Social

Discord took no action against server that coordinated costly Mastodon spam attacks

Comment

Discord logo in flames
Image Credits: Bryce Durbin/TechCrunch

Over the weekend, hackers targeted federated social networks like Mastodon to carry out ongoing spam attacks that were organized on Discord, and conducted using Discord applications. But Discord has yet to remove the server where the attacks are facilitated, and Mastodon community leaders have been unable to reach anyone at the company.

“The attacks were coordinated through Discord, and the software was distributed through Discord,” said Emelia Smith, a software engineer who regularly works on trust and safety issues in the fediverse, a network of decentralized social platforms built on the ActivityPub protocol. “They were using bots that integrated directly with Discord, such that a user didn’t even need to set up any servers or anything like that, because they could just run this bot directly from Discord in order to carry out the attack.”

Smith attempted to contact Discord through official channels on February 17, but still has only received form responses. She told TechCrunch that while Discord has mechanisms for reporting individual users or messages, it lacks a clear way to report whole servers.

“We’ve seen this costing server admins of Mastodon, Misskey, and others hundreds or thousands of dollars in infrastructure costs, and overall denial of service,” Smith wrote to Discord Trust & Safety in an email viewed by TechCrunch. “The only common link seems to be this discord server.”

In a statement to TechCrunch, a Discord spokesperson said, “Discord’s Terms of Service specifically prohibit platform abuse, which refers to activities that disrupt or alter the experience of Discord users, including spam, or sending unsolicited bulk messages or interactions.” Though Discord says it is monitoring the situation, the server responsible for the spam attacks remains online.

Mastodon founder and CEO Eugen Rochko said in a post that these attacks are more difficult to moderate than past ones, because they deliberately target smaller servers, which often have fewer moderation tools in place. Some of these servers offer open registration, making it possible to quickly start new accounts and post spam. And as Smith notes, these mass spam attacks can drive up server costs, leaving admins with unexpected bills.

According to reports on Mastodon, this fully automated attack was sparked by a conflict between teenagers on two different Japanese language Discord servers.

“It’s this sort of weird social behavior, where these kids are essentially acting like schoolyard bullies,” Smith told TechCrunch. She thinks that they carried out the attack simply to show that they can, not because they have any ill-will toward these social networks.

“They’ve got technological capabilities that are well above where they are emotionally or psychologically,” she said.

Kevin Beaumont, a cybersecurity expert, posted on Mastodon that this incident recalls a similar, yet much larger attack from 2016, in which three college kids created a botnet to make money on Minecraft. But what they built was so powerful that it was able to take down huge swaths of the internet, including sites like Reddit and Spotify.

“I had to do a radio show on NPR about that one and the presenter kept asking me if it was Putin — and I was like, no, it’s teenagers. Advanced Persistent Teenagers,” Beaumont posted.

As a decentralized social media network, Mastodon’s team is unable to intervene in moderation issues on servers that they don’t own, which is a vulnerability for the fediverse. On servers that are actively maintained and moderated, Mastodon offers tools to prevent automated account registration, like CAPTCHAs.

While Mastodon’s nonprofit, open source model gives users more ownership over their social media experiences, it also limits the company’s ability to hire more developers. Most of the social network is run by volunteers, like Smith herself.

“I would estimate that the entire fediverse is developed off of the backs of maybe, at best, 100 engineers,” she said. “All of whom are either low paid, underpaid, or unpaid, who are trying to build software, and at the same time, are supporting the userbase of monthly active users in the range of 1.1 million to 7.4 million.”

Spam attack on Twitter/X rival Mastodon highlights ‘fediverse’ vulnerabilities

More TechCrunch

If you’re anything like me, you’ve tried every to-do list app and productivity system, only to find yourself giving up sooner than later because sooner than later, managing your productivity…

Hoop uses AI to automatically manage your to-do list

Asana is using its work graph to train LLMs with the goal of creating AI assistants that work alongside human employees in company workflows.

Asana introduces ‘AI teammates’ designed to work alongside human employees

Taloflow, an early stage startup changing the way companies evaluate and select software, has raised $1.3M in a seed round.

Taloflow puts AI to work on software vendor selection to reduce cost and save time

The startup is hoping its durable filters can make metals refining and battery recycling more efficient, too.

SiTration uses silicon wafers to reclaim critical minerals from mining waste

Spun out of Bosch, Dive wants to change how manufacturers use computer simulations by both using modern mathematical approaches and cloud computing.

Dive goes cloud-native for its computational fluid dynamics simulation service

After growing 500% year-over-year in the past year, Understory is now launching a product focused on the renewable energy sector.

Insurance provider Understory gets into renewable energy following $15M Series A

Ashkenazi will start her new role at Google’s parent company on July 31, after 23 years at Eli Lilly.

Alphabet’s brings on Eli Lilly’s Anat Ashkenazi as CFO

Tobiko aims to reimagine how teams work with data by offering a dbt-compatible data transformation platform.

With $21.8M in funding, Tobiko aims to build a modern data platform

In 1816, French physician René Laennec invented an instrument that allowed doctors to listen to human hearts and lungs. That device — a stethoscope — eventually evolved from a simple…

Eko Health scores $41M to detect heart disease earlier and more accurately

The number of satellites on low Earth orbit is poised to explode over the coming years as more mega-constellations come online, and it will create new opportunities for bad actors…

DARPA and Slingshot build system to detect ‘wolf in sheep’s clothing’ adversary satellites

SAP sees WalkMe’s focus on automating contextual, in-app support as bringing value to its own enterprise customers.

SAP to acquire digital adoption platform WalkMe for $1.5B

The National Democratic Alliance (NDA) has emerged victorious in India’s 2024 general election, but with a smaller majority compared to 2019. According to post-election analysis by Goldman Sachs, JP Morgan,…

Modi-led coalition’s election win signals policy continuity in India – but also spending cuts

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the…

17 hours ago
A comprehensive list of 2024 tech layoffs

Featured Article

What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

Apple is hoping to make WWDC 2024 memorable as it finally spells out its generative AI plans.

17 hours ago
What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

We just announced the breakout session winners last week. Now meet the roundtable sessions that really “rounded” out the competition for this year’s Disrupt 2024 audience choice program. With five…

The votes are in: Meet the Disrupt 2024 audience choice roundtable winners

The malicious attack appears to have involved malware transmitted through TikTok’s DMs.

TikTok acknowledges exploit targeting high-profile accounts

It’s unusual for three major AI providers to all be down at the same time, which could signal a broader infrastructure issues or internet-scale problem.

AI apocalypse? ChatGPT, Claude and Perplexity all went down at the same time

Welcome to TechCrunch Fintech! This week, we’re looking at LoanSnap’s woes, Nubank’s and Monzo’s positive milestones, a plethora of fintech fundraises and more! To get a roundup of TechCrunch’s biggest…

A look at LoanSnap’s troubles and which neobanks are having a moment

Databricks, the analytics and AI giant, has acquired data management company Tabular for an undisclosed sum. (CNBC reports that Databricks paid over $1 billion.) According to Tabular co-founder Ryan Blue,…

Databricks acquires Tabular to build a common data lakehouse standard

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

The next few weeks could be pivotal for Worldcoin, the controversial eyeball-scanning crypto venture co-founded by OpenAI’s Sam Altman, whose operations remain almost entirely shuttered in the European Union following…

Worldcoin faces pivotal EU privacy decision within weeks

OpenAI’s chatbot ChatGPT has been down for several users across the globe for the last few hours.

OpenAI fixes the issue that caused ChatGPT outage for several hours

True Fit, the AI-powered size-and-fit personalization tool, has offered its size recommendation solution to thousands of retailers for nearly 20 years. Now, the company is venturing into the generative AI…

True Fit leverages generative AI to help online shoppers find clothes that fit

Audio streaming service TuneIn is teaming up with Discord to bring free live radio to the platform. This is TuneIn’s first collaboration with a social platform and one that is…

Discord and TuneIn partner to bring live radio to the social platform

The early victors in the AI gold rush are selling the picks and shovels needed to develop and apply artificial intelligence. Just take a look at data-labeling startup Scale AI…

Scale AI founder Alexandr Wang is coming to Disrupt 2024

Try to imagine the number of parts that go into making a rocket engine. Now imagine requesting and comparing quotes for each of those parts, getting approvals to purchase the…

Engineer brothers found Forge to modernize hardware procurement

Raspberry Pi has released a $70 AI extension kit with a neural network inference accelerator that can be used for local inferencing, for the Raspberry Pi 5.

Raspberry Pi partners with Hailo for its AI extension kit

When Stacklet’s founders, Travis Stanfield and Kapil Thangavelu, came out of Capital One in 2020 to launch their startup, most companies weren’t all that concerned with constraining cloud costs. But…

Stacklet sees demand grow as companies take cloud cost control more seriously

Fivetran’s Managed Data Lake Service aims to remove the repetitive work of managing data lakes.

Fivetran launches a managed data lake service

Lance Riedel and Nigel Daley both spent decades in search discovery, but it was while working at Pinterest that they began trying to understand how to use search engines to…

How a couple of former Pinterest search experts caught Biz Stone’s attention