Ten seconds of your voice is now enough to clone it: what to do at home
ElevenLabs now clones a voice from ten seconds of audio, the length of a short voice note. What changed, how the scam the Dominican police warned about works, and the family code word the FBI recommends.
On September 28, ElevenLabs, one of the best-known AI voice companies, launched its v4 model. One line in the announcement made me stop: its instant voice clones "can now capture voices with high fidelity using just 10 seconds of audio."
Ten seconds is a short WhatsApp voice note. And if someone in your family sends seven-minute voice notes, there's material to spare.
I'm not writing this to scare anyone. I'm writing it because the defense most of us rely on, "I'd know my own kid's voice," has stopped working. The one that replaces it is free, takes a minute, and gets set up at the dinner table.
What exactly changed
Three things from the announcement matter here:
- Ten seconds. That's the audio an instant clone needs in v4, according to the company. TechCrunch reports the same figure.
- More than 90 languages. The previous version had 70. Spanish is there, and the announcement includes a Spanish sample.
- About 150 milliseconds. That's the median time the Turbo version takes to start speaking. It's built for voice agents that hold live conversations: that speed is for talking back to you, not for reading a recording.
That last one matters more than it looks. Advice on spotting a cloned voice almost always says to listen for odd pauses; the Dominican outlet CDN lists it among the expert tips that accompany its report on the police warning. At 150 milliseconds, that tell is on its way out.
To be fair to ElevenLabs: its safety page says it blocks the cloning of celebrity and other high-risk voices, requires verification for its professional voice cloning, and offers a classifier that tells you whether an audio clip came from its system. I'm not saying scammers use its product.
The point is a different one: ten seconds is now normal for this technology, and not every tool comes with those brakes.
How the scam works
In the Dominican Republic, DICAT, the police department that investigates high-tech crime, has already warned about this. As CDN reported in April, criminals first "obtain audio fragments from their victims, usually through social media, voice notes or videos published online." Then they call or send voice notes pretending to be a relative and "ask for immediate money transfers, taking advantage of fear and emotional pressure."
The FBI described the same pattern in its December 2024 alert on generative AI fraud: short clips in a loved one's voice, "in a crisis situation, asking for immediate financial assistance or demanding a ransom."
Notice the order. The technology supplies the voice, but what makes people fall for it is the rush: an accident, an arrest, a problem you "can't tell anyone about." Nobody verifies anything when they believe their child is in danger. So the defense can't depend on thinking calmly in that moment. It has to be decided beforehand.
The family code word
The FBI recommends it in that same alert: agree on "a secret word or phrase with your family to verify their identity." It's the cheapest defense there is, and this is how I'd set it up:
- Pick something nobody can guess. No pet names, dates, nicknames or sports teams: all of that is on social media. A ridiculous phrase that only makes sense to you works better.
- Say it in person. Not by text, and not by voice note, which is exactly the channel you're protecting.
- Make the rule explicit. If someone in the family asks for money urgently by phone or voice note, you ask for the word. No word, no transfer, even if the voice is identical.
- Practice with the older relatives. They're the ones who get called most, and the least likely to remember to ask if they never have. One dry run over dinner beats the best explanation.
- Change it once it's used. Once you've said it on a call, it has left the table.
Hang up and call them yourself
The second rule comes from the same FBI advice: hang up and call them directly. If "your cousin" texts from a new number because "my phone broke," don't answer that number. Call the old one, or ask someone else in the family where they are.
It sounds obvious read calmly like this. But the scam is built so that you don't hang up: "don't hang up," "I don't have much time," "don't tell Mom." If you hear that, it's one more reason to hang up.
What you can limit, and what you can't
The FBI also recommends limiting the audio and video of you that's public, and making your accounts private.
It's worth doing, but don't fool yourself. If you talk in public videos, send voice notes, or someone calls and keeps you talking for thirty seconds, ten seconds of your voice already exist. A private profile raises the cost for someone harvesting voices in bulk. Against someone who picked you, it's not enough.
That's why the code word comes first: it doesn't depend on your voice being a secret.
If it already happened
- Don't delete anything. Keep the voice notes, the number, the chats and the transfer receipts.
- Call your bank right away. The sooner you report the transfer, the better the chance of stopping it.
- File a report. In the Dominican Republic, the National Police has an online portal, denuncias.policia.gob.do. In the United States, the FBI takes reports at ic3.gov.
- Warn the family. If they used someone's voice, they'll most likely try it on more people.
What I take from this
When I wrote about RD Inteligente, the Dominican government's free AI course, I said it wasn't for my developer friends but for the people who could lose their savings to a cloned voice on the phone. This week that got ten seconds truer.
Send this to the family group chat. And the word: say it in person.
Sources: ElevenLabs: Eleven v4, September 28, 2026 · TechCrunch, September 28, 2026 · ElevenLabs: Safety · CDN: DICAT's warning on voice cloning, April 1, 2026 · FBI, IC3: alert on generative AI fraud, December 3, 2024 · Dominican National Police: online reports