Meta’s Kromix ‘Nudify’ Ads: What Happened and What the Case Proves
The important fact is not that a prohibited ad was eventually removed. It is that a campaign reportedly passed several layers of review long enough to reach users, while the harmful capability sat one click away.
The short answer: the ads were removed, but only after outside scrutiny
On 18 August 2026, WIRED reported that Facebook and Instagram had carried advertisements for Kromix, an app presented as an AI image-styling tool but described in the investigation as offering paid users sexual face-swap and image-generation scenarios involving real people. One advertisement reportedly used the likeness of a prominent female US politician before cutting to explicit synthetic footage.
According to Meta information cited by WIRED, the advertiser account ran 32 ads for periods ranging from five to 46 hours. The campaign was targeted only at male users. Meta removed the ads after the publication asked about them and said it was investigating how they bypassed its systems. Apple also removed Kromix from the App Store after being contacted, saying the app appeared to have added prohibited content and features after its initial review.
Those are the verified actions reported by the publication: ads ran, the companies were contacted, and the ads and app were removed. The report does not establish how many people used Kromix, whether any particular person’s photograph was uploaded, how much revenue the campaign produced, or whether a named individual suffered a completed offence. Those questions remain open and should not be filled with assumptions.
A concise chronology of the Kromix case
Researchers associated with the Tech Transparency Project identified the campaign while examining advertisements for generative sexual-content tools. The ads were visible through Meta’s advertising system and linked users to an app that appeared in Apple’s App Store. That combination gave the offer two separate signals of legitimacy: a paid placement inside familiar social platforms and distribution through a mainstream app marketplace.
WIRED reviewed the ads and the app before seeking comment. The report says some advertisements used ordinary-looking cover material while the destination offered far more harmful functions. Meta told the publication that it prohibits this content, that no system is perfect, and that it was investigating the bypass. Apple said nudification and pornography-generation apps breach its rules and removed Kromix after concluding that prohibited functionality appeared to have been added after review.
The sequence matters. This was not a platform announcement of a newly detected campaign. It was an outside investigation followed by enforcement. Removal reduced continued exposure, but it does not show that preventive review worked as intended. Nor does the incident prove that every comparable advertisement remains online; it demonstrates a specific, documented failure mode.
How an ad can look acceptable while the destination is not
A moderation system normally sees several surfaces: the image or video in the advert, its caption, the advertiser account, the landing page and sometimes the behavior of the destination after installation. An operator trying to evade review can keep the first surface relatively benign, use vague phrases such as ‘AI image styler’, and reveal the prohibited capability only after a click, payment, login or app update.
That creates a classification gap. The ad may contain no explicit nudity even though it sells a tool designed to produce sexualised synthetic media. A marketplace review can face a similar gap if the submitted version behaves differently from the version or server-controlled features available later. Apple’s response in this case points to that possibility, but it does not disclose the app’s complete update history or establish who made each change.
This is why visual moderation alone is insufficient for high-risk generative services. Review needs to connect the creative, advertiser identity, destination, payment path, app developer and post-install behavior. Repeated domains, near-identical captions and reused developer infrastructure can be more revealing than any single ad frame.
- Benign cover creative can conceal a prohibited downstream service
- Server-side features may change without an obvious store update
- Short campaigns can finish before a complaint is reviewed
- New accounts, domains and wording can weaken simple blocklists
What the incident says about platform accountability
Meta publicly states that it bans promotion of nudify apps and has developed technology intended to detect those ads even when the creative itself contains no nudity. It has also described legal action and information-sharing designed to disrupt repeat operators. The Kromix report therefore tests an existing enforcement claim rather than exposing an absence of policy.
Our editorial view is that the useful accountability metric is not the number of ads removed in isolation. Platforms should measure how many violating campaigns were stopped before delivery, how long evading campaigns remained active, how many users saw or clicked them, whether linked apps and payment accounts were disrupted, and whether the same operator returned under another identity. A large removal number can mean strong enforcement, high abuse volume, or both.
The case also shows the limits of treating an app-store listing as an independent safety certificate. Store review and advertising review are separate controls with different evidence. When both are bypassed, each can make the other appear more trustworthy. A user sees a familiar social platform and a familiar store badge, but neither confirms consent from the person whose likeness may be used.
What is known, and what cannot yet be concluded
The strongest public evidence is WIRED’s direct review of the campaign and app, together with on-record responses attributed to Meta and Apple. Meta’s own earlier policy statement independently confirms that advertisements for nudify services are prohibited and that the company has built specialized detection measures. Apple’s published review rules likewise prohibit overtly sexual or pornographic material and misleading app behavior.
There is not yet a public regulator finding, court judgment or complete technical report establishing the operator’s identity, the total audience, the number of generated files or harm to specific victims. The absence of those figures should not minimise the risk, but it does constrain responsible reporting. ‘Available to create’ is not the same fact as ‘used to create’, and an investigation is not a conviction.
It is also too early to claim that one moderation technology caused the failure. Automated review, human review, advertiser verification and app-store controls all form part of the path. Without internal logs, an outsider cannot reliably attribute the bypass to a particular model, threshold or staffing decision.
How to document and report a similar advertisement safely
Do not upload somebody’s photograph to test whether a suspicious tool works. That can create another copy of sensitive material, expose the image to an unknown operator and compound the privacy harm. Verification should begin with the advertisement and its infrastructure, not with generating an example victim.
Capture the full ad screen, including the account name, platform, date, ‘sponsored’ label and visible destination. Save the app-store listing, developer name, privacy-policy address and purchase screen without installing or paying. Use the platform’s ad library where available to record campaign variations and active dates. Keep the original URLs and timestamps; a cropped image without context is much harder for investigators to use.
Report the advertisement and app through their official abuse channels, choosing the category for non-consensual intimate imagery, sexual exploitation or deceptive products where available. If the content involves a child, do not download, forward or attach the imagery to an ordinary email. Use the relevant national reporting service or NCMEC’s Take It Down resources. Adults facing intimate-image abuse can use established victim-support and hashing services such as StopNCII.org, alongside local law-enforcement or specialist support where appropriate.
- Preserve account, advertiser, developer, domain and timestamp details
- Do not create a test deepfake or redistribute suspected intimate media
- Report the ad and the destination app as separate items
- Keep confirmation numbers and note when the material was removed
- Treat a removal as containment, not proof that every copy is gone
Continue with independent verification.
Check a suspicious imagePrimary reading
We use original standards, regulators, public institutions and research papers wherever possible. Sources were last checked on 18 August 2026.