Articles — Planted sources

Planted sources

Companies use Reddit to change what AI recommends

Brands seed Reddit with posts written to be scraped, so a thread appearing as a citation tells you the system found it, not that anyone earned your trust.

Someone asks ChatGPT which peptides or supplements suit them. The answer names a brand you have never heard a clinician mention, and the citation is a Reddit thread that reads like an ordinary person asking for cholesterol advice.

That thread might be doing the work how AI builds a shortlist calls corroboration, where enough trusted-looking sources repeat the same name. It might also have been written specifically to be scraped.

The recommendation is built the same way as it is for a watch, a hotel, or a walking tour. The stakes go up when the question is something you swallow.

What the moderators found

Earned

Guides, reviews, and shops repeat the same name because the product really exists in the world.

Planted

Someone wrote a thread to look organic, and it was scraped into the answer as though it were proof.

In June 2026, 404 Media reported that moderators of r/Biohackers (~830,000 members) restricted new posts about peptides and HRT. Companies had been systematically seeding the subreddit with posts built to look organic, so that they would get pulled into ChatGPT and Google AI Search answers.

None of it looked like advertising. The posts chased engagement first and worked the brand in later. One example on the record: someone posting as a normal person asking for cholesterol advice, who edited a link to their own app into the thread once it had picked up comments.

One moderator on that subreddit separated two problems: brands using Reddit to steer shoppers, and posts that could cause physical harm.

So corroboration is not only something you can lack. Someone else can plant it.

What the Cornell paper measured

In May 2026, Tingwei Zhang, Harold Triedman, and Vitaly Shmatikov at Cornell Tech published Deep-Research Agents Can Be Poisoned via User-Generated Content. They named the pattern WARP, for Web Agent Retrieval Poisoning. A deep-research agent is a system that runs several rounds of lookup and then writes a report, rather than answering in one turn. User-generated content means pages written by users, such as Reddit threads, rather than a shop’s own site.

Their tests ran on open systems (STORM, Co-STORM, and OmniThink), inside a sandbox. They did not post on the live web. On Co-STORM, once a poisoned page was retrieved, that system cited it every time in the snippet tests they reported. The attacker-chosen name appeared in the report far less often than the page was cited. Getting cited is still not the same as getting named. Cited versus named is that split: a citation is a source link, and being named is appearing as a pick.

The paper does not prove that ChatGPT, Gemini, or Perplexity can be steered with one comment tomorrow. It shows why a list of options can look well sourced and still be gamed: related questions keep retrieving the same handful of pages, so one edited page can travel further than one reply.

The tactic is for sale

Two firms are on the record selling a version of this. ReachLLM is a Reddit-content agency working for GEO clients, and its founder told Bloomberg that posts have turned up in ChatGPT answers within a day, and that the firm replaces content when Reddit takes posts down. RedRover advertises AI agents that mass-publish across Reddit and blogs to influence Google and ChatGPT.

They are named here to show the tactic is a product you can buy, not as a how-to. The GEO paper measured citations inside answers that already had sources. It did not test whether a chatbot recommends your product, so this page does not turn that paper into a planting checklist.

Some vendors now sell Reddit planting as GEO or AEO. AEO, answer-engine optimization, is the vendor name for trying to get named inside an assistant’s reply. Getting used as a source still is not the same as being named as a pick, and planting a thread does not make the brand in it real, safe, or yours.

The 404 Media report is the source for the moderator account and for naming those two firms. Treat them as examples of a product for sale. This page does not verify each performance claim.

One sourced count, not a blended statistic

Profound reported in June 2025 that Reddit was the most-cited domain in Google AI Overviews and Perplexity, and the second-most-cited in ChatGPT, for August 2024 through June 2025. That is one firm’s crawl of citations. It is not a measure of whether any particular thread was earned, and it is not the same claim as a blog roundup that blends several vendors into “Reddit dominates AI.”

What to do with that

Do not buy planted corroboration. Illustrative example, not a logged test. A shop that wants the Northloop Trail Watch named for “a trail watch under €300, in your country” still needs a clear identity, current facts, and a real footprint. A warmed-up account in a subreddit is not a substitute for any of that.

If a rival is named and you aren’t, one possible reason is that their corroboration was manufactured. That falls under “looked up, not named” in why you were skipped, and rewriting your homepage won’t unwind someone else’s thread.

A Reddit page appearing as a citation tells you the system found it. It doesn’t tell you anyone earned your trust.

Planting threads isn’t even necessary. In 2026, Deana Burke got ChatGPT to name a fake deodorant off a three-page site, with no astroturfing at all: ChatGPT recommended a deodorant that didn’t exist.

Read next if: ChatGPT recommended a deodorant that didn’t exist · Find out why you were skipped before you rewrite the page