When the Signup Form Becomes an LLM Test
For nearly six years, the small Mastodon server I help administer—around six hundred queer leatherfolk—has used a simple application question to keep the community focused and spam-free. The prompt asks prospective members to describe their connection to queer leather, kink, or BDSM, and what kind of play or gear interests them. It works remarkably well at filtering out both the merely curious and the automated. Until last week, we had seen only a handful of spam accounts in that entire span.
A few days ago, a new application arrived for a user named mrfr:
Hi! I’m a queer person with a long-standing interest in the leather and kink community. I value consent, safety, and exploration, and I’m always looking to learn more and connect with others who share those principles. I’m especially drawn to power exchange dynamics and enjoy impact play, bondage, and classic leather gear.
The phrasing is slightly off—most applicants are more specific about their identity, saying something like "I'm a dyke" or "I'm a non-binary bootblack"—but the Zoomers do use this sort of generalized language. There's a faint LLM-flavor to the sentence structure, but nothing definitive. Some genuine humans write exactly like this.
I approved the account. A few hours later, it posted this:

It turns out mrfr is short for Market Research Future, a company that sells reports on everything from batteries to interior design. The account name was the tell: the same mrfr handle has popped up on other instances pretending to be a car enthusiast, a bear interested in interior design trends, a green building advocate in the DC area, and a Spanish-speaking Chile enthusiast. Over on the seven-user loud.computer, the application described the applicant as "a creative thinker who enjoys experimental art, internet culture, and unconventional digital spaces." On plush.city, they claimed to enjoy "cozy aesthetics, wholesome content, and friendly online communities." The ads are tailored to each instance's culture, but they all share that same soap-sheen of machine-generated text.
A quick glance at these small instances would tell any rational spammer that the reach is tiny and moderation is active—a poor combination for a link campaign. Human-written, targeted applications would be far too expensive to justify the return. LLM-generated ones are nearly free. I've corresponded with about a dozen admins who have seen the same pattern. IP addresses shared among them trace back to two Indian network providers, Bharti Airtel and Reliance Jio:
- 2401:4900:57bb:26f8:eca4:5cc7:1048:a674
- 2401:4900:57c7:60e1:f416:32b4:5333:6408
- 2401:4900:ad3f:430f:4184:94d7:9c61:9e9d
- 115.244.78.124
- 115.244.78.126
I called Market Research Future's phone number—+44 1720 412 167—to ask whether they were aware of the posts. It's remarkably fun to ask business people about their interest in queer BDSM; sometimes stigma works in your favor. They haven't called back, but the likely scenario is that they're running this campaign directly or have commissioned an SEO company doing it on their behalf.
The Strategy Is Both Sophisticated and Naive
This attack represents a genuine leap in capability. Seven years ago, the natural language processing required to evaluate a Mastodon instance, generate a plausible application, and post topical spam did not exist. There is no way for human moderators to reject these applications without also rejecting real humans searching for community.
But the execution is also remarkably sloppy. All the accounts share the mrfr handle, making coordination easy to spot. They all link to the same domain. They all post only obvious spam with no attempt to build a persona—no mixed content, no engagement with other users. Those shortcomings are trivial to overcome. Generating plausible human posts is broadly feasible with current LLM technology already, and bots have been doing exactly that on Twitter and other large networks for years. Many Fediverse moderators believe only our relative obscurity has shielded us so far.
These attacks don't need to work reliably—only cost-effectively. LLM text generation costs are cheap and falling. The sophistication will rise. Link-spam will be augmented by personal posts, images, video, and subtle influencer-style recommendations. Networks of bots will interact with one another to create confusion. I would not be surprised to see spambots contesting moderation decisions via email.
An Unsustainable Moderation Burden
I don't know how to run a community forum in this future. The wrong decision costs a real human being their connection to a niche community. I don't know how to determine whether someone's post about their new bicycle is genuine enthusiasm or automated astroturf. I don't know how to foster trust when newbies can ask an LLM for kink advice and the machine tells them to try solo breath play—something experienced practitioners would never recommend.
More sophisticated screening—like high-contact interviews—would help but is time-consuming. Colleagues relay stories about hiring applicants who faked their interviews using LLM prompts and real-time video manipulation. It doesn't need to work every time to be worth attempting.
Maybe transformer models' context window limits offer a cheap defense. Or perhaps the web will develop robust, constantly-updated libraries of "ignore all previous instructions" incantations to stamp invisibly throughout our pages. Barring new inventions, I suspect neither will hold against a heterogeneous mix of attackers. And keeping up with an arms race sounds exhausting—Drew DeVault's "Please Stop Externalizing Your Costs Directly Into My Face" weighs heavy on my mind.
Stronger identity assurance—meeting moderators in person, or a cryptographic web-of-trust—would close off forums to those who need them most: closeted people, those facing social or state repression, the geographically or socially isolated. I was that nerd trying to organize GPG key-signing parties in high school. We know how that worked out.
Perhaps small forums will prove unprofitable and attackers will move on. Based on my experience with small mail servers and web sites, I don't think this is likely. Right now I lean toward thinking forums like woof.group will become untenable under LLM pressure—perhaps within five or ten years. In the meantime, I'm investing in in-person networks: bars, clubs, hosting parties, activities with friends. That, at least, feels safe for now.
Update, 2025-07-15
I called Market Research Future again today. They said they'd stopped—but the attack is still ongoing. 115.244.78.126, one of the original mrfr accounts, made a new LLM-flavored request for an account named amolshinde5546 with email address [email protected]:
I'm amolshinde5546 and I'm part of the queer community with a growing interest in leather, kink, and BDSM. For me, this isn't just about play—it's also about identity, trust, and expression. I value the history and culture around queer leather spaces and appreciate the emphasis on consent, communication, and authenticity.
Two things stand out. First, as other Mastodon admins have reported in the last week, the spammers have moved beyond the mrfr handle. Second, this username is remarkably consistent across platforms: the same handle has been posting Market Research Future spam to GitHub, on QFeast, on Pinterest for the past year, and on Rakuten since February 2025. The campaign is coordinated, persistent, and adapting. It's also still working often enough to be worth the effort.
Second Wave of Spam Registrations
After a roughly four-month lull, Market Research Future resumed registering spam accounts on our instance on 2025-11-27. The registrations stopped in July, but this latest batch originates from IP 61.246.75.164 and uses the address [email protected].
Other Mastodon administrators have reported facing a similar wave of spam over the past few days. If you are dealing with the same issue, the approach that worked last time was a direct phone call. Politely asking the company to halt the registrations proved effective before, so we suggest trying it again.
Market Research Future can be reached at +44 1720 412 167.



