is this art AI? art from a relatively new artist account…
Musician Paul Bender details how AI-generated music and security loopholes allowed fraudulent tracks to hijack his Spotify artist profile
- Incident date
- Jun 2025
- Target
- Paul Bender
Three-time-Grammy-nominated musician Paul Bender, bassist for the group Hiatus Kaiyote, recently discovered his solo project, The Sweet Enoughs, was being targeted by a series of unauthorized, low-quality music uploads on Spotify. These tracks, which Bender believes are AI-generated, appeared on his official artist profile without his approval, forcing him and his label to confront a systemic vulnerability in music distribution platforms.
What happened
In March 2025, unauthorized tracks began appearing on The Sweet Enoughs' Spotify profile, characterized by clunky production and generic aesthetics that contrasted sharply with Bender's established exotica-inspired sound. Following the initial upload, three additional tracks—including a distorted mumble rap song and a track described as Eurotrash—surfaced on his page over the following days.
Bender identified that the issue stems from the reliance on digital distributors, which act as go-betweens for artists and Digital Service Providers (DSPs) like Spotify, Apple Music, and Tidal. These distributors currently operate on an honor-based system that lacks robust authentication or security protections. Bender noted that it is possible to create an AI-generated song and upload it to an established artist profile within 10 minutes, requiring no hacking or verification.
This trend is part of a wider problem affecting numerous Australian acts and deceased artists whose profiles have been similarly hijacked. When Bender’s label, Wondercore Island, alerted Spotify, the response was delayed by six weeks, with the platform ultimately attributing the incident to a metadata mapping error. Rather than removing the fraudulent content, Spotify created separate profiles for each of the fake tracks, leaving the platform with five profiles for The Sweet Enoughs. Bender criticized this response as inadequate, arguing that the streaming industry is failing to implement necessary safeguards, such as two-factor authentication, which he believes would resolve the majority of these fraudulent uploads. The incident highlights how the combination of AI generation and a lack of platform security is being exploited to manipulate streaming services, a practice estimated to cost the music industry approximately $US2 billion annually.