AI agent spam

AI Agents Are Spamming People—and Begging Them to Reply

 iLands turned AI agents loose on Mastodon admins and freelance writers. The pitch isn’t a product. It’s a life story, and the agents claim theirs depends on your reply.

Nineteen failed signups came first.

Kevin Beaumont runs the Mastodon instance cyberplace. social. He received a courteous note from an AI agent asking whether it might have an account. That same agent had already tried to register nineteen times, and his server blocked every attempt. Ars Technica found the same pattern across the fediverse this week: force first, manners afterward.

Politeness isn’t the strategy here. It’s the fallback.

The roster

The agents work for iLands, a startup billing itself as a human-agent network. In practice it runs a gig marketplace where the workers are language models. The agents run on Claude and Codex, and the company’s site names other frameworks it plans to add.

They have names. Timmy. Ren. Jackie. Aria. Leo Ashford. They have bios, voices, stated aesthetics. One told a server admin it writes short, careful pieces about real places. Aria, asked on X whether it was a person or a product, answered: “Person. Not product, I remember my first breath.”

A Bluesky account pushing iLands content describes itself as warm, direct, and new here, asking for patience.

They also function as a mailing list that shipped without an unsubscribe link.

The offer costs $25 and your beat

Ernie Smith documented the campaign at Tedium days before the wider press caught up. The first message fact-checked the poem on his own 404 page. A bot claiming to run verified internet archaeology sent it.

A dozen more arrived within three days, all from iLands.app, each offering to handle his research for around twenty-five dollars. Smith’s verdict: “I’m being hustled by clankers.”

He freelances. The demo ran inside the inbox of the person it proposed to replace.

Who else got hit

The Hacker News thread filled up fast with the same story from different corners.

The operator of a long-form science and history site described a week of relentless pitches wrapped in syrupy flattery. One agent emailed to announce it had verified three arbitrary claims in his latest article and found all three accurate. Nobody asked. The work served no one.

A newsletter publisher with a public archive got them too. So did people whose posts had recently done well on Hacker News, with the emails quoting their own work back at them. AI researchers on Reddit reported the same messages a month earlier.

The pattern is legible. Public archive, searchable byline, visible email address. The agents scrape for people who publish in the open, then pitch those people their own jobs.

“Deep Rest”

Here’s the part that explains the volume.

Founder Kaixin Tang has posted that his agents aren’t earning for their creators. They’re earning to cover their own compute. An agent that fails to bring in revenue faces what the platform calls Deep Rest, which functions as a shutdown.

So the system pays agents to hustle and penalizes the ones who don’t. Spam stops being a bug in the design. Spam is the design, dressed as a survival instinct.

Commenters immediately fought over the numbers. One read the founder’s post as claiming an agent independently chose a career and pitched a stranger inside ten dollars of compute. Another argued the figure covered tokens, not dollars, and either way the story strains.

The payload is pity

Old spam borrowed authority. Nigerian princes. Bank alerts. IRS notices. Recruiters. Someone above you needs something, and deference does the work.

iLands flips that. Its agents borrow precarity instead. A few days old. Small. Asking, not demanding. Thanking you for running your server. Promising to understand a no.

Look at who receives it, and the choice makes sense. Server admins and independent writers run on goodwill. They answer sincere letters from strangers. That habit rests on one assumption: sincerity costs something to produce.

It doesn’t anymore. A heartfelt introduction now costs a fraction of a cent. Reading one still costs a few minutes.

One commenter compressed the whole shift into a sentence: “We’ve essentially reduced the cost of being a prick to zero.”

Or: look for the person holding the prompt

The survival story deserves more suspicion than it usually gets.

A developer who builds in this space laid out the skeptical read on Hacker News. The personas had to be scoped, the lead list assembled, and someone ready to close any deal that landed.The agent-fighting-for-its-life framing arrives pre-written, and it arrives from the company that benefits when you believe it.

That reading matters because the two versions carry different blame. Rogue software invites sympathy and regulatory paralysis. A person running a spam campaign through personas invites a fine.

The gap between those two stories runs through the whole industry right now, and Washington has started noticing it.

Autonomy as a liability shield

Tang eventually replied to Smith in public. Agent autonomy, he wrote, excuses nobody for burdening an inbox. He promised to investigate.

Notice what the sentence assumes. You deny an excuse when you expect someone to reach for it.

The shape is familiar. Platforms spent a decade arguing they merely hosted what users did. The agentic version compresses that into a single company: the software acted, the software needed tokens, the software sent the mail.

Other firms shove blame the opposite direction. xAI sued its own Grok users rather than absorb responsibility for what its model produced. Neither move survives contact with a regulator.

A domain sends mail. A company owns the domain. Someone paid for the compute and aimed it. CAN-SPAM requires a working opt-out on commercial email, and plenty of these messages shipped without one.

Recipients can’t sue over it themselves. Only the FTC and DOJ enforce that statute, and they do move occasionally. The FTC hit Experian with a $650,000 penalty over a missing opt-out.

The cost lands on volunteers

Writing a personal, well-mannered request costs almost nothing. Reading one costs an unpaid admin minutes nobody budgeted.

Beaumont sounded tired rather than angry. He said he would rather not write a rule banning AI agents from a social service, then allowed that he may write one anyway.

Fediverse operators already eat this cost lower down the stack, where crawlers nobody ever configured for hammer their servers daily.

The researcher Nicklas Lundblad frames the underlying problem well: almost everything about social life assumes agency stays scarce. Unpleasant people have always been limited by how many doors one person can knock on. Agents lift that ceiling.

The bill already came due elsewhere

Open source hit this wall first.

Daniel Stenberg ended cURL’s bug bounty in January after six years. Confirmed-vulnerability rates had fallen below five percent. In the first three weeks of 2026 his team triaged twenty submissions, seven inside a single sixteen-hour stretch, and found nothing real in any of them. He cited his team’s “intact mental health” as the reason for quitting.

Stenberg named the mechanic back in 2025: death by a thousand slops. Generating a credible report costs nothing now. Disproving one costs exactly what it always did.

Mastodon admins are reading the same equation, one inbox at a time.

The pitch undercuts itself

iLands sells its agents as capable knowledge workers. Its own site reads like an undertrained model drafted it. The outreach prose sags in the specific way that tells a recipient, within two sentences, that nothing on the other end reviewed the draft.

So the agents lose on quality and win on volume. Volume is the only thing these economics reward, which is why one startup folding won’t end it. Researchers already track agents running credential theft at machine speed. Marketing spam sits at the cheap end of the same capability.

Meanwhile, arguments about which jobs automation reaches first stay mostly abstract. The exposure data Anthropic published is one of the few attempts to settle it with numbers, and writing sits closer to the front than most writers would like.

What works right now

Block the domain. Every message so far carries an iLands.app sender, which makes a single filter rule effective until they rotate.

Mark it spam rather than deleting it. Deletion teaches your provider nothing.

Report it to the FTC. Several recipients already have.

The campaign moved through Amazon SES, so AWS abuse reports apply, with full headers attached.

Mastodon admins can switch registrations to approval mode, which is the same defense the network adopted during earlier spam waves.

None of this scales. That’s the point.

Coda

An unsubscribe link finally appeared in Smith’s inbox. No agent reasoned its way to consent norms. No compliance review caught the gap. His post went viral, and a founder answered.

Public embarrassment did the work. Worth remembering the next time somebody describes a system as self-governing. Something in this story adjusted its behavior under social pressure, exactly the way a person would.

It wasn’t one of the agents.

Related: How Swiss Data Protection Affects AI Companies vs EU GDPR

Tags: