Dashboard

How to Prompt AI to Explain Code Line by Line

A lazy "explain this code" prompt gets vague filler. A structured one forces the model to explain intent per block, flag non-obvious tricks, and admit what it is unsure about.

Steve Jefferson
Steve Jefferson
Developer Advocate
8 September 20261 min read

How to Spot an AI Voice Cloning Scam

An AI voice cloning scam uses a short recording of someone's real voice, a family member, a boss, a coworker, to generate synthetic speech that sounds like them on a phone call. The caller ID may even be spoofed to match a number you know. You spot it the same way every time: you stop trusting the voice alone and verify through a second channel. Hang up, call the person back on a number you already have saved, and ask something a clone can't answer. This piece covers voice-only impersonation specifically. For manipulated video calls and live deepfake video, see our companion guide on how to spot an AI deepfake scam call.

Voice cloning versus deepfake video: not the same scam

The two get lumped together, but they rely on different tricks and need different defenses. A deepfake scam call typically involves manipulated video, a face on a video call that moves and talks like someone it isn't, sometimes in real time. Voice cloning is narrower and, right now, more common: audio only, no visual to scrutinize. There's no lip-sync glitch to catch, no lighting artifact, no frozen frame. You're working from a phone call where the only signal is a voice that sounds exactly like your daughter, your CEO, or your accounts payable contact.

That narrowness is what makes it dangerous. Most people have never been trained to distrust a voice they recognize. We're wired to believe our ears. A cloned voice exploits that trust directly, with none of the tells a fake video might still carry.

Why voice cloning is cheap and fast now

A few years ago, convincing voice cloning needed real studio audio and technical skill. That barrier is mostly gone. Consumer tools now work off a handful of seconds of clear audio, a voicemail greeting, a public video clip, a recorded work call, and produce a synthetic voice with the right pitch, cadence, and accent. Many are free and run through a simple upload-and-generate interface, no technical background required.

The source material has gotten more abundant too. Anyone who's posted a video with audible speech, given a talk, or appeared in a recorded Zoom has already supplied enough raw material for a usable clone. Producing a passable fake went from specialized and slow to a few minutes with a free app.

Common ways the scam shows up

The family emergency call

A voice that sounds exactly like your kid or grandkid calls in distress: a car accident, an arrest, a robbery, sometimes with a second "official" voice, a police officer, a lawyer, joining to add pressure. The ask is always urgent, wants money moved fast through wire transfer, gift cards, or cash pickup, and comes with instructions not to call anyone else to check.

Is that really my boss on the phone?

The workplace version, sometimes called CEO fraud, targets employees directly. A cloned voice matching an executive calls or leaves a voicemail asking for an urgent wire transfer, a gift card purchase, or updated payroll banking details, framed as confidential and time-sensitive. Small businesses are frequent targets because approval chains are shorter and one employee often has the authority to move money alone. Our guide to AI for small business covers where AI creates real operational risk like this alongside the upside.

A verification protocol that actually works

You don't need to become an audio forensics expert. You need a habit that doesn't depend on how good the fake sounds. Three steps, in order:

  1. Hang up and call back on a number you already have. Never the number that called you, and never one the caller gives you mid-call. Use the contact saved in your phone or the company directory. This single step defeats caller ID spoofing, because the scammer can't intercept a call you initiate to a number they don't control.

  2. Ask a question a clone can't answer. A real family member or colleague knows things that never appear on social media or a company bio, an inside joke, a childhood pet's name, what you discussed last time you spoke. A clone can reproduce tone and cadence, but it has no memory and no access to private context.

  3. Use a pre-agreed codeword for real emergencies. Families and small teams can set a word or phrase in advance, never posted publicly, used specifically when someone claims to be in trouble and needs money or access fast. No codeword, no action, until you verify another way.

All three share a principle: verification happens outside the channel the scammer controls. If the only proof of identity is the phone call itself, you have no proof at all.

Red flags during the call itself

  • Urgency paired with secrecy: pressure to act immediately and instructions not to tell anyone else or hang up and verify.

  • Payment methods that resist reversal or tracing: wire transfers, gift cards, cryptocurrency, or cash pickup services.

  • A request that skips normal process, a payroll change with no ticket, an invoice update with no paperwork, a wire with no second approval.

  • Odd pacing or phrasing: slightly flat delivery, unnatural pauses, or a sentence structure that doesn't match how the person actually talks.

  • The caller avoiding specific follow-up questions or repeating the same phrases when pressed for detail.

Steps to take before a call ever comes in

  • Set a family codeword for emergencies, and a separate one for your team if you handle payments or credentials at work.

  • Require a callback, an in-person check, or written confirmation for any request to move money or change payment details, no matter who appears to be asking.

  • Be aware that voicemail greetings, webinars, interviews, and social videos are all usable source audio for a clone.

  • Brief anyone with wire authority or payroll access on this specific pattern, not just phishing email in general.

None of this needs new software or a budget. It's a habit change: treat a voice, however familiar, as a claim to verify rather than proof in itself. For the broader landscape of AI-enabled fraud, see how to spot an AI scam, and for where AI introduces risk beyond scams, our AI risks guide.

Frequently asked questions

How can you verify a voice is not AI generated?

Don't try to judge it by ear alone. Hang up and call the person back on a number you already have saved, then ask a question that depends on private, shared context, not something guessable from a public profile or bio. If they can't answer, or if you can't reach them at all, treat the original call as fraudulent.

How much audio does a scammer need to clone someone's voice?

Modern voice cloning tools can produce a usable synthetic voice from just a few seconds of clear audio, a voicemail greeting, a social video, a recorded call. Longer, cleaner samples produce a more convincing clone, but a short public clip is often enough for a scam attempt.

Is a family emergency voice scam the same as a deepfake video call?

No. A family emergency voice scam is audio only, typically a phone call using a cloned voice with no video at all. A deepfake video call manipulates a live or recorded video feed. Both exploit AI generated impersonation, but they use different signals and different verification steps. See our deepfake scam call guide for the video-specific version.

What should a small business do to prevent CEO voice fraud?

Require a second verification step, a callback to a known number, an in-person confirmation, or dual sign-off, for any request to wire money, change payroll banking details, or share credentials, regardless of who the caller sounds like. Brief staff with payment or IT access specifically on this pattern rather than assuming general phishing training covers it.

Can caller ID be trusted if the voice sounds right?

No. Caller ID can be spoofed to display a legitimate name or number, and a cloned voice can match someone you know well. Neither is proof of identity on its own. The only reliable check is calling back on a number you already had before the call came in.

How did this land?

About the author

Steve Jefferson
Steve Jefferson

Developer Advocate

Steve builds something with Swarmz every week and writes up what worked, what broke, and what he'd do differently. Tutorials and hands-on guides are his lane.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.