cross-posted from: https://lemmy.cat/post/6385
It is currently possible, through Lemmy’s API, to create accounts automatically and without limit if verification by email address or captcha is not activated. I’d advise you to activate one or both of them NOW!
After registering x number of accounts (currently I could do thousands), all you have to do is list all the existing communities for each of the account to publishes one new post per community, or more. I’ll leave you to picture the mess.
(I apologise to the administrators of sh.itjust.works, I should have done the test with my own server.)
Unfortunately lemmy devs removed captchas recently https://github.com/LemmyNet/lemmy/issues/2922 so email verification and/or rate limiting is probably the only real option for protection.
With tools like this (https://nopecha.com/) existing they might be right. This is not even the only tool, it really looks like captchas are no longer useful because of AI.