The New Spam Economy: When Every Comment Sounds Plausible

Spam has always been a game of economics. For decades, the math was simple: spammers invested labor proportional to the value of their target. Cheap, mass-produced spam—the endless Viagra pitches and PHPBB forum junk—was easy to generate and easy to filter. The spammers made it up in volume. At the other end of the spectrum sat spear phishing: a highly time-consuming, manual effort requiring careful research into a target and their network. That kind of attack was expensive, but it was far more likely to succeed and was reserved for high-value victims.

Large Language Models have upended that balance. Over the past year, a new class of blog comment spam has emerged that is qualitatively different from what came before. These comments make specific, plausible remarks about the exact contents of a post or image, then seamlessly work in a link to some website or a product mention. One recent example caught on aphyr.com:

"Walking down a sidewalk lined with vibrant flowers is one of life’s simple joys! It reminds me of playing the [link redacted] slope game, where you have to navigate through colorful landscapes while dodging obstacles.

What would previously have demanded a human paid a few cents per message is now fully automated. The models happily fabricate relatable personal experiences as part of a coordinated campaign. Consider this comment on a photography post:

That photo reminds me of the first time I tried macro photography in my backyard. I spent an hour trying to get a clear shot of a red flower, experimenting with angles and lighting. It was so much fun discovering the little details up close! If you ever need a break from photography, I recommend playing Snow Rider 3D for a bit of quick, light-hearted fun.

Some spam is even clumsier, gluing an LLM-generated paragraph to what appears to be hand-written ad copy. The abrupt shift in grammar, diction, and specificity makes the seam obvious:

This piece masterfully blends technical depth with mythological storytelling, transforming a standard Haskell programming interview into an epic narrative. It cleverly critiques the complexity and absurdity of some technical interviews by illustrating how type-level Haskell can be pushed to esoteric extremes beautiful, powerful, and largely impractical. A fascinating and relevant read for anyone interested in the intersection of programming, language design, and narrative. I’m James Maicle, working at Cryptoairhub where we run a clear and insightful crypto blog. I’ll be bookmarking your site and following the updates. Glad to see so much valuable information shared here looking forward to exploring more strategies together. Thanks for sharing. If you interest about Crypto please visit my website and read my article [link redacted] Crypto Blog.

The phenomenon extends beyond commercial blog spam. Aggregators like Hacker News see commenters posting obviously LLM-generated output, apparently chasing karma. Some bots, like the Hacker Briefs account on Bluesky, appear to use LLMs to summarize trending HN posts. In a summary of a recent Jepsen analysis of Amazon RDS for PostgreSQL 17.4, the bot wrote:

“Jepsen: Amazon RDS for PostgreSQL 17.4”

New multi-AZ clusters in Amazon RDS for PostgreSQL offer better failure recovery but may return outdated data when reading after writes. Caution is needed.

The summary is superficially plausible and entirely wrong: multi-AZ clusters in this context are nothing new, and the actual anomaly described in the analysis—Long Fork—does not involve reading after writes or real-time orders at all. The bot didn’t miss the point; it invented a different one. While this variant of spam may lack a commercial motive, it is one more drop in a growing pool of misinformation that humans must wade through.

Moderation in the Age of Synthetic Text

Content moderation has always involved sorting sincere humans from automated attacks. LLMs have made it dramatically worse. Unlike earlier spam, which could be caught because it was cheap, repetitive, and easy to fingerprint, LLM-generated text is unique at scale and appears on its surface to be reasoned and personal. The line between “awkward but sincere human” and “automated attack” is blurring. Filters and human moderators now have to spend more time per message—and there are more messages to check.

The economics driving this problem are also evolving. Generating credible text at near-zero marginal cost opens the door for attacks that previously required significant labor. In recent weeks moderators note receiving vague voice messages from strangers with unnatural speech patterns, simply ~asking to catch up. Pre-2023, a voice message like that would be odd enough to be dismissed; now it’s plausible that these are AI-generated, possibly as part of a pig butchering scheme or worse. It’s not hard to imagine such techniques extended to impersonating a friend, colleague, or even a trusted service provider in a detailed conversational context.

A Shifting Target for Defenses

Social networks have historically responded to these threats with out-of-band signals: IP reputation, browser and mobile fingerprinting, and statistical correlations across many accounts. These defenses rely on centralized observation of user behavior. For decentralized platforms—email, self-hosted blogs, and federated networks like Mastodon—those tools translate poorly. Mastodon remains relatively quiet, likely because its user base isn’t lucrative enough yet to justify sustained effort. But, as these economics shift, even niche communities may fall into target range.

That’s the long-term worry: LLMs make it increasingly cheap to generate accounts, personae, and even long-term relationships with real humans, before turning those relationships toward commercial or political purposes. When the cost of a plausible, unique spam comment collapses to fractions of a cent, the traditional defense-in-depth around content quality itself appears far more fragile, especially for systems that aren’t centralized enough to monitor users at scale.