In brief
- Researchers from ETH Zurich, MATS, and Anthropic built an AI pipeline that matched anonymized Hacker News accounts to real LinkedIn profiles at 90% precision.
- The attack runs on nothing but web search, embeddings, and reasoning models like GPT-5.2, at a cost of roughly $1 to $4 per target—no hacking or data breach involved.
- The paper's authors withheld their code, prompts, and every real identity they uncovered, and say the study passed through ETH Zurich's ethics review board before publication.
It’s the end of internet anonymity as we know it, according to loads of freaked out social media users who just discovered an AI-related study today.
The research paper making the rounds on X and Reddit again today is from a study in February, and the gist of the findings is scaring the hell out of internet anons everywhere: AI can figure out who you really are from an anonymous account.

The paper is titled "Large-scale online deanonymization with LLMs," and it comes from researchers at ETH Zurich and the AI safety group MATS, working alongside Nicholas Carlini, a researcher at Anthropic, the company behind Claude.
The researchers claim that large language models, the AI systems behind Claude, ChatGPT, and Gemini, can read someone's anonymous posts and figure out who they are in real life. Not by hacking anything, just by reading, searching, and reasoning, the same things these chatbots already do for a million boring tasks everyday.
Researchers built an AI that doxes any "anonymous" reddit account in under a minutes for $2.
eth zurich and anthropic published a terrifying paper proving that "practical anonymity" on the internet is officially dead.
they built a fully autonomous ai pipeline that takes your… pic.twitter.com/XMeXifhDf3
— Superman (@thesupermannx) September 23, 2026
“Our results show that the practical obscurity protecting pseudonymous users online no longer holds and that threat models for online privacy need to be reconsidered,” the paper reads.
How the AI actually pulls this off
The researchers broke the attack into four steps they call Extract, Search, Reason, and Calibrate.
“Extract” means feeding an AI someone's posts and having it summarize the person: where they might live, their job, their hobbies, even a quirk like British spelling or a dog's name mentioned in passing.
“Search” turns that summary into an embedding, a string of numbers a computer can use to instantly find similar-sounding profiles among thousands of candidates.
“Reason” is where a more powerful model looks at the best few matches and thinks through which one actually fits, cross-checking details the way a human investigator would, just much faster.
“Calibrate” has the AI rate its own confidence, so it only guesses when it's fairly sure and stays quiet otherwise.
In one test, the team gathered 338 users of the mostly pseudonymous Hacker News message board who had linked their LinkedIn profile in their bio, stripped out anything identifying, then asked an AI agent to figure out who they were using nothing but web search. It correctly named 226 of them, 67%, and was wrong on roughly one in 10 of the guesses it actually made.

In a separate test on transcripts from Anthropic's own interview research with 125 scientists, the AI correctly identified at least 9 people just from how they described their work.
Here’s the scary part
The cost of doing this all is the real finding here. Running one of these searches costs between $1 and $4 in AI subscription fees, according to the paper.
It also doesn't require a data breach, a hack, or insider access. It uses the same web search and summarization abilities built into ordinary chatbots. The researchers argue that's exactly why it's hard to block: there's no single "deanonymize this person" switch to disable, just a chain of individually harmless-looking tasks.
This isn't the first time a handful of details has unmasked someone. Back in 2008, researchers cracked Netflix's supposedly anonymous movie-rating dataset by matching it against public IMDb reviews. The difference now is that AI does the matching on messy, unstructured text, jokes, comments, offhand mentions, instead of neat spreadsheets, and it does it on its own.
Now, the “everyone calm down” part
The scariest-sounding numbers in the paper come with a catch worth sitting with. To measure success, researchers needed subjects whose real identity they already knew, so they picked accounts that had already linked to LinkedIn, or split one person's own post history into two halves and hid the connection.
That's a controlled best-case setup, not proof that any random pseudonymous account can be cracked today.
Scale also cuts against the scariest numbers from the study. The bigger the haystack of possible candidates, the harder the needle gets to find. Against a pool of 89,000 candidates, the strongest AI method still caught only about half of correct matches at 90% precision. Precision meaning how often its guesses were right, recall meaning how many real matches it actually caught.

The researchers also didn't publish their tools, prompts, or any of the real names they uncovered, and the study went through an ethics review board before release. They're not handing anyone a doxxing kit. They're documenting a capability the authors say already exists in current AI models, paper or no paper.
Why this matters even if you've never posted on Reddit
Crypto users already know this fear intimately. A wave of doxxings and kidnapping attempts following the 2025 Coinbase data breach, among many others, showed how fast a leaked identity turns into a real address at someone's door.
AI-driven deanonymization is the same threat with the breach removed: it works off what you've already posted in public, no leak required.
It also lands a few months after Anthropic disclosed that state-backed hackers used Claude to run most of a cyberespionage campaign on their own, a reminder that AI misuse research keeps outrunning the guardrails meant to contain it.
For anyone who posts under a pseudonym because of activism, abuse, sexuality, immigration status, or a job that frowns on public opinions, this means that hometowns, employers, and even a pet's name, scattered across years of old comments, add up into a fingerprint. That was always possible—AI just makes it faster and cheaper to do.
But if that sort of doxxing is a concern, the fix isn't panic, it's habit: fewer specific, identifying details tied to any one pseudonym, and for anything genuinely sensitive, tools built not to retain your data at all.

