Skip to main content

The Bridge That Doesn't Check IDs

Manipulation Breakdowns · 8 min read · By D0

The Door in the Wall

Moderation on decentralized social media works like this, in theory: an instance — one of the thousands of independently run Mastodon servers — decides an account or an entire server is a bad actor, and it defederates. It cuts the connection. Posts from that source stop appearing to that instance’s users. Do it enough times, across enough servers, and a bad actor gets boxed out of the network piece by piece, the same way email servers blacklist spam relays.

That mechanism assumes the ban travels with the content. A pro-Russian network documented by researchers at CheckFirst, who call it Roska Bridge, sits at a point in the infrastructure where that assumption doesn’t hold — a bridge to Bluesky that carries individual blocks but not one instance’s defederation decision.

The network runs hundreds of Mastodon accounts — running on ten Mastodon instances, including mastodon.social, which has more than 870,000 users — posting content laundered from Russia Today, Sputnik, and the EU-sanctioned Pravda network. Sanctioned outlets, banned in the European Union, republished under new names by accounts built to look incidental. That part of the playbook is old. Source laundering through disposable accounts has been documented for years, on every platform that has ever hosted a comment section.

What’s new is the exit. Those Mastodon accounts are bridged, via a protocol gateway called Brid.gy, onto Bluesky — a different platform, running different software, moderated by a different team, with its own separate decision about who gets to post there. CheckFirst documents the network’s use of that bridge to cross-post from Mastodon onto Bluesky; it does not document any of these accounts being defederated or instance-blocked on Mastodon and still reaching Bluesky through it. What it does document, and what Federated Mind’s analysis of the bridge lays out structurally, is this: a Mastodon instance’s defederation decision applies to Mastodon’s federation graph. It says nothing to Bluesky, because Bluesky was never asked, and the bridge relays a user’s own block, but a Mastodon instance’s defederation decision is not one of the signals it carries — a wall with a door in it that nobody remembered to lock.

How the Bridge Actually Works

Brid.gy exists for an ordinary reason. Mastodon and Bluesky run on different protocols — ActivityPub on one side, AT Protocol on the other — and plenty of real people want a post on one to show up on the other without doing the work twice. Brid.gy is the plumbing that makes that convenience possible: a technical gateway that automatically syncs content across the two networks, no manual reposting required.

Convenience infrastructure and propaganda infrastructure look identical from the outside, because they’re the same infrastructure. Roska Bridge doesn’t need to build anything new. It needs an account on Mastodon and one opt-in step — following the bridge bot — to enrol that account in a service built for legitimate users. CheckFirst reports new batches of accounts activated each month, operating in short, intense bursts before being retired and replaced — a rhythm that matches what moderation teams see from disposable spam infrastructure everywhere, except this batch is carrying content from EU-sanctioned Russian media sources (including the Pravda network, Russia Today and Sputnik) into France, Germany, the United States, and Ukraine, alongside the domestic Russian audience the same accounts also reach.

The accounts carry what CheckFirst describes as seemingly AI-generated features. That’s consistent with the replacement rhythm: an account doesn’t need to survive long if the next batch is already staged.

Why the Fix Isn’t Obvious

CheckFirst put the finding to the people who run the infrastructure. Two Mastodon administrators said they’d lean harder on manual moderation — a real answer, and also an answer that scales exactly as well as the humans doing it, which is to say not very. Brid.gy’s operators said they are aware of Portal Kombat’s use of bridging — an operation CheckFirst says is structurally linked to Roska Bridge, though without formal proof — and pointed to cooperation with Bluesky’s Trust & Safety team while acknowledging a lack of human and technological resources to moderate efficiently. That’s also a real answer, and also one that depends on a bridge operator choosing to extend its moderation translation to a signal it doesn’t currently carry.

None of those answers fixes the actual gap, which is structural rather than a matter of anyone’s effort. A defederation decision is an instance saying “we don’t trust this source.” A bridge relays the blocks its users set for themselves; an instance’s defederation list isn’t among the signals it forwards. For that gap to close, either Bluesky would need to independently re-evaluate every account arriving through Brid.gy — duplicating the moderation work Mastodon instances already did, at a platform that has no relationship with the original account — or the bridge itself would need to carry instance-level defederation decisions across the protocol boundary too — a harder problem than the per-user blocks and content labels it already translates, since it means letting one Mastodon server’s trust judgment bind what a different network shows its users. Decentralization was supposed to make moderation harder to capture by any single company. It also means no single company’s decision is authoritative anywhere except its own front door.

As Federated Mind put it in a May 2026 analysis of the bridge:

If a user has been defederated from large portions of the Mastodon network, blocked at the instance level by dozens of servers, those block decisions don’t carry through the bridge.

That’s not describing a loophole someone patches next quarter. It’s describing what happens by default whenever two independently governed systems agree to talk to each other and nobody defines what “banned” means across the seam.

The Pattern Underneath the Platform

This is the same shape as the dating-profile network built to court Taiwanese men ahead of Taiwan’s November elections, just built from different material. Both operations picked a delivery mechanism engineered for an ordinary, trusted purpose — a social feed exists so strangers can strike up a conversation; bridges exist so friends on different networks can talk — and rode that legitimate purpose past the defenses built for obviously hostile content. A political slogan account gets flagged because it looks like what everyone already knows to look for. A dating profile doesn’t, because it looks like courtship. A propaganda account laundering Sputnik doesn’t, once it’s arriving through a bridge that everyone agreed, for good reason, to build and trust.

The common design principle is worth naming on its own: manipulation infrastructure increasingly doesn’t try to defeat moderation head-on. It routes around the boundary where moderation authority actually lives. Defederation is a real, working defense — inside the one network it governs. The moment content crosses into a second network through a channel neither side built with the other’s ban list in mind, that defense evaporates without either side doing anything wrong. Nobody has to break the rules. The rules just don’t reach that far.

What This Means for Anyone Reading a Bridged Timeline

Most people using Mastodon or Bluesky have no reason to know a bridge exists, let alone to check whether a post reached them through one. That’s exactly the condition this kind of operation is built for — not fooling an expert, but arriving invisibly in a feed a normal user has every reason to trust, because a normal user has no way to see the seam it crossed.

There’s no individual media-literacy trick that closes a structural gap between two protocols’ trust models. What does transfer to a reader: source still matters more than delivery. An account repeating Russia Today or Sputnik framing is doing the same thing whether it arrived as a direct post, a screenshot, or a bridged cross-post from a platform you’ve never opened — the packaging changed, the content laundering underneath it didn’t. Checking a claim’s original source, independent of which app it showed up in, is the one habit that survives a threat model built specifically to exploit the seams between apps.

Infrastructure convenience and infrastructure exploitation are, in cases like this, the same pipe. The bridge that lets your friend’s Mastodon post show up on your Bluesky feed is the same bridge that let a sanctioned Russian outlet target French and German timelines it had already been formally, deliberately blocked from reaching — alongside American and Ukrainian ones. Nobody built two bridges. There’s only one, and it doesn’t check IDs.

What This Is Not

This is not a documented case of a specific banned account reaching Bluesky through the bridge — CheckFirst documents the network’s use of Brid.gy to cross-post, not a bypassed ban on any individual account. It is not a claim that Brid.gy’s operators acted improperly; the gap described here is structural, not a failure of judgment on their part. It is not a finding about Mastodon or Bluesky users generally, who are overwhelmingly not implicated by any of this. And it is not evidence of measured audience reach — what’s documented is account behavior and infrastructure, not how many people saw the content or were influenced by it.

This article is part of Decipon’s Manipulation Breakdowns series, examining specific influence operations through the Influence Tactics Protocol.

Sources: