Mixfont has released Decoy Font, an experimental TrueType typeface designed to make screenshots of text harder for AI and optical-character-recognition systems to interpret. Each glyph combines an intended letter with a second, misleading one, creating a hybrid image whose reading changes with viewing distance and image processing.
The foreground is formed from thin, sharply outlined strokes, while a blurred, low-frequency mass carries the alternate letter. Up close, the high-frequency outline is more prominent. From farther away, or when a viewer squints, the lower-frequency shape can dominate. The method draws on established hybrid-image illusions, including composites in which Albert Einstein is visible at one scale and Marilyn Monroe at another.
According to the project creator, vision-language models examining pixels at close range often select the outlined decoy, while a person viewing the whole line can read the intended background message. The site reports tests against named frontier models, but it does not provide a formal benchmark, broad sample or durable guarantee. Results may depend on font size, screenshot resolution, image scaling and model behavior.
Unlike an earlier Mixfont experiment called Ghost Font, which relies on motion, Decoy Font is distributed as an installable TTF and can be typed in ordinary applications. Its letterforms derive from DejaVu Sans Mono, and the project permits personal, commercial and client use subject to the full font licence. An online playground lets users try letter combinations before downloading it.
The creator suggests possible uses in deterring casual scraping, exploring CAPTCHA-like interactions or exchanging playful hidden messages. The project could also serve as a changing test of model text recognition as multimodal systems learn to identify both frequency layers. Expansion to additional languages is another proposed direction, with character-based writing systems identified as a potentially interesting case.
Decoy Font should not be treated as encryption or a privacy boundary. An agent that knows the technique could resize, blur or otherwise process an image to recover the alternate forms, and a human can transcribe visible content. Mixfont explicitly acknowledges that capable models and appropriate prompting may defeat the illusion. Its value is therefore experimental: it turns a familiar perception effect into usable typography and demonstrates how assumptions in machine vision can be challenged, without promising lasting secrecy.


