Is The Viral "Let's Buy Spirit Airlines" Campaign a Scam?
How to actually fact-check TikTok/Instagram campaigns in 2026 - when the old "scam tricks" don't work anymore
On May 2, 2026, Spirit Airlines shut down at 3AM. Years of debt, multiple bankruptcies, and the recent spikes in fuel prices finally caught up with them. Thousands of employees lost their jobs overnight.
In light of the news, an LA voice actor named Hunter Peterson posted a video with an idea: there are 250 million adults in the US, and if 20% of them paid the price of a single Spirit ticket, the public could just… buy the airline. Peterson’s vision is that Spirit would be run like a co-op.
That video got around 2.8 millions views in one day. By Saturday night, Peterson had stood up letsbuyspiritair.com to collect non-binding monetary pledges. By Sunday afternoon, the site had crashed under its own traffic. And on Tuesday morning, the campaign had over $132 million pledged from over 156,000 people with a slated target of $1.75 billion.
It is a wild premise. And the comment sections under every post seem to be split. Half of the comments think this is a genius idea and want to know where to send their money, and the other half say "this is 100% a scam do not fall for it.”
So which is it? Let’s actually check.
Red Flag #1: A Website That Appeared Overnight
For most of the internet’s history, a clean professional-looking website was a strong “this is a legitimate operation” signal. Building a site often took either money, or time (and skill). A scammer was not likely to invest in either.
That heuristic is dead. It died sometime in 2024 and we are still adjusting.
Hunter’s site is pretty well-designed: strong typography and a clear pledge flow. A few years ago, that alone would be a green flag.
But Hunter said, that he built the original site “in like an hour” using AI. The ability to build a website like this so quickly, and cheaply can be great for legitimate small businesses. But… it is also great for scammers.
My point is: a polished, fast-launched site tells you almost nothing about legitimacy in 2026.
It is no longer evidence of investment, planning, or even competence. It is evidence that someone clicked a button and wrote a prompt. If you want to know if something is legit, you have to look for other signals and dig deeper.
One thing that does matter though, especially now, is understanding the difference between a quickly-built AI assisted website and a securely engineered platform.
A growing percentage of sites launched in the last year were made through a process called “vibe-coding.” Which basically means someone describes what they want in text, and AI generates most of the code. For simple landing pages, portfolios, and prototypes vibe coding can be great. It dramatically lowers the barrier to building something useful.
But the moment a site starts collecting personal information, or interacting with databases, APIs etc. things get more complicated…
Risks of Vibe Coded Websites
AI generated code can introduce serious security issues that the person deploying it likely didn’t realize. We’re seeing examples of this everywhere. Security researchers (myself included) have repeatedly found AI-generated web apps exposing private databases, hardcoded API keys, admin dashboards without authentication, and vulnerable payment flows because inexperienced builders trusted generated code they didn’t fully understand.
There have also been several cases of startups that tried to use fully AI generated platforms as their “product” and accidentally leaked user email addresses, uploaded sensitive documents to the internet, or exposed credentials simply because there was no one to verify if basic security practices were being followed:

To be clear: that does NOT automatically make Hunter’s project unsafe or malicious. AI website builders can be very useful, and safe when used correctly. Collecting pledges is a very different category of risk, than entering a credit card number, uploading identity documents or connecting a bank account.
But as a general rule for the modern internet, if any rapidly launched AI-based startup is asking for sensitive info, that should absolutely give you pause.
Red Flag #2: Who actually Owns this Domain?
When I want to verify a website, one of the first things I do is a WHOIS lookup, basically a domain ownership search. Every public domain has a registration record that includes (or used to include) the registrants name, organization, and contact info. In 2018, GDPR and ICANN privacy rules redacted most personal info, but you can still see the registrar the country, and the creation date, and often the organization that registered it.
You can do this yourself in a few seconds. Two easy options:
Go to
whois.domaintools.comorwho.isand paste in the domain.Or in your terminal, type
whois letsbuyspiritair.com
When I ran this on Hunter’s domain, here is what stood out:
The domain registration trail leads back to Butterfly Effect Pte. Ltd, an Singapore-based company*
At first glance, this was a red flag. An American Tik Toker with a domain owned by a foreign tech company… But when I dug deeper, I found that Butterfly Effect is the parent company of Manus. An AI company headquartered in Singapore and now partnered with Meta. This actually checks out. It’s been confirmed Hunter built the originally site with Manus. So when Hunter clicked ‘deploy’ the domain was registered under Butterfly Effect rather than under his own name.
As a software developer, that part worries me a little bit for Hunter. A domain name is a valuable business asset, it is your identity online. If someone else technically controls the registration, it can create problems later. A third party platform can theoretically lock you out, suspend the account, fail to transfer ownership correctly, or create a messy legal situation if the domain suddenly becomes valuable.

There are horror stories all over the startup world involving founders losing access to a domain because an employee registered it personally, a contractor disappeared, or a deployment platform technically controlled the registration. In some cases, companies have had to pay massive sums to regain control of their domains.
Basically, all im saying is if you’re starting a website, you should make sure you really own your domain.
Note: there is an update posted related to the domain situation at the end of the article!
The Big Green Flag: He’s Not Asking for Money
This is the single most important thing about this campaign, and it’s what removes red flags and solidifies this as an earnest social experiment.
Nowhere on letsbuyspiritair.com is anyone being asked to send actual money.
What you’re submitting is a non-binding pledge, a statement of how much you’d theoretically be willing to contribute if this campaign ever materializes into a real regulated investment offering. No credit card field. No payment information taken of any kind. Hunter explicitly walked back a joke he made in his first video about setting up a Venmo by saying in a follow up video:
“Register your intent. I won’t take any money. We’re not going to use the Venmo… that was kind of a joke”
This is huge for two reasons:
It is the cleanest possible signal of intent. Scams need cash. If a campaign has been running for days at a viral scale and no one is being asked to part with any money, it’s very unlikely it’s a scam. As time goes on, the potential upside for a scammer would dwindle.
It is also the legally correct move. Under SEC rules, you can’t just collect investment money from the public for a future business venture without registration.
By keeping pledges non-binding and unfunded, Hunter is staying inside the lines while he figures out what the actual offering would look like.
So the core campaign clears the bar.
But, this is where it gets dangerous. that same setup creates a perfect environment for parasitic scammers.
Where the Real Scam Risk Lives
When a campaign like this goes viral, and millions of people are searching for it, scammers will immediately try and impersonate it. Within a couple of days of the original site launching, lookalike domains and instagram accounts started popping up:
letsbuyspiritair.organdletsbuyspirit.org- some examples of domain look alikes that have popped up. And some of these are asking for direct payment - HUGE red flagspiritairlines_2.0on instagram - an imposter account riding off of Hunter’s real accountspiritair2.0. Note the extra underscores tacked on… easy to miss.
This is a tactic known in cybersecurity as typosquatting, and it’s one of the oldest tricks in the social-engineering playbook. The variations are tiny on purpose, your brain pattern matches and skips over the difference.
If anything in the “Let’s Buy Spirit” universe is asking you for actual money right now its a scam.
How to protect yourself:
Type the url yourself, don’t click links from untrusted sources, comments or DMs
Check the exact handle, including underscores, dots and pluralization
Look for the verification trail, Hunter has been posting consistently from existing accounts with hundreds of thousands of followers. A brand new account with 200 followers asking for $45 to buy Spirit is NOT the same thing.
If they want money, walk away. That alone resolves 99% of the risk here.
The Updated Framework
The old “spot a scam” checklist was built for a world where even making a simple site was expensive. AI has flattened that cost to roughly zero. Which means:
“It looks polished” does not mean legit
“It launched fast” does not mean well funded
“The copy is well written” does not mean its real
“There’s a custom domain” does not mean to trust it
What still works
Follow the money: who is asking for what, and into what account? A legitimate campaign structures the money carefully or doesn’t ask for it at all.
Cross reference identity across platforms: Real people accumulate verifiable history online. A new account with no prior post running major fundraising operations is a red flag.
Run a WHOIS lookup: Knowing how to ask “who actually owns this domain” is a valuable skill you can learn in 30 seconds.
Check for typosquats. When something is viral, the imposters arrive within hours. Always verify the url and handle character by character.
The single most reliable signal is: are they asking for your money, and where is it going?
In the Let’s Buy Spirit case, the answer is no. The campaign is (as far as I can tell) exactly what it appears to be: a motivated content creator using the leverage of viral video and AI tooling to organize an ambitious social experiment. And we’re watching it happen in real time. Whether it ever turns into a real airline is a completely different question.
Many have pointed out that he’s facing massive hurdles ahead, buying and operating an airline involves FAA certification, billions in working capital, and the navigation of a regulatory landscape that is pretty intense. Those are all HUGE obstacles.
But a “longshot” is a very different thing from “a scam.” And I think what Hunter has accomplished so far is really really cool. He saw a moment, used the tools available and organized hundreds of thousands of strangers around a collective goal in just a few days. And so far he has done this responsibly, transparently, and without taking anyone’s money. He’s openly figuring it out in public, consulting legal and tech help where he needs it and being upfront about the parts he doesn’t know about yet.
That is a pretty incredible use of modern technology, and I’m genuinely interested to follow his journey and see where it goes.
Just please, do not send anyone actual money thinking you’re buying a part of Spirit. Not to him, not to anyone claiming to be him, and absolutely not to a Venmo, Cash App or crypto wallet posted in a comment somewhere.
The hackers and imposters are out there. Stay safe.
*Update/Additional Note:
At the time of writing this article, the WHOIS registration for letsbuyspiritair.com pointed back to Butterfly Effect Pte Ltd, as stated. But since then, the domain registration has been updated and now routes through Cloudflare instead.
This is a green flag!
Cloudflare provides services like DDoS protection, DNS management, SSL security and domain infrastructure for millions of websites. This change strongly suggests that Hunter either hired a developer or began working with someone experienced in web infrastructure and security to properly manage the project as it scales.
This is exactly what I would want to see happen with a rapidly growing viral site collecting user information and handling traffic spikes.
In other words: the technology stack seems to be maturing alongside the project. Nice job, Hunter!
Tech Glossary
WHOIS — A public protocol for querying who owns a registered domain name. Returns the registrar, registration date, expiration date, and (depending on privacy settings) registrant organization or country.
Typosquatting — A scam tactic that registers domains or social handles that differ from a legitimate one by a single character, an extra letter, or a different top-level domain (.com vs .org). Designed to catch users who mistype or skim.
Top-Level Domain (TLD) — The part of a URL after the final dot — .com, .org, .net, .io, etc. Different TLDs are operated by different registries and have different rules, but a .com and a .org with the same name are completely separate websites owned by potentially completely different people.
Domain Registrar — The company you pay to register and renew a domain name (GoDaddy, Namecheap, Cloudflare, etc.). On AI website builders like Manus, the registrar relationship is often held by the platform on the user’s behalf, which is convenient but gives the user less control.
Vibe Code Builder — A new category of tool (Manus, Lovable, etc) that generates websites and web app prototypes from natural-language prompts. They have compressed the time-to-launch for a website from weeks to minutes, but have also introduced serious cybersecurity risks.






Great insights. I agree this was an interesting social experiment. Perhaps if Hunter had been an executive at Spirit, the airline might
have survived.
Very useful info! 👍🏼