Bluesky Hit by Another DDoS Attack, the Second in Four Months

Bluesky confirmed on Monday, August 18, 2026, that a day-long service disruption affecting its platform was caused by a distributed denial-of-service (DDoS) attack. In a post on its own platform, the company said the attack had taken place over the previous 24 hours and that it had "upgraded our defenses in response, and we continue to monitor the situation" TechCrunch.
A DDoS attack works by flooding a target's servers with so much junk traffic that legitimate users can't get through. Think of it as a crowd of people deliberately blocking the entrance to a store so real customers can't enter.
According to a report in the IFIN public forum, Iran-backed attackers claimed responsibility for the DDoS attack TechCrunch. A Bluesky spokesperson did not immediately respond to TechCrunch's questions about the attack.
This is not the first time Bluesky has been targeted. In April 2026, the platform was hit by a prolonged series of outages caused by a similar flood of web traffic. The first intermittent app outages were reported at approximately 11:40 PM PDT on April 15, caused by a DDoS attack that intensified over time Bluesky Blog. Bluesky engineers worked through the night to mitigate what the company described as a "sophisticated" DDoS attack The Record. A pro-Iran hacker group also claimed responsibility for that April disruption Security Affairs.
The April attacks did not end after a single day. Bluesky reported that its application remained largely stable from the evening of April 16 onward, despite an additional DDoS attack on the afternoon of April 20 Bluesky Blog. The company published multiple service interruption updates between April 16 and April 20, keeping users informed as its engineering team worked to absorb ongoing traffic floods.
The August 18 attack follows a recognizable pattern: a sustained DDoS campaign, a pro-Iran group claiming credit, and Bluesky responding with infrastructure upgrades rather than a fundamental architecture change. The company's statement that it "upgraded our defenses" is notably similar in spirit to its April posture, where engineers mitigated traffic in real time without disclosing the specific mitigation strategies employed.
The repeated nature of these attacks raises a straightforward operational question. DDoS mitigation is a well-understood problem with mature commercial solutions, from Cloudflare-style edge proxying — where a third-party service sits between the attacker and the target, filtering out malicious traffic before it reaches the server — to scrubbing-center services that divert suspicious traffic to specialized facilities for cleaning. Bluesky's federated architecture, built on the AT Protocol, distributes identity and data hosting across personal data servers (PDS instances), but the relay and app-view layers that aggregate and serve content to users remain centralized. That centralization creates a concentrated target for volumetric attacks in a way that a more fully decentralized content-delivery path might not.
Worth flagging is that Bluesky has now disclosed two major DDoS events within a four-month window, both attributed to the same category of threat actor. Whether the August attack was carried out by the same group responsible in April has not been confirmed; the IFIN forum report attributes the claim to Iran-backed attackers, but Bluesky has not independently verified that attribution. The company's public statements address the mechanism (junk traffic overwhelming the service) and the response (defense upgrades), not the identity or motive of the attackers.
For the platform's user base, the practical impact is repeated availability gaps during peak-usage windows. DDoS attacks of this nature do not compromise user data or breach backend systems; they deny service by saturating bandwidth and connection-handling capacity. The risk is operational disruption and erosion of user confidence in platform reliability, not data exposure.
Bluesky has not disclosed whether it is working with a third-party DDoS mitigation provider or handling traffic filtering internally. In April, the company characterized the attack as "sophisticated," a label that suggests the traffic patterns were crafted to evade standard rate-limiting and signature-based filtering. The August 18 attack's effectiveness in producing a day-long disruption suggests the upgraded defenses from April either were not sufficient to absorb this volume or that the attack vector differed enough to bypass existing mitigations.
The broader context here is that Bluesky occupies a growing niche as an alternative to centralized social platforms, and its visibility makes it a target. DDoS campaigns against social platforms are not new; what is notable is the recurrence interval. A four-month gap between major volumetric attacks, both claimed by Iran-aligned groups, suggests either a sustained operational interest in disrupting the platform or a low-cost, repeatable attack method that existing defenses have not fully closed off. Bluesky's ability to maintain service through subsequent attacks will depend on whether its infrastructure investments outpace the attack capacity of its adversaries.


