill from their own infrastructure providers and no way to recover the costs.
What OpenCode Learned
OpenCode changed several processes after this experience.
First, the company now verifies all enterprise customers through multiple independent channels. They do not accept a single video call as sufficient proof of identity. They check domain registration dates. They verify email addresses against known company records. They look at traffic patterns from the start of the sales process.
Second, they treat urgency as a red flag. When a potential customer says they need to move fast and cannot provide information, they slow down. Legitimate customers understand verification. Scammers rely on urgency.
Third, they always find a way to contact the real person through a known independent channel. The Instagram message to the real CEO is now part of their standard verification playbook. If they cannot independently verify that the person they are talking to is who they say they are, they do not proceed.
Fourth, they train their sales team to trust their instincts. The sales representative sensed that something was off even though he could not articulate it immediately. That instinct saved the company from a large loss. OpenCode now explicitly encourages everyone on the team to speak up when something feels wrong, even if they cannot explain why.
The Hard Truth
This is the new reality of doing business online. Deepfakes are getting better. Scammers are getting smarter. The tools that make AI useful for legitimate purposes are also being used to commit fraud.
The attack on OpenCode was sophisticated enough to almost work. The deepfake was convincing. The domain was almost identical. The sales process was well executed. It was only a combination of instinct, verification, and a direct message to the real CEO that stopped it.
Be careful out there. The person on the video call might not be the person you think they are. The urgency might be manufactured. The deal might be a trap. Trust your instincts. Verify everything. And never let urgency override your verification process.