Ok, who sold my email address to these dickheads?

Spammers have been programmatically creating accounts on Mastodon instances for years. Sometimes they post once and never again, sometimes they post on a schedule. Sometimes they never post, like a waiting botnet.
As Mastodon's anti-spam solutions are effectively nonexistent, most instances in our network require manual approval of new accounts. Up until recently, it was easy to spot a spammer; their join reasons were generic.
ChatGPT spammers have now arrived.




Spammers have been programmatically creating accounts on Mastodon instances for years. Sometimes they post once and never again, sometimes they post on a schedule. Sometimes they never post, like a waiting botnet.
As Mastodon's anti-spam solutions are effectively nonexistent, most instances in our network require manual approval of new accounts. Up until recently, it was easy to spot a spammer; their join reasons were generic.
ChatGPT spammers have now arrived.




Besides the logic of inspecting username against email, the join reason statement structure and content, etc- are there external tools you use to vet users?
Example: I use arin.net to check the IP address of a prospective user. Is the IP block registered to a datacenter, or an ISP? If it's an ISP, I'll check the origin country against the interface language for a match.
What have y'all had luck with?

Question #spam #telephonique
Hier soir un +33800112112 a tenté de me joindre. Vérification faite à l'instant, ça ressemble au numéro qui s'affiche lorsque les services d'urgence vous rappelle après que vous ayez composé le 15 ou le 17, 18, 112, 197
Bien sûr, je n'ai composé aucun de ces numéros donc je m'interroge : existe-t-il une possibilité que le +33 permette de "détourner" le numéro initial ?
J'invoque @dada parce que c'est notre "urgentiste" masto favori 🙂

🆕 blog! “Grinding down open source maintainers with AI”
Early one morning I received an email notification about a bug report to one of my open source projects. I like to be helpful and I want people who use my stuff to have a good time, so I gave it my attention. Here's what it said:
😱 I Can't Use On This Day 😭
Seriously, What’s Going On?! 🔍
I’ve been trying to use…
👀 Read more: https://shkspr.mobi/blog/2025/07/grinding-down-open-source-maintainers-with-ai/
⸻
#AI #git#LLM #spam
Anyone else get this bullshit #propaganda #email from #US social security:
Social Security Applauds Passage of Legislation Providing Historic Tax Relief for Seniors
I've NEVER gotten anything from #ssa except yearly statements. And NOW we're getting #partisan #junk #mail #spam from a #government agency. My #tax #dollars wasted so they can push this crap and suck up to #Trump
Pixelfed (and Mastodon) are increasingly targeted by spammers.
Our current AutoSpam detection using Naive Bayes isn't enough*, so we are building a better detection and mitigation system.
Not only will it leverage (optional) established 3rd party services like SpamHaus, but also threat intel from other trusted "reporter" instances like Pixelfed.social.
It's called https://FediThreat.net, and will be available soon!
A website appears to be scraping hashtags and creating AI articles, and then replying to the OG post
It stole one of my posts (https://oldfriends.live/@paul/114770093020700675) for its AI created article then spammed me from @s00laiman
It's doing it with #HashTagGames tags and other trending hashtags.
https://www.trend247daily.com/articles
Article created from scraped post: https://www.trend247daily.com/article/mastering-the-art-of-the-productive-day-wake-up-look-busy-go-to-bed
See this thread above, unless the AI content spammer deletes its reply and breaks the thread.
I don't know where it is getting its content, from it's Mastodon Account ( @s00laiman ) account, rss, or the API. If it has an application I would hope @staff and @moderation would shut it down from scraping the API.


PSA: there's a new spam campaign hitting fedi, this one claims to be raising money for insulin and usually has a banner saying "black lives matter" or another progressive slogan.
You can recognize it in the usual ways:
- Brand-new accounts doing nothing but ask for money.
- Cold-messaging strangers with personal requests for a boost or donation.
- Identical or near-identical accounts appearing all over fedi, primarily on open-registration instances.
If you see these accounts or get pinged by them, don't panic! Just report the profile and let your moderators handle it. The image below is an example of what to look out for.
#PSA #Spam #Scam #FediSpam #MastoSpam #FediAdmins #MastoAdmins
Hey @lightweight, is this is a new spam pattern? A series of posts containing what looks like auto-generated art, and a huge number of tags, some of them totally unrelated. Posted by accounts purporting to belong to professional artists or photographers.
Three examples seen today at #fediverse;
https://socel.net/@DeborahLeagueFineArt
https://socel.net/@peggycollins
I am here to announce that I have decreased #spam on my web contact form from 1 message every 15 minutes (for months straight) to 0 messages in the last week by adding a "I am a spam bot" radio button.
I am not joking.
No I am not using something like ReCaptcha, I literally just added a radio button to the list.