GO
Overall Score
ClaimJury
1. One-liner
Tells a merchant whether that photo of a smashed product was taken by a camera or generated by ChatGPT.
2. Trend signal — why now?
For twenty years, a photo of a broken product was the proof. A customer said “it arrived cracked,” attached a JPEG, and the merchant refunded. That entire assumption died in about six months.
In March 2026 PYMNTS documented a wave of shoppers submitting AI-generated images of damaged goods to claim refunds on merchandise that arrived perfectly intact. Modern Retail ran the same story with named brands. Boll & Branch’s CEO Scott Tannen described the fakes his team caught: “They were just so blatantly AI that I couldn’t believe it.” His team only killed the claim because they asked the “customer” to show the damage on a FaceTime call — and the person vanished. That is not a detection system. That is luck plus a phone call.
The volume curve is what matters. Yofi’s CEO Jordan Shamir: “We went from seeing it onesie-twosie to seeing it daily across our merchants.” Ravelin’s writeup spells out the attack: upload the product photo you already have to ChatGPT or Gemini, ask it to add a tear or a crack, submit. It takes ninety seconds and no skill. 65% of consumers now say AI has made it easier to falsely claim refunds online.
Meanwhile the money got bigger and the clock got tighter. NRF puts fraudulent returns at roughly 9% of all returns — north of $100B a year. Visa’s VAMP thresholds tightened on 1 April 2026, dropping the merchant “excessive” ratio from 2.2% to 1.5% and attaching an $8-per-dispute fee in the excessive tier. So merchants are being squeezed from both ends: more fake evidence coming in, and a harsher penalty for the chargebacks that result.
And the tooling that exists doesn’t cover this. Signifyd, Loop, and NoFraud (which swallowed Yofi in October 2025) score the customer — telemetry, return history, device fingerprint, behavioral graph. Siena Vision reads the damage — it identifies the product and assesses severity. Nobody rules on the photo itself. Claimlane, which sells warranty-claim image recognition, says the quiet part in public: “With so many images to sort through in warranty claims, it’s nearly impossible to catch duplicates, internet-sourced images, or AI-generated photos.”
That’s the hole. A first-time customer with a clean device fingerprint and a plausible-looking crack sails straight through every one of those systems.
Provenance:
- Signal 1 (demand): Named DTC brands hit by AI-generated damage-claim photos; merchant quotes on frequency and detection-by-luck — https://www.modernretail.co/technology/from-boll-branch-to-bogg-brands-are-battling-a-surge-of-ai-driven-return-fraud/ — 2026-03-02. Corroborated by Amazon Seller Central sellers reporting the same attack — https://sellercentral.amazon.com/seller-forums/discussions/t/c5f5d635-3b89-4505-9537-f30be0a9d250
- Signal 2 (feasibility): Multi-layer image-authenticity stack (C2PA Content Credentials + SynthID + metadata forensics + trained classifiers) matured into a usable production pattern in 2026, with published accuracy ceilings per layer — https://www.eyesift.com/ai-image-detection-2026-c2pa-content-credentials-synthid-watermarks-diffusion-fingerprints-deepfake/ — 2026
- Signal 3 (economic): NRF puts return fraud >$100B/yr; NoFraud acquired Yofi (Oct 2025) to chase it; Visa VAMP tightened to a 1.5% ratio with $8/dispute fees on 1 April 2026, raising the cost of every fake-photo refund that becomes a chargeback — https://www.nofraud.com/press-release/nofraud-yofi-ai-the-first-unified-fraud-abuse-prevention-platform/ and https://www.chargeflow.io/blog/visa-chargeback-dispute-rules-fees-time-limit Category: Tech-unlock
3. The opportunity
The incumbents are all looking at the wrong object.
Signifyd, NoFraud/Yofi, and Loop are behavioral systems. They ask “is this person likely to be a fraudster?” — device, IP, order history, return velocity, graph links to known bad actors. They are good at that. Signifyd reportedly catches 89% of return fraud in comparison testing; Loop 61%. But every one of those numbers is about serial abusers, wardrobers, and known-bad networks.
The AI-photo attacker breaks the model because the attacker is a real customer with a real order. She bought the duvet. She received the duvet. She kept the duvet. Then she spent ninety seconds in Gemini adding a tear and asked for a refund without return. Her device is clean, her IP is residential, her purchase history is spotless, and this is her first return. Behavioral scoring says: approve. It’s the evidence that’s fake, not the identity.
Siena Vision, the other side of the market, looks at the image — but to grade the damage, not to question whether the image is a photograph. It cross-references warranty terms and severity. It is a very good tool that fully trusts its input.
So there is a specific, nameable gap: nobody adjudicates the artifact. And the obvious naive product — “an AI detector that says FAKE” — is a trap I want to be explicit about, because it’s why this hasn’t been built well yet. State-of-the-art synthetic-image detectors run 70–90% true-positive against generators they were trained on, drop to 50–60% against the next generation, and throw 5–15% false positives on genuine photographs. Ship that raw verdict to a CX rep and you will, on a predictable schedule, accuse a real customer whose real product really broke. That’s a refund you should have paid, a public review you can’t delete, and possibly a regulator’s attention.
The product that works is not a detector. It’s a jury: it stacks the independent signals (C2PA manifest present or stripped, SynthID watermark, EXIF/device coherence, generator-fingerprint classifier, reverse-image match against the merchant’s own product catalog and the open web, and cross-claim reuse of the same image across merchants), weighs them, and returns one of three verdicts — clear, contest, or escalate — with the specific reasons attached. Then, and this is the part that pays, it assembles the evidence packet the merchant needs downstream: the one that gets attached to the chargeback representment when she escalates to her bank.
Nobody in this market is doing forensics-to-representment as one motion. That’s the wedge.
4. Target market
Primary customer: Head of CX or Head of Ops at a DTC brand doing $3M–$50M/yr on Shopify, in a high-AOV, high-damage-plausibility category — furniture, home textiles, glassware, ceramics, appliances, instruments, high-end apparel. Typically 2–15 people on the support team. US and EU first.
Why they buy: In their words. Boll & Branch’s CEO on the fakes: “They were just so blatantly AI that I couldn’t believe it.” Yofi’s CEO on the trajectory: “We went from seeing it onesie-twosie to seeing it daily across our merchants.” Bogg’s CX manager, hedging but watching: “It’s not all that frequent, thankfully, but it’s definitely something we’ll be keeping an eye on.” And from the Amazon seller forums, the raw version: “We have a customer who is using AI to generate fake images of our product to show damage in the attempt to get a free product and abuse us.” Another seller, on what happens when you fight back without evidence: “The scammer reported our account and we got a policy warning. This is insane lol. We are out the money and our account is at risk.”
That last quote is the whole business case. Merchants aren’t just losing the refund — they’re losing the argument, because they have nothing to argue with. A CX rep’s gut feeling is not evidence. A forensic verdict with six cited signals is.
Why this customer and not the enterprise: Walmart and Wayfair will build this in-house or buy it from Accertify. The $3M–$50M brand has a five-person CX team, a Shopify store, a Gorgias inbox, and zero forensic capability. They’re the ones eating it.
Rough TAM reasoning: Roughly 87% of Shopify merchants install apps, and a $5–20M brand spends $5K–$15K/mo on apps total. The addressable slice is the high-damage-claim categories. Home goods run ~19% return rates, apparel ~25%. If 40–60K Shopify/Shopify-Plus brands sit in the $3M–$50M band globally and even a third are in damage-plausible categories, that’s a 15–20K-merchant target list. At $299/mo blended, capturing 2% is ~$1.2M ARR. This does not need to be a big market to be a good business — which is exactly the point.
Why now for them: The attack didn’t exist eighteen months ago. Their refund policy — “send a photo and we’ll make it right” — was written in a world where photos were evidence. That policy is now a public API for free products, and they know it.
5. Product sketch (MVP)
- Verdict on every claim photo. Drop-in for the returns/claims flow: every customer-submitted image gets a clear / contest / escalate verdict in under two seconds, never a bare “fake” label.
- The reasons, in plain English. “No C2PA manifest. SynthID watermark detected. EXIF shows no capture device. Diffusion-fingerprint classifier: 0.91.” A CX rep with no forensics training can read it and act.
- Catalog cross-check. Reverse-matches the submitted image against the merchant’s own product photography and the open web — because the laziest fraud is not generated at all, it’s the merchant’s own PDP shot with damage painted on, or a stock photo lifted from Google.
- Cross-merchant image reuse ledger. The same “cracked vase” image submitted to four different brands in the network gets flagged instantly. This is the asset that compounds.
- Evidence packet, one click. For any contested claim, generates the representment-ready PDF: the forensic verdict, the signal breakdown, the capture-provenance analysis, the order linkage — formatted for the merchant’s PSP dispute flow.
- Verified-capture link (the honest path). When a claim is contested, the merchant sends the customer a one-tap link that captures the photo in-session with device attestation and a signed timestamp. A real customer with a real broken vase takes ten seconds and gets a fast refund. A fraudster does not click it. This converts the false-positive problem into a customer-friendly step.
- Policy autopilot. Set thresholds — auto-approve clears under $X, route contests to a human, escalate the rest — so the CX team’s queue actually shrinks instead of growing.
- Gorgias / Zendesk / Loop / Shopify integration. The verdict shows up where the rep already works. Nobody logs into a new tool.
6. AI angle — what’s load-bearing
AI is both the weapon and the shield here, and if you take it out, the product is nothing.
The attack is purely generative — there is no version of this fraud without diffusion models. So the product’s entire reason to exist is downstream of an AI capability that became free and frictionless in the last year.
The defense is a multi-model ensemble doing genuine forensic work: a generator-fingerprint classifier, a vision model doing catalog and open-web matching, a model reasoning over EXIF/C2PA/metadata coherence, and a perceptual-hash system detecting cross-merchant reuse. Then an LLM does the last, most important job — turning six numeric signals into a paragraph a CX rep can defend to a customer and a bank.
Strip the AI out and you have… a person squinting at a JPEG. Which is exactly the status quo that’s failing, and the reason Boll & Branch had to resort to a FaceTime call.
The honest caveat, stated up front because it drives the whole product design: no single detector is reliable enough to ship as a verdict. 70–90% TPR on trained generators, 50–60% on the next one, 5–15% FPR on real photos. That’s why this is an ensemble that outputs a contest state and a verified-recapture path rather than a binary accusation. The AI is load-bearing; the AI is also not trusted alone. Both things are true and the product architecture has to say so.
7. Localization angle (if any)
N/A — this is a global play. The attack is generator-driven and the generators are the same everywhere; the merchants are on the same three platforms (Shopify, WooCommerce, BigCommerce) and the same two helpdesks (Gorgias, Zendesk). US and EU first purely because that’s where the AOVs and the chargeback penalties are highest, so the ROI math closes fastest. There is a real EU wrinkle worth noting — GDPR means the cross-merchant image ledger must store perceptual hashes, not images, and the customer-facing verdict language has to avoid automated-decision traps under Art. 22. That’s a constraint on how you build it, not a localization wedge.
8. Business model — path to $1M–$5M ARR
- Pricing: Tiered by claim volume, not order volume — this is a deliberate contrast to Signifyd, which takes a percentage of approved order value and therefore feels like a tax. $99/mo (up to 100 claim images), $299/mo (up to 500), $799/mo (up to 2,000), custom above. Evidence-packet generation included; the verified-capture links metered at high volume.
- ACV: ~$3,600 blended (the $299 tier is the center of gravity for a $10M brand).
- Rough math to $1M ARR: 280 merchants × $299/mo × 12 ≈ $1.0M. That’s under 2% of the target list.
- Rough math to $5M ARR: ~1,000 merchants at a $415 blended ACV/mo — meaning meaningful upsell into the $799 tier plus a second product line. The obvious one: the same forensic engine sold to carriers and 3PLs adjudicating shipping-damage claims, and to warranty administrators, both of which have the identical “is this photo real” problem with bigger budgets. That’s where the fifth million comes from, not from squeezing more DTC brands.
- Expansion path: Claim volume grows with the merchant. Then seats for larger CX teams. Then the cross-merchant ledger becomes a paid data product in its own right — a “this image has been submitted to 6 merchants” lookup that anyone in returns wants.
- Gross margin reality check: Inference is the COGS. An ensemble pass on one image runs cents, not dollars, and claim images are a tiny fraction of order volume. At the $299 tier and 500 images, COGS is comfortably under 10%. This is a healthy-margin SaaS, not an AI-wrapper burning cash on tokens.
9. Go-to-market wedge — first 100 customers
This is a market where the customers have already publicly identified themselves as victims. That is rare and I intend to abuse it.
- Mine the seller forums and DM the complainers. The Amazon Seller Central and eBay community threads are full of merchants describing this exact attack in detail, by name, with dates. Same on r/ecommerce and r/shopify. Pull every thread from the last 9 months, build a list of 300–500 merchants who have posted about fake damage photos or fraudulent damage claims, and reach out with a free forensic audit of the specific images they got scammed with. Not a demo — an answer to the thing they’re angry about. Expect a very high reply rate, because you’re not pitching, you’re solving the open loop.
- The reverse-audit cold open. For 200 target DTC brands in high-damage categories, buy one product, request a damage refund with a deliberately AI-generated photo you made yourself, and see if it clears. When it does — and it will, most of the time — that’s the email: “We refunded ourselves $340 of your product with a photo we made in 90 seconds. Here’s the receipt. Want to see how many other people are doing this to you?” It’s aggressive, it’s ethical (you’re buying the product and disclosing immediately), and it converts, because it’s not a claim about their vulnerability — it’s a demonstration of it. This is the single highest-leverage move in the plan.
- Ride the helpdesk ecosystems. Gorgias and Zendesk app marketplaces, plus Loop’s integration directory. These are the surfaces the CX lead already browses. Shopify App Store listing under fraud/security, which is a real discovery channel — fraud apps there start around $9/mo and merchants shop it actively.
- Own the search term before anyone else does. “Is this photo AI generated” + “customer sent fake damage photo” + “return fraud AI images” — this is a brand-new query cluster with essentially no authoritative content behind it. Publish the quarterly AI Return Fraud Index off the cross-merchant ledger: which categories get hit, which generators are being used, what the fakes look like this month. That’s a report journalists will cite (PYMNTS and Modern Retail are already covering this beat and looking for data), and it doubles as the top-of-funnel for the whole business.
- Partner with the returns platforms, don’t fight them. Loop, Returnly, AfterShip all have the photo-upload step and none of them adjudicate the photo. Be the forensics layer inside their flow rather than a competing returns app. One integration deal here delivers more merchants than six months of cold outreach.
10. Build complexity — justification
Medium. Nearly every forensic component is off-the-shelf or near it: C2PA verification libraries are open, SynthID detection is exposed by Google, EXIF/metadata parsing is trivial, perceptual hashing is a solved problem, and reverse-image matching is a vector-DB job. Commercial detector APIs (TruthScan and peers) can be licensed for the classifier layer on day one rather than trained from scratch — which means v1 does not require a research effort.
The genuinely custom work is three things: (1) the ensemble scoring layer that turns noisy per-signal outputs into a calibrated three-state verdict without over-accusing — this is the product, and it needs real evaluation discipline; (2) the verified-capture flow with device attestation, which is fiddly cross-platform mobile work; (3) the integrations into Gorgias/Zendesk/Loop/Shopify, which are individually easy and collectively a slog.
Two people, 12–16 weeks to a v1 that a design partner can run live. The hard part isn’t the code, it’s assembling an honest evaluation set of real-vs-generated damage photos so you can prove your false-positive rate rather than guess it. Budget four weeks just for that.
11. Gating checklist
| Gate | Pass? | Note |
|---|---|---|
| Legal in target market | ✅ | Merchants have an existing right to evaluate claim evidence. EU: must store hashes not images for the cross-merchant ledger, and must keep a human in the loop on adverse decisions to stay clear of GDPR Art. 22. Design constraint, not a blocker. |
| Ethical — no harm / dark patterns | ✅ | With one hard rule that must be enforced in the product: never surface a bare “fraud” verdict. Three-state output, cited reasons, human-in-the-loop on contest, and a friction-light recapture path for honest customers. Get this wrong and you’re a machine for falsely accusing real people. |
| Market exists (evidence above) | ✅ | Named brands on record, seller forums full of it, NRF sizing, incumbent M&A in the adjacent space. |
| 1–5 person team can build this | ✅ | Two people, 12–16 weeks. |
| Launchable with <$50K / ₹40L | ✅ | Detector API licensing, inference, and hosting. Well under. |
12. Feasibility score
| Axis | Weight | Score | Notes |
|---|---|---|---|
| Problem intensity | 20 | 16/20 | Real money, felt now, and rising fast — Yofi went from “onesie-twosie to daily.” Held below 17 because for many merchants the loss is still a nuisance line-item rather than a fire; the ones in high-AOV categories feel it acutely, the rest don’t yet. Urgency is a function of AOV. |
| Demand evidence | 15 | 13/15 | Unusually strong for a brand-new problem: named brands quoted on the record, two trade publications on the beat, seller forums, NRF sizing, and an acquisition (NoFraud/Yofi) in the adjacent category. Short of 14–15 only because nobody is yet paying specifically for image forensics — the spend exists in the neighbouring category, not this exact line. |
| Build feasibility | 15 | 11/15 | Components are off-the-shelf; the ensemble calibration and the eval set are genuine work. 12–16 weeks for two people, not a weekend. |
| Distribution clarity | 15 | 13/15 | The reverse-audit cold open is about as concrete as a GTM motion gets, and the victims have self-identified in public forums. Docked for dependence on app-marketplace and partner channels that are outside your control. |
| Revenue mechanics | 15 | 12/15 | Pricing is benchmarked against a live app-spend market, margins are healthy, and $1M needs only ~280 merchants. Docked because willingness-to-pay for this specific line item is unproven — merchants may expect it bundled free into Loop or Signifyd. That’s the central commercial risk. |
| Time to first revenue | 10 | 8/10 | The reverse-audit demo pre-sells before the product is finished. Realistically 6–10 weeks from launch to first paid, not 4. |
| Defensibility | 10 | 4/10 | This is the weak axis and I won’t dress it up. The detection stack is licensable by anyone. Signifyd, NoFraud, or Loop can bolt an image-forensics tab onto an existing product in a quarter and give it away to keep the account. The only durable asset is the cross-merchant image-reuse ledger, which compounds with every merchant and is worthless on day one. This is a race: get to enough merchants that the ledger is the reason to buy, before an incumbent commoditizes the detector. Execution moat, 12–18 month window. |
| Total | 100 | 77/100 |
13. Qualitative modifiers
Founder-fit tags
technical-heavy · content-heavy
Technical because the ensemble calibration and the false-positive discipline are the entire product — a founder who ships a naive detector will destroy their own customers’ relationships. Content-heavy because the AI Return Fraud Index is not a marketing garnish, it’s the distribution engine and the thing that makes the ledger visible as an asset.
Key assumptions to validate (3–5)
- Assumption: DTC merchants in high-AOV categories will pay $299/mo for image forensics as a standalone line item, rather than waiting for Loop or Signifyd to bundle it. How to test: Run the reverse-audit cold open on 40 brands. Don’t pitch — show them the successful fraudulent refund you performed on their own store, then quote the price. If fewer than 8 of 40 ask about pricing within a week, the willingness-to-pay is bundled-only and the standalone business is dead.
- Assumption: A licensed ensemble can hold false positives on genuine customer photos under ~3% — low enough that “contest” doesn’t routinely insult real customers. How to test: Build the eval set first. Source 500 genuine damage photos from 3 design-partner merchants’ historical claims, generate 500 fakes across 5 current generators, and measure. If FPR won’t go below 5%, the verified-recapture flow has to carry the entire product and the value prop changes shape.
- Assumption: Honest customers will actually complete a verified-capture link rather than churn in annoyance. How to test: Instrument it with one design partner for 60 days. Completion below 70% among customers who do get refunded means the friction is costing more in goodwill than it saves in fraud.
- Assumption: The cross-merchant image ledger produces real hits — i.e. fraudsters reuse images across merchants rather than generating fresh each time. How to test: Once 20 merchants are live, measure the reuse hit rate. If it’s near zero, the only defensible asset in the plan evaporates and defensibility drops from 4 to ~2.
Risk flags
- Incumbent bundling (the big one): Signifyd, NoFraud/Yofi, and Loop can each add an image-authenticity signal to an existing product and bundle it at zero marginal price to protect the account. They have the distribution and the merchant relationship; you have a better answer to one narrow question. This is a land-grab against a clock.
- Detector arms race: Every new generation of image model degrades the classifier layer — 70–90% accuracy on trained generators collapses to 50–60% on the next. This is a permanent treadmill, and it’s an operating cost forever, not a one-time build. Products that pretend otherwise get quietly worse over time.
- False-accusation blowback: A single viral “this brand called me a fraud and their AI was wrong” post is worse for a customer than the fraud it prevented. The three-state verdict and human-in-the-loop are not nice-to-haves — they are the license to operate.
- Platform dependency: Meaningful reliance on Shopify/Gorgias/Loop marketplaces for distribution, and on third-party detector APIs for a core signal. Both are rentable, neither is owned.
14. Structured verdict
Score: 77/100
Verdict: GO
Confidence: Medium
Best-fit builder: Technical founder with ML evaluation discipline, paired with someone
who can write and get cited. Prior e-commerce/fraud exposure is a real
advantage but not a gate.
Time to revenue: 6–10 weeks from launch (pre-sellable via the reverse-audit demo before
v1 is complete)
Capital to launch: $15–25K (detector API licensing, inference, eval-set construction)
Top 3 assumptions to validate first:
1. Standalone willingness-to-pay — reverse-audit cold open on 40 brands; need ≥8 pricing
conversations inside a week
2. False-positive rate under ~3% on real customer photos — build the eval set from 3 design
partners' historical claims before writing the scoring layer
3. Cross-merchant image reuse is real — measure hit rate once 20 merchants are live; this is
the only durable asset in the plan
Kill criteria:
- Abandon if Signifyd, NoFraud, or Loop ships bundled image-authenticity forensics before
you have 50 paying merchants — you will not win a feature war on their distribution
- Abandon if the ensemble's false-positive rate on genuine photos cannot be driven below 5%
after the eval build; at that rate the product harms the customers it's sold to protect
- Abandon if <8 of 40 reverse-audit targets engage on pricing — the spend is bundled-only
15. Next step — 1-week validation sprint
- Day 1–2 — Build the attack, not the defense. Pick 20 DTC brands in high-AOV damage-plausible categories. For each, take their own PDP photography and generate a plausible damage claim image in a current model. Document exactly how long it takes. This is simultaneously your threat assessment, your eval set seed, and your sales collateral. If you can’t produce convincing fakes in under two minutes each, the threat is smaller than reported and you should stop here.
- Day 3–4 — Run the reverse audit for real. On 5 of those brands, actually buy the product, submit the damage claim with your generated photo, and record the outcome. Disclose immediately on approval and pay for the product regardless — you are buying evidence, not stealing goods. The measurable output is a single number: how many of 5 cleared.
- Day 5 — Sell the finding. Email the CX or Ops lead at all 20 brands with the specific result for their store (“we cleared a fraudulent $340 refund on your store in 90 seconds — here’s the image, here’s the transcript, here’s what we paid you back”). Ask for a 15-minute call.
Falsifiable go/no-go: If ≥3 of 5 reverse audits clear a fraudulent refund AND ≥5 of 20 brands take the call within seven days, build it. If the audits mostly get caught, the incumbents’ behavioral scoring is already covering this and there’s no product. If the audits clear but nobody takes the call, the pain is real and the budget isn’t — which is a PASS dressed up as a GO, and the more likely failure mode of the two.
Interested in a detailed proposal?
Get a deep-dive with market research, competitive analysis, and implementation roadmap.
Contact usinfo@startupbasket.ai