The first StrictlyVC of 2026 hits SF on April 30. Tickets are going fast. Register now.
Save up to $680 on your Disrupt 2026 pass. Ends 11:59 p.m. PT tonight. REGISTER NOW.
Mastodon’s flagship server was hit by a distributed denial-of-service attack on Monday, the social networking software maker said, which rendered the instance unusable at times.
Much of the site was inaccessible, throwing error messages or displaying a full-screen outage warning.
The makers of the decentralized social networking software, which runs its official mastodon.social instance, said in a status update at around 7 a.m. ET on Monday that it was investigating the cyberattack.
By 9:05 a.m. ET, Mastodon said it implemented a “countermeasure against the DDoS attack, and the site is accessible.” However, the company warned that some instability may continue to be seen as the attack is ongoing.
Reached for comment, Mastodon told TechCrunch that, so far, the millions of malicious requests it has seen are consistent with the pattern of a distributed denial-of-service attack. So far, only mastodon.social has been targeted, but its team has deployed countermeasures, and access to the site was restored within a couple of hours of the attack’s start.
“This is a case where the decentralized nature of the Fediverse is a true advantage,” noted Mastodon’s head of communications, Andy Piper. “Users with accounts on other Mastodon (or any other Fediverse) servers were completely unaffected, and in most cases, the outage would have been invisible to them — they have been able to access the network, read and share posts as usual.”
Distributed denial-of-service (DDoS) attacks rely on sending massive amounts of junk web traffic toward an app or website’s servers, with the aim of knocking them offline. These cyberattacks don’t involve data theft, but DDoS attacks can be disruptive to users.
DDoS attacks have become exponentially more powerful over the years. Last year, network security company Cloudflare said it mitigated what it says is the largest DDoS attack to date, measuring a peak of 29.7 terabits per second, the equivalent of filling up thousands of hard drives with data every minute.
When aimed at decentralized social networking services, the attacks can cause instability and outages, but not everyone is taken offline. In Bluesky’s case, for instance, those who had moved their account to other providers, like Blacksky, which run on the same protocol and interoperate with Bluesky, were not impacted.
Similarly, the attack on Mastodon has so far targeted only the larger server (mastodon.social) and not the many smaller instances that make up the full Mastodon social network.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.
StrictlyVC kicks off the year in SF. Get in the room for unfiltered fireside chats with industry leaders, insider VC insights, and high-value connections that actually move the needle. Tickets are limited.
Blue Origin’s New Glenn put a customer satellite in the wrong orbit during its third launch
Sean O'Kane
Palantir posts mini-manifesto denouncing inclusivity and ‘regressive’ cultures
Anthony Ha
‘Tokenmaxxing’ is making developers less productive than they think
Tim Fernholz
Anthropic launches Claude Design, a new product for creating quick visuals
Aisha Malik
Anthropic CPO leaves Figma’s board after reports he will offer a competing product
Tim Fernholz