Ghost Font: Anti-AI Text That May Not Stay Anti-AI
11 Jul 2026
A font designed to be unreadable by machines
A new project called Ghost Font claims to solve a problem that has vexed designers for over a decade: how to render text that humans can read but AI models cannot. The font encodes messages using motion, video, background-matching dots, and deliberate decoys — a departure from earlier static anti-OCR approaches.
According to the report, Ghost Font's dots are colored to match the background, meaning a single screenshot reveals no readable text at all. The message only emerges through motion across a video sequence, and every generated video includes a decoy message specifically designed to mislead AI models attempting to decode it.
The ZXX precedent
This isn't the first attempt at building anti-machine-reading text. In 2013, designer Sang Mun released ZXX, a font intended to be human-readable but resistant to optical character recognition (OCR) software. The report notes that modern AI models can reportedly now read ZXX text with ease — a reminder that anti-OCR designs can become obsolete as AI capabilities improve.
Ghost Font is positioned as the next-generation alternative, built specifically to resist not just OCR but modern multimodal AI systems.
Testing against AI models
The creator reportedly tested Ghost Font videos against AI models identified in the report as Claude Fable and GPT Sol 5.6 Ultra. In one demonstration, a system referred to as ChatGPT 5.5 Pro was shown a Ghost Font screenshot and spent 19 minutes analyzing it before ultimately hallucinating a message that didn't exist.
It's worth flagging: these model names are not identified in the report as verified, publicly known AI systems, which raises questions about the exact test conditions. The report also provides no information on sample size or methodology behind these claims, so the results should be treated as preliminary rather than conclusive.
Cracks in the armor?
Despite the encouraging early results, the report highlights two notable risks:
- AI is already catching up. Modern AI models reportedly can already read ZXX text, the very font Ghost Font aims to improve upon — suggesting a pattern where anti-AI text techniques have a limited shelf life.
- Determined attackers may have an edge. A dedicated agent equipped with a local code execution environment may be able to analyze the dot motion in Ghost Font and decode the message, suggesting the protection may not hold up against sophisticated, motivated adversaries.
Sources in the report leave open several questions: there's no release date given for Ghost Font itself, no explanation of exactly how human readers are supposed to decode the motion-based message despite the noise and decoys, and no technical detail on how long or difficult it would be for a dedicated agent to break it.
What's next
The creator has announced plans to open-source the Ghost Font video generation code, though no timeline was given for this release.
Potential opportunities
The report points to a couple of directions where this technology could find practical use:
- CAPTCHA systems. Ghost Font's motion-based obfuscation could potentially be incorporated into bot-detection tools, making them harder for automated systems to solve while remaining accessible to humans.
- AI benchmarking. The font might serve as a useful benchmark for tracking AI progress in visual perception and video-analysis tasks over time.
Why founders should care
For founders building in AI security, bot detection, or visual verification, Ghost Font is a data point worth watching rather than a proven solution to adopt today. The precedent set by ZXX suggests that any technique designed to block AI vision may have a limited effective lifespan — what works against today's models could plausibly be defeated within a few product cycles, especially as multimodal AI systems continue to improve rapidly.
Founders evaluating CAPTCHA or anti-bot products should treat claims like these with healthy skepticism until independently verified: the AI models referenced in testing are not confirmed as real, publicly known systems, and no methodology or sample size is disclosed. That said, the planned open-source release of the video generation code could offer a low-cost opportunity for technical teams to experiment directly once it becomes available — potentially informing internal R&D on obfuscation techniques or AI-robustness benchmarking without requiring upfront investment. Until then, it's reasonable to view Ghost Font's anti-AI claims as promising but unproven, with real risk that determined technical attackers could decode the underlying motion patterns given enough time and computing resources.