The whole point of Cara was to be the one place where photographers and illustrators could post their work without feeding it to a machine. That promise took a serious hit today, when a bad actor reportedly vacuumed up the platform’s entire library — and then bragged about it online.
According to a now-deleted Reddit post, a user going by u/MandarinDawnPoppy994 claimed to have scraped over 12 million works from the service. The post didn’t just describe the deed; it gloated about it, which is roughly the digital equivalent of robbing a bank and posting the security footage yourself.
For anyone unfamiliar, Cara is an image-sharing platform and social network built specifically for artists and creatives to showcase their portfolios. It launched on December 15, 2022, and exists both as a mobile app and a website. Both are free to use. Its entire pitch has always leaned on being a safe space — a corner of the internet explicitly designed so that human-made art wouldn’t be quietly ingested into generative AI training sets.
That’s what makes this sting. Cara didn’t rise as another generic gallery app; it grew precisely because a wave of artists were fed up with their work being harvested without consent. The community migrated there on the understanding that this platform had their back. A mass scrape — if the claims hold up — undercuts that founding principle in one blunt move.
It’s worth being precise about what we know and what we don’t. The 12-million figure comes from the scraper’s own boast, not an independent audit, and the post has since vanished. Whether the data was genuinely exfiltrated at that scale, what it contained, and where it now lives are open questions. But the incident lands as a pointed reminder of an uncomfortable truth:
- No public gallery is truly scrape-proof. If an image can be viewed in a browser, it can, in principle, be copied at scale.
- Policy is not a firewall. A platform can forbid scraping and add technical deterrents, but a determined actor can still ignore the rules.
- Anti-AI branding raises the stakes. The stronger the promise of protection, the harder a breach hits the people who trusted it.
For Cara’s users, the immediate worry is practical: work uploaded to a self-declared sanctuary may now be sitting in someone’s dataset, doing exactly what they joined the platform to avoid. For the wider debate around AI and creative labor, it’s another data point in a long-running fight over consent, ownership, and who gets to decide how art is used.
The takeaway isn’t that Cara failed its mission — building a defensible space for artists is a worthy goal — but that the arms race between creators and scrapers is far from settled. Right now, the scrapers keep finding the gaps, and they’re not shy about saying so.