The Daily Read·Y Combinator · Aug 5, 2026

Y Combinator · Request for Startups

Proving You're Human

Deepfakes and voice clones have shattered every trust signal the internet was built on. Y Combinator argues that rebuilding human verification—without surrendering privacy—is the infrastructure challenge of the decade.

thumbnail
$25M
Wired by one worker
100%
Deepfake call cast
1 min
Runtime
~5 min
Read time

Tap a timestamp pill below to jump the video to that moment.

Every trust signal we built assumed faking a human was expensive

In early 2024, a finance employee at a multinational firm joined what looked like a routine video call with his CFO and several colleagues. He wired $25 million. Every other person on that call was a deepfake—AI-generated video and cloned voice, indistinguishable in real time from the real people.

“Recently, a finance worker joined a video call with his CFO and several colleagues and wired out $25 million.”
“Recently, a finance worker joined a video call with his CFO and several colleagues and wired out $25 million. It turned out that every other person on that call was a deepfake. This isn't science fiction anymore. Voice clones and fake video calls are getting cheap and ultra-realistic, and fraud like this is exploding.”

The deeper problem isn't that one heist succeeded. It's that this heist was possible at all because it exploited trust signals that date back to the early internet: if you can see someone's face, hear their voice, read their words—they must be real. That assumption held for decades because producing a convincing fake was genuinely hard. That world, as Y Combinator puts it bluntly, “has disappeared.”

The knock-on effects run far beyond wire fraud. Bot armies poison social media discourse. Fake profiles on dating apps waste real people's time and emotional energy. Astroturfed product reviews erode consumer trust in e-commerce. In each case, the underlying failure is the same: no reliable way to verify that a human being—a specific, real, non-duplicated human being—is on the other end of the interaction.

“We don't really have a good way to tell who is real online anymore.”
“The scary part is that we don't really have a good way to tell who is real online anymore. It used to be that if you saw someone's face or heard their voice, that was enough. Not anymore. Every trust signal we have was built for a world where faking a human was expensive, and that world has disappeared.”

Rebuild the trust layer—but do it without demanding everyone's identity

Y Combinator frames this as a platform-layer infrastructure problem, not an application-layer one. The analogy is instructive: just as HTTPS sits beneath every website and handles encryption so that individual apps don't have to, a human-verification layer would sit beneath every bank, app, and video call and handle the question of “is this a real person” so that each product doesn't have to solve it independently.

The spec for this layer is deliberately open-ended—YC says they don't know exactly what the solution looks like. But they name a constraint that rules out most obvious approaches: it cannot require everyone to surrender their privacy. National-ID verification and biometric databases can answer “is this a specific, named human?” but they concentrate enormous power in whoever runs the database, create honeypots for attackers, and exclude people who can't or won't submit to identity registration. The solution has to verify humanness, or uniqueness, without necessarily revealing identity.

“Rebuilding the trust layer of the internet—ideally without making everyone give up their privacy.”
“So we think one of the most important problems of the next decade is rebuilding the trust layer of the internet, knowing that there's a verified human on the other end of a call, a message, a transaction. We don't know exactly what the solution looks like here. Ideally, it's one that doesn't make everyone give up their privacy.”

The value proposition is stark. Whoever builds this credibly becomes mandatory infrastructure. Every bank needs it before authorizing a wire. Every social platform needs it to enforce one-account-per-human. Every dating app needs it to guarantee matches are real people. Every review platform needs it to strip out astroturf. That's not a startup building a feature—it's a startup becoming the authentication substrate for the internet.

“Imagine Twitter with no bots in the replies, dating apps where every match is a real person…”
“And it's not just about stopping scams. Imagine Twitter with no bots in the replies, dating apps where every match is a real person, and reviews written by people who actually bought the thing. Whoever builds this becomes the layer every bank, app, and video call will check before it trusts anyone.”

The technical approaches in play range from hardware-anchored attestation (Worldcoin's iris scanner, device-bound keys) to zero-knowledge proofs that let you prove “I am human and unique” without revealing which human, to web-of-trust models where existing verified humans vouch for new ones. Each involves hard tradeoffs between liveness, privacy, cost, accessibility, and resistance to collusion. YC is explicitly inviting founders to bring their own bets on which tradeoff profile wins.

The quick version

  • The $25M deepfake wire-fraud case is not an anomaly—it's a preview of what happens when every prior trust signal (face, voice, message) can be faked cheaply at scale.
  • The problem is infrastructure, not application: the fix needs to live one layer below individual products, the way HTTPS lives below websites.
  • Privacy-preserving humanness proofs—proving you're a unique real person without revealing which person—are the design target. Pure identity databases don't clear this bar.
  • The economic prize is unusually large: a credible solution becomes mandatory checkpointing infrastructure for banking, social, commerce, and communication simultaneously.
“Every trust signal we have was built for a world where faking a human was expensive, and that world has disappeared.”— Y Combinator

The internet's original trust stack assumed scarcity of fakes. That assumption is gone, and no single app can fix it alone—which is exactly why it looks like a platform opportunity rather than a product feature.