Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Wikipedia blacklists Archive.today after alleged DDoS attack

Google VP warns two types of AI startups may not survive

These former Big Tech engineers are using artificial intelligence to navigate Trump’s trade mess

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Sam Altman would like to remind you that people use a lot of energy too

    22 February 2026

    ‘Toy Story 5’ takes aim at creepy AI toys: ‘I’m always listening’

    21 February 2026

    Great news for xAI: Grok is now very good at answering questions about Baldur’s Gate

    21 February 2026

    UAE’s G42 partners with Cerebra to deploy 8 exaflops of computers in India

    20 February 2026

    Why these startup CEOs don’t think AI will replace human roles

    20 February 2026
  • Apps

    Apple’s iOS 26.4 arrives in public beta with AI music playlists, video podcasts and more

    22 February 2026

    India’s Sarvam launches Indus AI chat app as competition heats up

    21 February 2026

    Remember HQ? “Quiz Daddy” Scott Rogowsky is back with TextSavvy, a daily mobile game show

    21 February 2026

    As the browser war heats up, Chrome is adding new productivity features

    20 February 2026

    Google says its AI systems helped prevent Play Store malware in 2025

    20 February 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    InScope raises $14.5M to solve financial reporting pain

    20 February 2026

    OpenAI deepens India push with Pine Labs fintech partnership

    19 February 2026

    Cash app adds payment links so you can get paid in DMs

    11 February 2026

    MrBeast’s company buys Gen Z fintech app Step

    9 February 2026

    Stripe Alumni Raise €30M Series A for Duna, Backed by Stripe and Adyen Executives

    5 February 2026
  • Hardware

    Joseph C Belden: Last Chance for Innovators to Earn Scaling Privileges

    20 February 2026

    At a critical time, Snap is losing a top spec executive

    20 February 2026

    Freeform Raises $67M Series B to Scale Laser AI Production

    19 February 2026

    India’s Sarvam wants to bring its AI models to phones, cars and smart glasses

    19 February 2026

    Google debuts $499 Pixel 10a

    18 February 2026
  • Media & Entertainment

    Google adds music-making capabilities to its Gemini app

    21 February 2026

    Disrupt 2026 Super Early Bird pricing expires in 1 week

    20 February 2026

    YouTube’s latest experiment brings its AI chat tool to TVs

    20 February 2026

    OpenAI, Reliance partner to add AI search to JioHotstar

    19 February 2026

    SeatGeek and Spotify are teaming up to offer concert ticket discounts within the music platform

    19 February 2026
  • Security

    Wikipedia blacklists Archive.today after alleged DDoS attack

    22 February 2026

    Error on student admissions website exposed children’s personal details

    21 February 2026

    Ukrainian man jailed for identity theft that helped North Koreans get jobs at US companies

    21 February 2026

    Cellebrite cut off Serbia citing misuse of its phone unlocking tools. Why not others?

    20 February 2026

    FBI says ATM ‘jackpot’ attacks on the rise, hackers net millions in stolen cash

    20 February 2026
  • Startups

    Google VP warns two types of AI startups may not survive

    22 February 2026

    Co-founders behind Reface and Prisma join hands to improve on-device model inference with Mirai

    21 February 2026

    Nominations for the Startup Battlefield 200 are now open

    21 February 2026

    The OpenAI mafia: 18 startups founded by graduates

    20 February 2026

    Nvidia deepens early-stage push into India’s AI startup ecosystem

    20 February 2026
  • Transportation

    These former Big Tech engineers are using artificial intelligence to navigate Trump’s trade mess

    22 February 2026

    Rivian owners will soon be able to access vehicle controls using their Apple Watch

    21 February 2026

    Lucid Motors is cutting 12% of its workforce as it pursues profitability

    21 February 2026

    New York puts the brakes on robotaxi expansion plan

    20 February 2026

    AI data center boom fuels Redwood’s energy storage business

    20 February 2026
  • Venture

    Ali Partovi’s Neo appears to upgrade the throttle model in low dilution terms

    21 February 2026

    Peak XV Raises $1.3B, Doubles In AI As Global India VC Competition Heats Up

    21 February 2026

    General Catalyst commits $5 billion to India over five years

    20 February 2026

    Reload wants to give your AI agents a shared memory

    20 February 2026

    This VC’s best advice for building a founding team

    19 February 2026
  • Recommended Essentials
TechTost
You are at:Home»Apps»Spam attack on Twitter/X rival Mastodon highlights ‘different’ vulnerabilities
Apps

Spam attack on Twitter/X rival Mastodon highlights ‘different’ vulnerabilities

techtost.comBy techtost.com21 February 202406 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Spam Attack On Twitter/x Rival Mastodon Highlights 'different' Vulnerabilities
Share
Facebook Twitter LinkedIn Pinterest Email

A spam attack that affected open source X competitor Mastodon, Misskey and other apps highlights how the decentralized social web, also known as the fediverse, is open to abuse. In recent days, attackers have targeted smaller Mastodon servers, taking advantage of open registrations to automate the creation of spam accounts. Mastodon founder and CEO Eugen Rochko confirmed the attack with his post over the weekend, adding that Mastodon server admins should switch registration to approval mode and block spam email providers to help address the issue.

While this isn’t the first spam attack to affect Fediverse, Rochko notes that only larger servers like Mastodon.social have been targeted in the past. As this server is run by the Mastodon team themselves, they were able to mitigate these attacks themselves. What’s different this time is that spammers targeted smaller and even abandoned servers that offer open enrollment, allowing bad actors to quickly create accounts and create spam.

Image Credits: Eugen Rochko in Mastodon

This particular attack, which was fully automated once the attackers learned they could write spam, was caused by a dispute between two sides on Discord, where one side was trying to ban the other side’s Discord server, according to reports on Mastodon. (More details in this here.) Many of the other targets of spammers Mastodon wasn’t alone — they were also targeted Miski. (Misskey is an open-source, decentralized blogging platform that uses the ActivityPub protocol, like Mastodon, Pixelfed, PeerTube, and others, allowing its users to interact with those on other federated social media platforms.) As the origin of spam seems to be a Japanese forummany of the targets were also in Japan.

The spam attack highlighted one of the weaknesses that comes with the structure of the fediverse. Mastodon is open source software that anyone can install on their own server, essentially establishing their own instance or node, connected to other federated social networking servers supported by the ActivityPub protocol.

Because Mastodon’s smaller servers are often hobbyist projects run by enthusiasts, they were vulnerable to these types of attacks. If server admins didn’t pay attention to their servers on a daily basis and offered open registrations, they would likely be victims of spam.

Or as a server administrator, @Chris@mastodon.cosmicnation.co observed, “Some case managers recalled that they had an example. And we’ve also learned that there are a LOT of abandoned cases out there with the door wide open to registration without approval.”

In recent days, the server administrators they cooperated to create continuous lists abandoned cases that other administrators could use as a basis for a block list to protect their own users from spam attacks. Many servers were simply disabled as their admins decided it would be easier to wait out the attack or abandon Mastodon altogether.

The popular third-party app Mastodon Ivory, by Tapbots, an emergency update has been released which included a custom filter called “Potential Spam” under the Filter tab that would allow users to mute spam reports. Affected users could enable this filter to catch most spam, but could not stop spam push notifications, the company said.

The attack seems to be ending as of this morning. Technologist and researcher Tim Chambers (@tchambers@indieweb.social) noted that today was the first day in four days that he had fewer than 40 spam accounts to suspend on the server he manages, for example. Mastodon tells TechCrunch that on active servers with a reactive moderation team, Mastodon has several tools to prevent automated account registration, including approval mode, CAPTCHAs and various blocking tools, so the attacker is dealt with very quickly. He also noted that the spam attack has ended as the two hacker groups apparently made peace.

While some saw the experience as positive for the social network and the wider federation, as it exposed a weakness that could now be discussed and addressed, others were angry at the experience and Rochko’s lack of response in the early hours of the attack.

“This ruins my Mastodon experience for me. Makes me want to quit and quit,” wrote one Mastodon server admin sam@urbanists.social. “And Eugen’s continued silence on the problem doesn’t help matters,” they said.

Mastodon CTO Renaud Chaput said the attack will push the company to improve its software.

“Currently, there are no well-built tools to handle this, as this is a complex issue — federated networks are not easy! — but we have a lot of ideas about how to improve our anti-spam and anti-abuse capabilities,” he said. “These will be worked on in the coming months. We are always working on improving the software (the latest version introduced optional captcha support). Another measure we took today is to change the setting for new instances so that they are not wide open by default, and we added a banner to remind admins that fully open instances must be actively moderated, so this should be a careful decision by the administrator,” Chaput added.

Since the arrival of Instagram Threads, another Twitter/X competitor that also plans to merge using ActivityPub, Mastodon usage has dropped.

As of October last year, Mastodon had grown to include around 1.8 million monthly active users. By the time Threads went public, it had dropped to 1.5 million. Since the public release this month of Bluesky, another decentralized social network based on a different protocol (meaning it’s not part of the same fediverse, at least until a bridge is built), Mastodon’s use has he fell to 1 million monthly active users.

That’s where Mastodon’s usage remains today, according to the company’s homepage. The wider fediverse, which includes Mastodon and other apps, has around 2.9 million monthly active users. Entering threads at this time will overshadow other Mastodon servers and could offer Meta’s technical expertise in areas such as spam prevention, but many worry that Meta’s ultimate goal will be to essentially take over the fediverse by making it the default client that users choose and using it significant resources to scale the adoption of Meta’s application.

Updated 2/20/24, 1:31 p.m. ET to add Mastodon CTO comment

alike attack highlights mastodon pub activity Rival social media spam TwitterX vulnerabilities
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleOnePlus took a three-year “reflective pause” before increasing the battery of its smartwatch
Next Article China’s Moonshot AI Zooms to $2.5B Valuation, Raises $1B for Long-Frame Focused LLM
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Wikipedia blacklists Archive.today after alleged DDoS attack

22 February 2026

Apple’s iOS 26.4 arrives in public beta with AI music playlists, video podcasts and more

22 February 2026

India’s Sarvam launches Indus AI chat app as competition heats up

21 February 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Wikipedia blacklists Archive.today after alleged DDoS attack

22 February 2026

Google VP warns two types of AI startups may not survive

22 February 2026

These former Big Tech engineers are using artificial intelligence to navigate Trump’s trade mess

22 February 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

InScope raises $14.5M to solve financial reporting pain

20 February 2026

OpenAI deepens India push with Pine Labs fintech partnership

19 February 2026

Cash app adds payment links so you can get paid in DMs

11 February 2026
Startups

Google VP warns two types of AI startups may not survive

Co-founders behind Reface and Prisma join hands to improve on-device model inference with Mirai

Nominations for the Startup Battlefield 200 are now open

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.