Cross-border e-commerce is a machine that runs on trust at distance. You approve a supplier deposit after a video call where someone pointed a camera at a production line. You hire a remote brand manager after a 20-minute interview. You renegotiate with a distributor without shaking a hand. Deepfake video is now a direct threat to that trust — Arup’s finance employee wired $25 million after a video call full of deepfakes. This is why Scam AI and its new Halo by Scam AI matter. Halo flags synthetic faces during live calls, on your device, before the money moves. For sellers whose supply chain is a web of remote voices, that is not a security feature. It is a payment control.
The problem is deferred trust, not missing technology
Every cross-border operator I know has an informal verification process. Mine used to be: call the supplier, watch them walk the warehouse, check the time zone math, then trust the invoice. That process worked when the only threat was a bad actor lying in an email. Deepfake video changes the calculus because it removes the last sensory cue we used to validate a human: seeing a face move in real time. The person on the other end of a video call is no longer a reliable witness to their own existence.
The Arup case deserves the full quote. From the maker’s launch note: In 2024, a finance employee at Arup joined a video call with what looked like his CFO and several colleagues. Every face on that call was a deepfake. He wired $25 million before anyone realized. Most sellers will never face a $25 million wire, but they face the same pattern in smaller doses. A freight forwarder asks you to update bank details. A sourcing agent says the prep center changed ownership. A factory owner you’ve talked with for months suddenly needs a deposit advanced to a new account. The first video call with a new supplier is exactly the moment a deepfake can kill you, because you have no history with the voice, no reason to suspect the face, and a payment deadline in the email.
What I mean by deferred trust is that we don’t verify identity at the moment of truth. We verify once, early, and let habit carry the money. Halo attacks the moment of truth.
What Halo actually does, and what Scam AI is
Scam AI is positioned as an API-first detection platform. The Product Hunt page describes it as an “API-first solution combining NLP/visual/audio authentication” and says it can “detect synthetic media and malicious intent patterns.” That is a much broader mission than a meeting app. Halo is the meeting-shaped product the team is launching now, and the tagline is blunt: “The person on your next video call might not be real.” The pitch: Halo secures your Zoom, Teams, or Google Meet call live and flags synthetic faces the moment it detects one, entirely on your device. No recordings, no cloud inference.
The implementation matters. The most useful detail is in the maker’s answers in the launch thread. When someone asked whether Halo hooks into the system audio/video pipeline via a virtual camera, the answer was neither: it uses WGC to grab the rendered meeting window directly, so the model sees the same screen the user sees. That is a smart distribution choice. No native SDK from Zoom or Microsoft to wait on, no virtual camera to configure. You install it on your machine, it watches the meeting window, and it flags what it sees.
The most reassuring detail in that same thread is the false-alarm design. A commenter asked what happens when a real person gets flagged because of bad lighting or a compressed webcam feed. The maker said Halo first quality-checks the input. If the lighting is bad, the video is shaky, the compression is heavy, or the face is too far from the camera, it waits for better conditions and only makes a decision once it has good enough data. That is the correct behavior for a product that will live on real, ugly, low-budget video calls.
Keeping up with deepfakes is a treadmill. The same thread describes an agentic system that scrapes the web for new deepfake methods, collects data, and fine-tunes the model. That is the right maintenance problem to have. Whether it works as advertised is an open question, but the team is not pretending a static model will hold.
Pricing is not disclosed. Platform support is not disclosed. Accuracy numbers are not disclosed. For a cross-border operator evaluating this for a real workflow, those blanks are not nitpicks. They are the due diligence.
How it compares to the tools I’d otherwise use
Most deepfake detection I evaluate falls into two buckets. First, post-hoc analysis: upload a recording or a still to Deepware or Sensity, wait for a score, then get a report after the decision has already been made. That is useful for investigations and content moderation, but almost useless for a live wire transfer. Second, research demos: Intel’s FakeCatcher can detect manipulated video in real time, but it is not a consumer-ready layer on top of the meeting apps where money decisions actually happen. Halo’s contribution is distribution and timing. It puts detection in the same window where the decision is being made.
The closest commercial comparison is identity verification infrastructure — the kind that confirms a user is a real person during onboarding. But those systems run on selfies and document uploads, not live meeting streams. Scam AI’s API-first positioning could eventually move into that territory. For now, Halo is the only product in this list that sits in a live call and says “that face is not real” while your finance person is still talking to it.
What cross-border operators should actually take from this
The first takeaway is operational. Add a detection step to your payment-change workflow. Every seller should have a rule that any request to change a supplier’s bank account, any request to advance a deposit, and any request to add a new approved payee must be confirmed on a live call — and that call should have a detection layer running. That is where Halo or something like it earns its keep. The app alone is not the product; the policy around it is the product.
The second takeaway is architectural. The API is more interesting than the app. If I were building a cross-border procurement platform, a payments tool, or a marketplace onboarding flow, I would ask Scam AI for API pricing today. The description says “API-first,” and that matters because sellers don’t need another meeting app as much as they need authentication embedded in the tools they already use.
Why Amazon sellers should care more than Shopify ones
Amazon sellers have more third-party counterparties inserted into the money flow than almost any DTC brand: sourcing agents, freight forwarders, prep centers, compliance consultants, and a constant stream of people claiming they can fix suspensions or recover account health. Each one is an impersonation opportunity. If a scammer convinces your operations person that a video call is with your freight forwarder, they can reroute a container payment. The attack is not unique to Amazon Seller Central, but the density of intermediaries makes it structurally worse. Shopify and other DTC operators control more of their own stack — their domain, their payment rails, their direct supplier relationships — so the attack surface is smaller. The more your business runs on third-party trust signals, which is the definition of marketplace selling, the more you need a real-time face check.
Where the math breaks
Here is the uncomfortable part. Any detector has two errors, and for this use case the costs are asymmetric. A false positive on a call with your real supplier can end a relationship and make you look paranoid. A false negative means you wire money to a deepfake. The maker’s quality-check design reduces false alarms, but it does so by withholding a verdict until the input is good enough. That means there is a window at the start of every call where you get no signal. An attacker who keeps the call short can live inside that window. Base rates are also cruel: if deepfake fraud is rare, even a very accurate detector will produce more false alarms than true catches. None of this is an argument against Halo. It is an argument for using a detector as one layer in a verification stack, not as the sole decision-maker.
The real opportunity is the API, not the app
Most sellers will not successfully roll out a new meeting app to every supplier and employee. But the same detection logic, exposed as an API, can be embedded in the workflows where trust is already verified. Imagine an onboarding flow that asks a new supplier to record a short video statement, then runs it through visual, audio, and NLP authentication before the vendor is added to your payables list. Imagine an influencer outreach tool that screens a pitch video for synthetic media before you pay a deposit. That is where Scam AI’s API-first positioning turns into a real cross-border e-commerce tool, not a meeting accessory.
Where I’d hold off on the hype
Halo is early. The product has a sensible design, but the absence of disclosed accuracy and platform support means you should treat it as a control to test, not a guarantee to trust.
The product catches synthetic faces, not malicious intent. A face can be real and the person can still be a scammer. A face can be synthetic and the conversation can still be benign, as with a brand avatar. The parent platform says it can detect malicious intent patterns, but Halo’s stated job is face authenticity. That distinction matters if you are building an approval workflow around it.
The maker’s answer about WGC suggests a desktop-centric product, and the launch thread’s question about Zoom desktop versus Meet in the browser was not fully clarified. If your finance team runs a mix of operating systems, you need to test both before you make Halo part of a control.
The arms race is real. An agentic scraping system that fine-tunes against new deepfake methods is a maintenance burden, and its speed will determine whether Halo catches the next generation of fakes. I would want independent testing against current generative models before trusting it with a supplier deposit.
What I’d watch / test next
If I ran an Amazon FBA brand with real supplier exposure, I would not wait for this to mature. I’d install Halo on the laptop I use for sourcing calls, run a few deliberate tests with a colleague using a generated deepfake, and then make it a rule: no bank-account changes get approved unless the confirming call was made with a detector running. The launch page points to scam.ai/halo, and that is the fastest way to see whether it works on the exact hardware and meeting clients your team uses. I’d also add an out-of-band rule: any request to change payment details gets re-confirmed through a channel you’ve used before, not through the call where the request appeared. If you build tools for sellers, I’d start watching the Scam AI API rather than the app. Ask for API pricing, test it against your own supplier selfie videos, and wire it into onboarding before the next wave of deepfake attacks turns this category from novelty into mandatory infrastructure.






