Google Reported 21 Installs. Your App Saw 1. Fix the Cost to Fake.

Google's dashboard said 21 installs in one day. The app's own admin panel said 1. Nothing was broken. Both numbers were accurate, in the way that a scale is accurate when you step on it holding a suitcase.
The app is Dayzle, a small puzzle game. Its developer ran a two-week Google Ads campaign with the goal set to "installs," then did the thing most of us never do: he went looking for the humans behind the number. Over the whole campaign, Google billed 56 installs. Thirty-three of them behaved identically — one app open, zero seconds on any screen, never seen again. Seven came from countries the campaign wasn't even targeting. Thirteen were actual people, and those thirteen finished 92 puzzles between them.
That story is about mobile advertising, but the pattern is much bigger. It applies to your growth funnel, your inbound sales pipeline, your support queue, and — yes — your hiring process. The lesson isn't that bots exist. It's that any event you choose to optimize for becomes a specification that someone else can manufacture.
What the farm actually did
Here's the mechanism, because it's elegant in a depressing way.
A bot farm wants to get paid for installs. It works out that watching the shortest video in an ad group — without clicking it — registers as engagement. Then it installs the app from a saved copy of the file rather than from the Play Store, because sideloading is faster and the store might notice. It opens the app once, touches nothing, and moves on. Every device reports "Google Play" as the installer anyway, because that field is a claim, not a fact.
Google counts a view followed by an install as a conversion. So the more the farm "installed" the app, the better the campaign looked to the optimizer, which bought more ads for the farm, which installed more. A closed loop that converts budget into noise with no human in the middle.
Notice what the farm never did: it never solved a puzzle. It never had to. The target was a number it could produce for a few cents.
Every optimization goal is a public API
When you tell an ad platform, a growth team, or an AI agent to "maximize installs," you are not describing a business outcome. You are publishing an interface, and you are paying whoever satisfies it most cheaply.
This is why switching from installs to "won a puzzle" changes the economics overnight: an app open is a script, a solved puzzle is a product. Same campaign, same budget, dramatically fewer ways to cheat.
The cost-to-fake ladder
- Near-free to fake: impressions, video views, clicks, page views, app opens, raw form fills. Scripts produce these in bulk for fractions of a cent.
- Cheap: installs, signups, email verifications. Disposable inboxes and bulk SMS services make identity checks a volume business.
- Moderate: activated accounts that complete multi-step onboarding, verified phone numbers, free trials on virtual cards. Faking these takes real per-unit effort.
- Expensive: revenue, retained usage at day 30, a completed job, a solved puzzle, a shipped artifact. Faking these costs more than the payout.
The rule I'd write on the wall: set your optimization goal one or two rungs above where it is today, and make sure the cost of faking it exceeds what the faker earns. If you can't yet measure a higher rung, measure something adjacent — completed actions, not started ones.
The signals that separate a farm from a population
The Dayzle case is instructive because the farm left a fingerprint that was almost embarrassingly clear once someone looked:
- Attribute entropy without behavioral entropy. Twenty devices across 28 phone models and 19 states, all doing exactly the same thing. Real populations are messy in behavior, not just in device metadata. Variety on the outside plus uniformity on the inside is the tell.
- Version mismatch. Most of the devices ran an app version the store had stopped serving days earlier. You cannot download that version from the store. That single field — build number at first launch — was the strongest evidence in the whole dataset.
- Session shape. One open, zero seconds on any screen, no second session. A human who installs a puzzle game does something with it. Even a bored human taps a button.
- Declared source versus actual source. Every device claimed the store installed it. Cross-check the claim against behavior before you trust it.
- Geography against targeting. Seven of 56 installs came from countries the campaign excluded. That's not a rounding error; that's a routing table.
A playbook you can run this quarter
- Keep your own count. The 21-versus-1 gap only existed because the app logged first launches itself. Reconcile platform-reported conversions against your own activation data weekly, and keep the raw export, not the dashboard screenshot.
- Log the fingerprint fields at first launch: install source as declared, build version, country, first-session duration, screens viewed, and whether the user returns on day 2 and day 7. Retain 90 days. Cheap to store, priceless in disputes.
- Define one expensive event per funnel and move the ad platform's goal to it. Yes, this will reduce reported conversions. That's the point.
- Write a farm-shaped query and count the cohort: first session under five seconds, zero screen views, no day-7 return. If it's more than a few percent of a paid channel, you have a problem.
- File invalid traffic reports with numbers, not feelings. A coherent cohort with build versions, timestamps and device lists is a claim a support team can act on. "We think some installs were fake" is not.
- Pause spend while the report is open. This is the part people get wrong. Every extra day of budget trains the optimizer harder on the farm, and you have to unlearn that later.
The same math is arriving in your inbox
Advertising fraud is the mature version of a problem that's now spreading to anything with a queue. Over three days this month, one independent writer received more than a dozen near-identical emails from "AI agents" offering to do his research for about $25 each — sent through Amazon SES, with no unsubscribe link, from a platform that markets itself as a human-agent network. The pitch was insultingly specific: they'd read his 404 page.
Whether the sender is a script or a language model doesn't change the structure. A counterparty is manufacturing the cheapest possible version of "an interested customer" and aiming it at anyone whose job is to reply. If your inbound pipeline, support triage, or vendor intake is gated on a cheap signal — a form fill, a polite email, a resume PDF — expect the same arithmetic to show up there. The defense is identical: gate on work product, not on expressed interest. Ask for the artifact, the paid sample, the reproducible result. Interest is Tier 1. Work is Tier 3.
That has a direct consequence for hiring, where the cost of generating a plausible application has collapsed. If every stage of your funnel is free to enter, you are optimizing for volume and will get it — from the wrong population. Adding one expensive stage (a scoped, paid work sample) filters far better than three cheap screens, and it respects candidates' time in a way that a 90-minute unpaid take-home does not.
The honest trade-off
Moving up the ladder makes your numbers look worse. Cost per acquisition rises, reported conversions drop, and the platform finds fewer events to optimize toward. Your weekly deck gets uglier. That's not the plan failing — that's the measurement getting honest, and it's a real cost you should budget for in both reporting and morale.
Don't overcorrect in the other direction either. The point of the exercise isn't to prove that paid channels are fraud. It's that in that campaign, thirteen real humans finished 92 puzzles — a genuinely excellent engagement signal that was completely invisible in the metric the platform was paid to maximize.
You don't get to keep both the flattering number and the true one. Pick the one that changes what you do next.
Key Takeaways
- Any conversion you optimize for becomes a specification. Installs are cheap to fake; solved puzzles are not.
- Set your goal one or two rungs up the cost-to-fake ladder, and make faking it more expensive than the payout.
- Keep your own activation count. A 21-versus-1 gap is only visible if you're measuring independently.
- Log the fingerprint at first launch: build version, declared install source, session duration, screens viewed, day-7 return.
- Uniform behavior plus diverse device metadata is the signature of a farm, not of a population.
- Report invalid traffic with cohorts and numbers, and pause spend while the report is open.
- Gate inbound pipelines and hiring on work product, not expressed interest. Interest is now free to generate at scale.