Mastodon Signup Flood: One Admin’s Bot Census
On 2026-05-30, the Mastodon instance run by Aphyr began receiving a wave of signup applications that don’t pass the sniff test. The server’s rules and signup form make the intended audience explicit: users are asked to describe their interest in gay leather culture. Genuine applications usually read something like “42 yo levis enthusiast into piss” or a playful pup introduction. The new submissions look nothing like that.
Instead, the applications fall into a few recognizable categories. Some are conspicuously clean and generic:
I value online communities that are moderated with care and that encourage constructive interaction. I plan to use my account to share interesting stuff, connect with others who share similar interests, and contribute to discussions following the server’s rules and culture.
Others have an uncanny, auto-generated flavor:
Pick the Antarctic path and commit. Custodian inspired by Brendan Fraser, active with Axe Throwing in Indianapolis.
A third group lifts prose directly from existing Fediverse bios, like this one:
Ukraineophile, Save Western Culture and Civilization from russian kleptocracy Trying to make Putin’s bum as irritable as possible.
Patterns Point to Multiple Actors
Several red flags repeat across the submissions. Usernames are often nonsensical (ypy_asi being one example), email addresses don’t align with the display names or text, and similar phrasing appears across multiple email domains. The tactics don’t match perfectly between batches, which suggests more than one operator is active, but the fact that the wave began in the last few weeks points to a coordinated campaign.
A sample of the domains used in the applications includes:
- forge45k.io.vn
- shortweb.live
- vtx.pbhak.dev
- funnyfail.app
- cyberlinkhub.com
- ptncereio.com
- sugarloafstudios.net
- a6nc1sl.jejes.de
- tiksofi.uk
- nowtopzen.com
- nanopools.info
- tmail.lt
- tmail.mx
- phugruphy.com
- sphinx.launders.money
- datamzone.com
- deisgn-ai.work.gd
- haibabon.com
- ai46boh.jejes.de
- initwag.com
- mailba.uk
- compservmail.com
- ff.zero34.qd.je
The Domain Infrastructure Tells Its Own Story
Most of these appear to be transient domains, and many no longer resolve. A couple stand out: tmail.mx and tmail.lt are part of a temporary email service designed to bypass verification checks. The admin speculates that pbhak.dev might be a personal machine that was compromised. Others like jejes.de look like abandoned WordPress installs, likely also compromised and repurposed for this campaign. The browser fingerprints frequently trace back to European IPs, a mix of VPN exit nodes and cloud provider ranges.
This year’s influx differs from last year’s, when most spam traces back to a single company, as detailed in a prior post. The current setup looks messier and less centralized. As an experiment, the admin approved one of the inauthentic accounts and is monitoring it to see what activity follows.



