Music Streaming Loophole Lets Anyone Upload AI Tracks to Real Artists
A 404 Media investigation reveals how scammers exploit digital distribution systems to hijack verified Spotify pages with AI-generated content.
A fundamental vulnerability in how music reaches streaming platforms allows anyone to upload AI-generated tracks to verified artist pages—including those of Taylor Swift, deceased musicians, and independent bands—with virtually no verification.
404 Media demonstrated the exploit by successfully uploading an AI-generated song to Brooklyn punk band Lathe of Heaven's official Spotify, Apple Music, Tidal, and Amazon Music pages without the band's knowledge or consent. The process required only a $3.75 monthly subscription to digital distributor Distrokid and took less than 24 hours from upload to publication.
How the exploit works
Digital music distributors serve as intermediaries between artists and streaming platforms. Musicians upload their content once to a distributor, which then pushes it to dozens of streaming services simultaneously. This consolidation creates efficiency—and a critical security gap.
When 404 Media entered "Lathe of Heaven" as the artist name during upload, Distrokid automatically matched it to the band's existing verified pages across platforms. The system asked the reporter to confirm this was their band, then requested standard metadata like composer and producer names. After checking boxes claiming authorization to distribute the music and confirming no unauthorized use of another artist's name, the AI-generated track went live across 24 platforms within a day.
Neither the distributor nor any streaming platform verified the claims. The song appeared indistinguishable from legitimate releases, with any streaming royalties flowing to the uploader rather than the actual band.
"The fact that you were able to do that is insane," Lathe of Heaven vocalist Gage Allison told 404 Media. "The only thing smaller musicians like us have at the end of the day is recognition for the results of our work."
Scale of the problem
Musical duo Odette Child has documented over 300 instances of AI-generated songs fraudulently attributed to real artists, from major stars to obscure Broadway performers to deceased jazz musicians. In some cases, album covers for dead Black musicians feature AI-generated images of white artists. After Odette Child reported their findings to Spotify, the platform thanked them but took no action.
Streaming platforms receive over 100,000 new tracks daily, according to Deezer. The volume makes manual review impractical, while automated AI detection remains unreliable and prone to false positives that can harm legitimate artists.
Why it matters
This loophole represents more than a technical vulnerability—it threatens the fundamental attribution system that connects artists to their work and their income. Scammers can monetize another artist's reputation and fanbase while delivering low-quality content that damages that artist's brand. Lesser-known artists and deceased musicians whose pages aren't actively monitored face the highest risk, though even Taylor Swift's verified pages have been compromised.
The issue predates generative AI but has accelerated dramatically as AI music tools like Udio make content creation trivial. Spotify told 404 Media it's investing in detection and has introduced Artist Profile Protection, which lets artists review releases before publication. Amazon said its systems removed tens of millions of fraudulent tracks last year. But the core vulnerability—the ability to claim another artist's identity during upload with no verification—remains unaddressed.
The details were first reported by Emanuel Maiberg at 404 Media, who conducted the demonstration with Lathe of Heaven's cooperation to expose the security gap.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call

