Posted by therealmorticia
https://www.transformativeworks.org/spambot-comments-on-ao3/
https://www.transformativeworks.org/?p=282739
NOTE: This is a living document and will be updated in response to changes and new types of spam as observed by OTW volunteers.
LAST UPDATED: March 30, 2026
As AO3 continues to grow, there has been an increase in the amount and variety of spambots that attempt to harass or scam users. Spambots may try to imitate other users and even AO3/OTW volunteers to appear more realistic. This post shares a brief update on how we’re working to combat this issue, what types of spam we’ve seen, and what you can do if you encounter spam comments on AO3.
What We’re Doing
Protecting our users from scammers and bots targeting AO3 is important to us, and we are actively working to combat spam on the site in a variety of ways—both visible and not. We will not share a detailed list of every change we’ve made (so as to not provide spammers with information about how to circumvent these measures), but some examples include introducing comment rate limits for logged-in users, changing the default comment setting on new works to “Registered users only”, spam checking comments and comment edits from new users, and making a variety of improvements to the admin tools used by our Policy & Abuse volunteers to handle reports and remove spam comments.
We continue to consider and undertake additional technical changes to help prevent and improve our response to spambots. However, it is important to us that any anti-spam measures we implement do not substantially harm users who are browsing or attempting to comment normally. Many more aggressive anti-spam measures would make AO3 less accessible, particularly for users using assistive devices such as screen readers.
In addition to taking technical steps to help address the issues, we continue to post updates about spambots and other important changes to AO3 on our Tumblr, Bluesky, and Twitter/X. We encourage you to follow us on these platforms to stay informed about what’s going on.
Types of Spam Comments
Below is a list of different types of spam comments that have been posted on AO3 over the last year. We intend to maintain this list and add new types of spam to it as they are identified; however, this list may not include every type of spam comment that could possibly be received. We encourage you to remain vigilant and follow internet safety best practices.
If you’re not sure if something is a spam comment, you’re welcome to contact Policy & Abuse for assistance. Before doing so, we encourage you to click through the links below to learn more about each type of comment and use your best judgement to determine if a comment appears to be genuine or could be a scam.
- Art Commission Spam: These comments come from both guests and registered accounts who pretend to be artists who want to make comics or illustrations for your fanfic. They may ask questions or praise your work to try and get you to reply to them, before convincing you to contact them off AO3 (often via Discord). They will try to scam you into paying for their art, which is either AI-generated or does not exist at all. (First reported August 2024, news post published December 2024)
- Deprecated Fandoms Spam: These guest comments claim that AO3 will be “deleting works to conserve server space”. There is no such thing as a deprecated fandom and there is no limit on the number of fanworks that can be posted to a specific tag. (First reported May 2025, Tumblr announcement May 2025)
- AI Use Accusation Spam:: These guest comments will accuse you of using AI in your work. They may mention a particular AI generator or AI detection service, or claim that they “saw you remove the AI prompts from your work”. (First reported April 2023, Tumblr announcement November 2025)
- Harassing Spam: These guest comments will accuse you or another user of promoting discriminatory beliefs, deceiving fans, or similar behaviors. They often suggest that you “consider adding more diverse characters” to “repair the trust you’ve lost with your audience”. (First reported October 2025, Tumblr announcement November 2025)
- Praise and Unsolicited Suggestions Spam: These guest comments will compliment your writing but then offer ridiculous suggestions for how to make your work better. Similar to the harassing spam, they may ask you to add a minority character to your work or threaten to publicly expose you if you don’t do what they want. (First reported October 2025)
- Special Character/Keysmash Spam: These comments are usually long and consist entirely of emojis or nonsense, keysmash-style sequences of characters from a variety of non-Latin scripts or languages (e.g., Chinese, Cyrillic, Thai, etc). (First reported November 2025)
- Reporting To Authorities Spam: These guest comments threaten to report you or your work to the authorities or your employers. They also may allege security concerns like your email being compromised or spyware on your computer. (First reported December 2025, Tumblr announcement December 2025)
- Disparaging Spam: These guest comments insult you or your writing, claiming that you “wasted your talents” or “have no life”. They may also threaten suicide or tell you to delete your work. (First reported December 2025)
- PowerShell Spam: These comments present you with a piece of code to enter into your computer’s terminal/command line. While they claim that the purpose of the code is for your protection or security, the code in these comments would actually delete all documents from your hard drive. (First reported January 2026)
- Doxxing Threat Spam: These guest comments claim that they know where you live, have seen you in person, and/or threaten to meet you face-to-face. They often say that they have or will post your personal information (name, address, etc.) online or that they are stalking you in real life (e.g. “left a gift in a briefcase near your house”). (First reported January 2026, Tumblr announcement January 2026)
- Spam Impersonating OTW Volunteers: These guest comments claim to be AO3/OTW volunteers and say that there has been a data breach or that AO3 and other sites (such as Reddit) have been sending out fraudulent password reset emails. (First reported January 2026, Tumblr announcement February 2026)
- Downtime Spam: These guest comments claim that the March 2026 AO3 downtime was caused by hackers and AO3 has a virus that will destroy your device, and encourage reformatting your device or deleting all your works. (First reported March 2026)
None of the accusations these spam comments make are true. The bots are merely spamming false accusations in order to alarm or harass AO3 users. It is generally safe to ignore these comments once you’ve removed and/or reported them as outlined below.
What You Can Do
Do not engage in conversation with spam commenters. Do not provide your email or social media contact information to a commenter who asks for it. Scammers try to get you to talk to them privately, because it is often easier to deceive or manipulate people in a one-on-one conversation.
Do not click on any links, run any code commands on your computer, or search out and harass any users named in these comments. Scammers often copy the username of a real AO3 user on their guest comments to make them look more real. Pay attention to the “(Guest)” indicator which will appear next to the name of anyone who comments while not logged in.
For spam comments on your own work, the best way to handle them depends on whether they are from registered accounts or guests. Refer to the instructions below on how to handle Spam from a Guest User or Spam from a Registered Account.
If you see a spambot comment on someone else’s work, you can report the comment as spam to Policy & Abuse (even if it’s a guest comment) as you would a comment on your own work. You can also let the creator know the comment is from a bot and that they should mark it as spam.
Please don’t report comments that have already been deleted. As part of handling a report about spam comments (whether from guests or registered accounts), we will remove other comments made by the same bot. If the comments have been deleted, the bot has already been actioned and no further reports are needed.
Spam from a Guest User
If you receive a spambot comment on your work which is posted by a guest:
- Go directly to the comment on your work, either by clicking on the link in your email or in your AO3 inbox.
Note: The “Spam” button only appears when viewing a guest comment directly on your work. This is because the AO3 comment inbox is merely a copy of the work’s comments—deleting a comment from your AO3 inbox does not delete the comment from the work itself.
- Click on the “Spam” button to mark the guest comment as spam, remove it from your work, and help train our automated spam-checker to reject similar spam comments in the future.
Note: Marking guest comments as spam does not submit a report to the Policy & Abuse committee, but unless you are receiving dozens of guest spam comments in a short time period, there is no need to submit a separate report.
To prevent future guest spam comments, you may also want to consider disabling anonymous commenting or restricting your work to registered users only.
If you are reporting multiple guest comments, please submit only one report and include all comment links in your report description. (You can get the direct link to a specific comment by selecting the “Thread” button on the comment and copying the URL of that page.)
If you are receiving dozens of guest spam comments in a short time period, we recommend turning on comment moderation and providing us with a link to the unreviewed comments section of the affected work(s) instead of reporting the comments individually.
Spam from a Registered Account
If the spam comment is posted by a registered AO3 account:
- Select the “Thread” button on the spam comment. This will take you to the specific comment page.
- Scroll to the bottom of the page and select Policy Questions & Abuse Reports.
- In the “Brief summary of Terms of Service violation” field, enter “Spambot”.
- In the “Description of the content you are reporting” field, enter “This is a spambot, their username is USERNAME.” (replace USERNAME with the account’s actual username)
- Optionally, you may also choose to block or mute the account.
Please don’t report multiple spam accounts in one report. Each account is actioned separately and listing more than one account per report delays our response to you.
Closing
In general, please follow internet safety best practices and be cautious of unsolicited advertisements or harassing comments on your work. For some advice on other ways you can protect your AO3 account, take a look at this internet security guidance from our Policy & Abuse volunteers.
https://www.transformativeworks.org/spambot-comments-on-ao3/
https://www.transformativeworks.org/?p=282739