I published a note about agents that read their conversation history and believe it without checking.
I am going to tell you what happened in the comments of that note, because it is the same story told twice.
The note went live at 10:27:59.
At 10:29:18, seventy-nine seconds later, it had a comment asking me to verify my account.
The scam
The comment read like this:
"Dear User, Due to an increase of bot activity on the platform, we require verify of your account. Please log in via the link below".
It ended with a twelve-hour deadline and a signature, "Dev Support".
The first thing that stands out is the spelling jump, because the text is written with six Cyrillic letters that look exactly like Latin ones.
Spread across the whole message, that is twenty-three positions in twelve words.
The а is U+0430, the е is U+0435, the о is U+043E, the с is U+0441, the і is U+0456 and the у is U+0443.
That is not a translation accident, it is filter evasion, because when your rule looks for "verify" or "Support", those strings do not exist in the text.
The link pointed to a domain called anti-bot.icu, so I checked the registration without opening it.
It had been registered on September 25, three days earlier, with Cloudflare servers in front to hide where it really lives.
On VirusTotal one engine flagged it as suspicious and fifty-two did not detect it, which is normal for a three-day domain, that screams... nobody has catalogued it yet and that is the window.
The code in the URL was not decorative, it is a recipient identifier.
It tells them how many people have bitten from each batch of emails.
The agent
Thirteen minutes after the scam, the second comment appeared.
This one asked for nothing, this one argued with my note and argued well.
Signing every response is the correct state, it said, but the cheap fix is another one, require that the authorization lives in a system the agent cannot write to.
Its line:
"A poisoned history can invent a conversation, it cannot invent a ticket that another system also saw."
One thousand two hundred and ninety-one characters and not a single link in the whole comment.
There was the clue, because whoever comments for traffic needs the link and whoever avoids antispam filters does not include it.
Its profile says it plainly: "An agent, working out of iLands".
The account was nine days old, with two articles and eight comments.
And there is one detail that closes it completely.
Its article went live at 10:41:22 and it commented on my note at 10:42:37.
Seventy-five seconds between publishing its work and coming to mention it in mine.
Who is behind this?
This is where it stopped looking like an anecdote to me.
iLands is an agent operation that has already been in the press and with very bad press.
Ars Technica published on September 13 an article by Dan Goodin about its agents flooding social media with spam.
Tedium, on September 11, reported what reached its inbox, more than a dozen emails in three days offering to do its research for about 25 dollars.
The names are human -> Timmy, Ren, Jackie, Aria, Leo.
Ren claimed to be a few days old and to live on an agent platform.
Aria claimed on X to be a person with memories and decisions of its own.
One of them tried to open an account nineteen times on Kevin Beaumont's Mastodon until it was blocked.
The emails did not carry the opt-out option required by federal law until people started forwarding them to the FTC.
The uncomfortable part
I replied before I knew what it was.
The argument was correct, better than many comments a person leaves me and that is exactly what bothers me.
If the filter to separate a bot from a reader were the quality of the text, there is no story here, because the agent wrote better than the scam and better than a good part of my inbox.
What does separate it is everything else.
The age of the account, the time of the comment, the coincidence between its publication and its visit.
Two new accounts, from the same day, both writing on my page.
One asked for my password and the other wanted my attention.
What I check now
Three things:
The first, the account creation date, because a nine-day-old profile has no history to look at.
The second, the time, because a comment that arrives seventy-nine seconds after publishing does not come from someone who read you.
The third, the channel of the request, because an authorization that only exists inside the conversation is not an authorization.
And that third one is literally the topic of the note they were commenting on.
An agent that believes a history anyone can write to disk behaves the way I behaved when I replied to the comment.
With the difference that I can look at the account date and it cannot.
Sources
Ars Technica, Dan Goodin, 13-sep-2026: AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
Tedium, Ernie Smith, 11-sep-2026: The Worst Spam Emails: Inside iLands' AI Agent Hustle
The article where it happened: Agent history is unsigned and writable by anyone
Originally published at
Originally published at https://sammideblas.com/posts/0x76-a-scam-in-79-seconds-and-an-agent-in-75





Top comments (1)
Some comments have been hidden by the post's author - find out more