
Over the past few years, the Ecency free account creation service has been hacked by what appears to be an SEO botnet. Thousands of accounts have been created (Ecency received regular investigation reports). Regardless of some fixes implemented, this cybersecurity threat has not been prevented.
This mass, automated SEO spam is generally considered a cybersecurity threat. It abuses the Hive ecosystem's free account creation service (via Ecency) - deceptive and unauthorised activity.
It is not just a low-level cybersecurity threat because many backlinks published by these accounts are possible phishing links. As shown in this example:

Some other examples of these SEO spam accounts:


THE SAME PATTERN:
- An account is created using Ecency's free account creation service.
- Basic contact details are added in the account description. Sometimes the cover image is added and/or the avatar.
- While some of the accounts never publish anything, most tend to publish a single AI-generated post or comment that includes a backlink to a certain website (business, online casino, app, organisation, blog, etc).
- The content formatting is a cookie-cutter template.
THE THREAT ACTOR USES AN ADVANCED AUTOMATION TOOL THAT RUNS A COMPLEX SCRIPT
How this SEO botnet operates:
The bot script uses disposable email services (like Mailinator) to read emails with verification codes and verify the accounts.
CAPTCHA
It is cracked by using a bot that uses CAPTCHA-solving services - the puzzle/image is forwarded to human workers. These services are usually based in developing countries with a very low minimum wage. These "workers" solve dozens of CAPTCHA for a fraction of a US dollar.
It is possible that the hacker also uses AI tools trained to solve puzzles or visual patterns. That would likely require more computing/hardware power (and cost).
IP DECEPTION
The hacker may use automated services that lease IP addresses from some residential internet connections, tools that circulate through thousands of VPN nodes, or which rotate IPv6 addresses from cheap Virtual Private Server providers.
It might also happen that the botnet is using devices infected with certain malware that runs those scripts. It is also possible that some installed programs or applications secretly run scripts that use the device's bandwidth.
This would explain why different IPs are used for these accounts.
AI CONTENT
The script uses Large Language Models like ChatGPT or DeepSeek to generate posts and comments. These types of bots have been a common activity on Hive (the most famous bt that spams "waivio" tag).
THE SOLUTIONS THAT I SUGGESTED THAT MAY POSSIBLY FIX THIS:
- Adding phone verification.
- Switch to more complex and advanced CAPTCHA like Google reCAPTCHA v3 or Cloudflare Turnstile.
- Using a stronger email reputation check.
Currently, Ecency has only email verification and basic CAPTCHA.
This may not completely prevent this malicious actor, but it would frustrate its activity and force the hacker to use more hardware resources.
ESPAÑOL:
En los últimos años, el servicio de creación de cuentas gratuitas de Ecency ha sido hackeado por lo que parece ser una red de bots de SEO. Se han creado miles de cuentas (Ecency recibía informes de investigación con regularidad). A pesar de algunas medidas correctivas aplicadas, no se ha logrado evitar esta amenaza para la ciberseguridad.
Este spam SEO masivo y automatizado se considera generalmente una amenaza para la ciberseguridad. Abusa del servicio de creación de cuentas gratuitas del ecosistema Hive (a través de Ecency), lo que constituye una actividad engañosa y no autorizada.
No se trata solo de una amenaza de ciberseguridad de bajo nivel, ya que muchos de los enlaces externos publicados por estas cuentas son posibles enlaces de phishing.
EL MISMO PATRÓN:
- La cuenta se crea mediante el servicio gratuito de creación de cuentas de Ecency.
- Se añaden datos de contacto básicos en la descripción de la cuenta. A veces se añade la imagen de portada y/o el avatar.
- Aunque algunas de las cuentas nunca publican nada, la mayoría tiende a publicar una única entrada o comentario generado por IA que incluye un enlace a un sitio web determinado (empresa, casino online, aplicación, organización, blog, etc.).
- El formato del contenido es una plantilla estandarizada.
EL ACTOR MALICIOSO UTILIZA UNA HERRAMIENTA DE AUTOMATIZACIÓN AVANZADA QUE EJECUTA UN SCRIPT COMPLEJO
Cómo funciona esta red de bots de SEO:
CORREO ELECTRÓNICO
El script del bot utiliza servicios de correo electrónico desechables (como Mailinator) para leer los correos electrónicos con códigos de verificación y verificar las cuentas.
CAPTCHA
Se descifra mediante un bot que utiliza servicios de resolución de CAPTCHA: el rompecabezas o la imagen se reenvía a trabajadores humanos.. Estos servicios suelen estar ubicados en países en desarrollo con salarios mínimos muy bajos. Estos "trabajadores" resuelven decenas de CAPTCHA por una fracción de dólar estadounidense.
Es posible que el hacker también utilice herramientas de IA entrenadas para resolver rompecabezas o patrones visuales. Esto probablemente requeriría mayor potencia de procesamiento/hardware (y, por lo tanto, mayor costo).
ENGAÑO DE IP
El hacker podría utilizar servicios automatizados que alquilan direcciones IP de conexiones residenciales a internet, herramientas que circulan a través de miles de nodos VPN o que rotan direcciones IPv6 de proveedores de servidores virtuales privados (VPS) económicos.
También podría darse el caso de que la botnet utilice dispositivos infectados con cierto malware que ejecuta estos scripts. Asimismo, es posible que algunos programas o aplicaciones instalados ejecuten secretamente scripts que consumen el ancho de banda del dispositivo.
Esto explicaría por qué se utilizan diferentes direcciones IP para estas cuentas.
CONTENIDO DE IA
El script utiliza modelos de lenguaje complejos como ChatGPT o DeepSeek para generar publicaciones y comentarios. Este tipo de bots ha sido una actividad común en Hive (el bot más famoso que envía spam con la etiqueta "waivio").
SOLUCIONES QUE SUGIERO PARA POSIBLEMENTE SOLUCIONAR ESTO:
- Agregar verificación telefónica.
- Cambiar a CAPTCHA más complejo y avanzado como Google reCAPTCHA v3 o Cloudflare Turnstile.
- Usar una verificación de reputación de correo electrónico más estricta.
Actualmente, Ecency solo tiene verificación de correo electrónico y CAPTCHA básico.
Esto podría no detener por completo a este actor malicioso, pero dificultaría su actividad y obligaría al hacker a usar más recursos de hardware.
You can browse the Hivewatchers blacklist here to browse these accounts.
ES: Puedes consultar la lista negra de Hivewatchers aquí para ver estas cuentas.
https://hivewatchers.io/blacklist-search
https://promote.hive.io/metrics/onboarding/blacklisted
Top image by thepeakstudio.
From what it looks, a legitimate business that decides to create a Hive account might be blacklisted for SEO spam, right?
I have a google business profile account for my business and I post AI generated content there. I ask an AI to write a post about a certain job I did, or a certain interesting topic I came across in my job. I provide the information and the AI writes the post for me. All businesses do this nowadays. Not only on google, but also facebook, instagram, yelp, angies, etc.
In the end it's all about digital marketing and SEO is part of it.
So how do you filter the real legitimate businesses that are interested in blogging on Hive like they also do in other platforms?
Your comment has no logical connection.
6 months ago, I had already mentioned that it would be better if you learned what SEO spam is and why it affects Hive.
Since you keep suggesting that "legitimate" businesses come to Hive to create these accounts, you can email those from the list above and ask.
I stand by what I said, it's great that you got the screenshot.
If it's a bot creating a lot of accounts to point to the same link, then I agree it's spam. But if it's only one account for one business, then it's not SEO spam, it's just digital marketing, same as it's done in other social medias. If you don't separate the spam from the real businesses, then this will probably drive more real people away from Hive.
Ask AI what SEO Spam is.
Appreciate the writeup, but the central premise doesn't hold up and misleading.
We act on your reports. We don't just receive them - we work them: we look for the pattern behind these accounts and close the gaps iteratively. We closed another one from your recent reports today, in mattermost chat we talked about this. Framing this publicly as an unaddressed "threat" on the same day we were acting on your reports misrepresents what is an ongoing, working collaboration.
There's no SEO incentive. Ecency noindexes content from new accounts - search engines are told not to index it, and links from non-indexed pages pass no ranking value. Whatever this actors attempts, they get zero SEO benefit through Ecency. "SEO spam botnet that hacks Ecency" describes a payoff that doesn't exist.
"Hacked" is wrong. No vulnerability, no breach, no unauthorized access - a free onboarding service used at scale is abuse of a public service, not a cybersecurity incident. And by your own analysis this is a single actor with a repeating signature (new account → one templated post → outbound link → abandoned), which is the opposite of a distributed "botnet."
On our controls: the post says we have "only email verification and basic CAPTCHA." Not accurate. We run email verification, VPN/Tor detection, and IP quality checks at signup, alongside CAPTCHA - the IP-rotation theory in your post is exactly what those checks exist to catch. You can check our recent transparency report on how many of those never pass our checks. https://ecency.com/@ecency/ecency-operational-transparency-infrastructure-insights
Where you have a real point: if some links are phishing, that's a genuine user-safety issue - but it's moderation, not an "SEO botnet." A consistent signature is detectable, and first-post-with-outbound-link is the proportionate place to tighten. Not phone/ID verification, which conflicts with our no-biometric stance and punishes every legitimate new user for one spammer.
One clarification: "any account created via the faucet is doing spam" isn't true - the faucet onboards real users daily. If you mean the spam accounts came through the faucet, that's fair and far narrower.
If a gap is still open, the fastest path to closing it is the channel where you were reporting weekly, this post doesn’t help.
Congratulations @hivewatchers! You have completed the following achievement on the Hive blockchain And have been rewarded with New badge(s)
Your next target is to reach 10000 replies.
You can view your badges on your board and compare yourself to others in the Ranking
If you no longer want to receive notifications, reply to this comment with the word
STOPCheck out our last posts:
Exploited would be more accurate than hacked.
Could be borderline between both but I consider this hacking becsuse the threat actor uses knowledge to create the script that exploits vulnerability - bypasses phone, ip and captcha checks to mass create spam accounts. Even if it's script kiddie who uses someone else's script or tool.
Yet nothing was hacked or compromised, just exploited weaknesses.
Hacking doesn't need to compromise anything. Any exploitation of certain weaknesses in the system/app/program/hardware is a hack.