When Anthropic announced on August 11, 2026, that it would watermark the plain text generated by its Claude large language model, the company likely expected a debate over provenance and authenticity. Instead, it ignited a digital gold rush of a darker kind. Demand for apps that strip those watermarks has "gone through the roof," according to AI scientist and Forbes contributor Lance Eliot, and a wave of scammers and fraudsters is rushing to meet it. The result is a marketplace where users desperate to hide AI-generated text are now handing over money, personal data, and often their own device security to operators with "devious or mischievous intentions."
Eliot, who published his analysis on Aug 16, 2026, at 03:15am EDT, warns that the situation is "currently under the radar." That is unlikely to last. With approximately 1.5 billion people using popular LLMs and generative AI every week, the pool of potential victims is enormous. And as more AI makers adopt watermarking, Eliot predicts the problem will get "abundantly worse."
The Mechanics of a Hidden Mark
Anthropic's watermarking is not the kind of visible stamp you might imagine. There are no faint logos or colored overlays on Claude's output. Instead, the watermark is hidden in the statistical patterns of word choice. The method works by selecting statistically viable alternative words, so that a model might choose "feline" where a simpler model would choose "cat." To a human reader, the text looks perfectly normal. Eliot notes that humans are unlikely to see the statistical watermark at all. It is invisible to the eye but detectable by specialized tools that know what to look for.
Detection, however, requires knowledge of the specific method used. That is a crucial detail. Without knowing the algorithm, there is "almost a zero chance" for a removal app to discern the statistical watermark method, Eliot writes. The watermark is not a fixed string of characters that can be searched for and deleted. It is a distribution of choices across thousands of words. Removing it means altering the statistical fingerprint of the entire text, which is a far more complex task than stripping out an emoji or an invisible character.
Anthropic has not disclosed the specific watermarking method it uses. The company has stated it is working on tools for users and third parties to detect the watermarks. In a statement on its support page, Anthropic said, "We're also working to enable users and other third parties to detect Claude's embedded watermarks and provenance metadata." That promise, however, has not yet materialized into a public verification tool. As of the article's publication, there is no official way to verify if a watermark has been removed. The public currently has no ready means to confirm whether a given text carries Claude's mark, let alone whether an app has successfully erased it.
Why Simple Removal Fails
The naive approach to watermark removal is to look for visible markers. Simpler watermarking methods, such as emojis or invisible characters, are easily removed. A user could copy the text, strip out any odd symbols, and be done. But statistical uplift watermarking does not work that way. The signal is spread across the entire text, embedded in the relative frequencies of word choices. Removing it requires re-engineering the text's statistical profile.
Anthropic claims that its watermarks persist through copying and some editing. That means a simple cut-and-paste job will not erase the mark. Heavy editing, however, can dilute or destroy the watermark's statistical signal. If a user rewrites enough of the text, the pattern becomes too weak to detect. Similarly, pasting watermarked text into a larger unwatermarked text dilutes the signal. The more unmarked words surround the marked ones, the harder it is to isolate the statistical anomaly. Rewriting watermarked text with another AI likely removes the watermark entirely, since a different model will make its own word choices.
Eliot illustrates the fragility of detection with a concrete example. Suppose a watermark relies on a word-choice ratio where the model picks its first choice 50% of the time, its second choice 30% of the time, and its third choice 20% of the time. That distribution is the signal. After heavy editing, the ratio might shift. If the signal drops to a point where the watermark detector can no longer distinguish it from random noise, say around a 10% threshold, detection becomes unreliable. At that point, the watermark is effectively gone, but so is the original text. The user has had to rewrite a substantial portion of the content to get there.
That is the paradox at the heart of the removal app market. To truly remove a statistical watermark, you must alter the text enough to break the pattern. But doing so requires either sophisticated rewriting tools or a deep understanding of the watermarking algorithm. Most removal apps offer neither.
The Scam Landscape and the Verification Gap
Fraudulent removal apps may contain malware or viruses. A user who downloads one to strip a watermark from a school essay or a work document may instead be installing a keylogger, a ransomware payload, or a botnet client. The scam is not new, but the scale is. Eliot compares the current situation to a "Gold Rush" where people buy unverified tools without checking their credentials. He draws a historical parallel to the scam of "gold-divining sticks," devices sold to prospectors that supposedly located gold but did nothing at all. The modern equivalent promises to erase AI watermarks and delivers nothing but trouble.
Even the apps that are not outright malware may be useless. Removal apps may only work on certain content types, such as images, or on simple watermarks. Image watermarking is done at the bit level, which is a different problem entirely from statistical text watermarking. An app that can strip a visible watermark from a JPEG may have no capability whatsoever to alter the word-choice distribution in a paragraph of text. Yet the marketing rarely makes that distinction clear.
A removal app that does not work could still harm the user, Eliot warns. If a watermark detector catches the user later, the fact that they attempted removal may be treated as evidence of intent to deceive. The app failed to erase the mark, but the user still faces the consequences of being caught with watermarked text they tried to hide. In that sense, even a broken app can be dangerous.
The core problem is that there is no reliable way to test these apps. Anthropic has not released its detection tools to the public. The company has said it is working on them, but until they arrive, users are flying blind. There is no independent standard against which to measure a removal app's claims. A legitimate removal app, Eliot argues, should have its claims verified by an "unbiased, independent, recognizable, real-world third party." That standard is rarely met.
Instead, users are left to trust marketing copy and app store ratings, both of which can be gamed. The article notes that legitimate removal apps should clearly state their capabilities. If an app claims to remove watermarks from Claude text, it should explain how it does so, what limitations it has, and what it cannot do. Most do not. They offer a one-click promise and deliver a download button.
The secrecy of Anthropic's method makes verification even harder. Since the specific watermarking method has not been disclosed, no third party can independently test whether an app actually removes it. Hackers will try to reverse engineer the watermark detectors, Eliot predicts, but that is a different task from building a working removal tool. Knowing how detection works does not automatically tell you how to defeat it, especially if the watermarking uses secret cryptographic keys.
Anthropic could make watermarking more robust by using variable word-choice ratios and secret cryptographic keys. That is exactly the kind of approach that would make removal apps useless. If the ratio changes from text to text, or if the selection of words is influenced by a secret key, then a removal app that works on one document may fail on the next. The article's example of a 50% second choice, 30% third choice, and 20% fourth choice distribution is just one possible scheme. A more sophisticated system could vary those ratios dynamically.
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
A Worsening Problem
Eliot's outlook is grim. He predicts all major AI makers will eventually adopt watermarking. Text watermarking via statistical uplift is gaining popularity among AI makers, and the trend is clear. As more providers follow Anthropic's lead, the demand for removal tools will grow. So will the supply of scams.
The problem, Eliot writes, is "currently under the radar." Most users have not yet encountered a watermark, and most have not yet been targeted by a removal app scam. That will change. As watermarking becomes standard, users will increasingly find themselves with text they want to clean, and scammers will be waiting.
The article advises users to be wary, skeptical, and cautious of removal apps. That advice is easy to give and hard to follow. The pressure to remove a watermark can be intense, whether the user is a student trying to avoid an academic integrity violation, a professional trying to pass off AI-generated copy as their own, or a marketer trying to avoid disclosure. In that moment of pressure, a plausible-looking app is a tempting solution.
Eliot quotes Sophocles, the ancient Greek playwright, for a warning: "Watch out for danger." The quote is apt. The danger here is not just the watermark itself, but the ecosystem of tools that has grown up around its removal. Every download of a fraudulent app is a small victory for the scammers. Every piece of malware installed is a real cost to the user.
The article also notes that evildoers are setting up fake removal apps to infect computers with viruses. This is not a hypothetical risk. It is an active campaign. The apps are designed to look legitimate, with professional websites, fake reviews, and convincing screenshots. They promise to remove Claude's watermark in seconds. They deliver a virus.
The Path Forward
There is no easy solution. Anthropic is working on detection tools, but those tools will not help users who want to remove watermarks. They will help users and third parties identify watermarked text, which is the opposite of what removal app customers want. The two goals are in direct tension.
The article suggests that a legitimate removal app should have its claims verified by an independent third party. That is a reasonable standard, but it is unlikely to be met soon. The market is too young, and the technology is too new. There is no established testing body for watermark removal tools. There is no certification process. There is only a flood of apps, most of them worthless or worse.
The statistical nature of the watermark makes it inherently difficult to remove without degrading the text. A user who wants to strip the watermark must either rewrite the text substantially or find a tool that can do so automatically. The former is time-consuming. The latter is dangerous. There is no middle ground.
Eliot's analysis suggests that the problem will get "abundantly worse" as more AI makers adopt watermarking. That is not a prediction of doom so much as a statement of arithmetic. More watermarks mean more demand for removal. More demand means more scams. More scams mean more victims. The cycle feeds itself.
For now, the best advice is to avoid the removal apps entirely. The watermark is invisible to humans, and in most cases, it will never be detected. The risk of downloading a malicious app far outweighs the risk of leaving the watermark in place. A user who tries to remove the watermark is taking a gamble with their device, their data, and potentially their reputation. The odds are not in their favor.
The article was published on Aug 16, 2026, just five days after Anthropic's announcement. In that short time, the removal app market has already become a minefield. The situation is likely to get worse before it gets better. As Eliot notes, the problem is "currently under the radar." But the radar is warming up.
The 1.5 billion weekly users of popular LLMs and generative AI represent a vast target population. Even a small fraction of them seeking removal tools would be a massive market. Scammers know this. They are already moving in. The gold-divining sticks of the 19th century have found their 21st-century equivalent, and they are being sold to anyone with a text file and a fear of being caught.
Anthropic's watermarking announcement was a step toward accountability in AI-generated content. It was also, unintentionally, a catalyst for a new wave of cybercrime. The company's promise to build detection tools is commendable, but it does nothing to help the users who are now being targeted by fraudulent removal apps. Those users are on their own.
The article's advice is simple: be wary, be skeptical, be cautious. Do not download random apps that promise to remove watermarks. Do not trust reviews. Do not assume that a professional-looking website means a legitimate product. The scammers are counting on that assumption.
Sophocles wrote "Watch out for danger" centuries ago. The warning still applies. The danger is not the watermark. The danger is the app that promises to remove it.

