Introduction
Decentralized social media was built on a promise: no single company should get to decide what the world reads. Mastodon spreads that decision across thousands of independently run servers. Bluesky spreads it across an open protocol anyone can build a client or a moderation service on top of. Neither wants a single point of failure, and neither wants a single point of control. That’s the pitch, and it’s a good one.
It’s also, as of July 2026, a gap wide enough to drive a propaganda operation through. Researchers at CheckFirst published a report on July 2 documenting what they call Roska Bridge — a pro-Russian information manipulation set that has spent at least ten months laundering sanctioned Kremlin media through hundreds of accounts spanning two separate decentralized networks, using nothing more exotic than a small open-source tool built to let Mastodon and Bluesky users talk to each other. No exploit. No breach. Just a very precise reading of who, exactly, is supposed to be watching the space between two platforms that were each designed to answer to no one in particular.
What Roska Bridge Actually Does
The mechanics start with a real, useful, entirely legitimate piece of software called Bridgy Fed, run at the domain brid.gy. It exists to solve an honest problem: Mastodon runs on a protocol called ActivityPub, Bluesky runs on a different one called the AT Protocol, and without a translator, a post on one network simply doesn’t exist on the other. Brid.gy is that translator. A Mastodon account can opt in, and from then on its posts are automatically mirrored to a corresponding Bluesky account, and vice versa, in something close to real time.
CheckFirst found hundreds of Mastodon accounts, spread across at least ten separate Mastodon instances — including mastodon.social, the largest server in the network with more than 870,000 users — bridged outward into hundreds of matching Bluesky accounts. New batches get activated roughly monthly. The accounts carry what researchers describe as seemingly AI-generated features. Their output is not original commentary. It’s Kremlin media, laundered and rebroadcast: content traced back to the EU-sanctioned Pravda network, Russia Today, and Sputnik, alongside promotion of Max, the Russian state-backed messaging app the Kremlin has been pushing as a domestic alternative to Western platforms. CheckFirst’s assessment goes further: the operation’s infrastructure and content patterns “strongly suggest a structural link” to Portal Kombat, the sprawling pro-Russian website network France’s VIGINUM first documented in February 2024 — a caveat worth taking as seriously as the finding itself, since the researchers are explicit that this is a structural resemblance, not a signed confession.
The Seam, Not the Platform
Here is the part that makes this worth a separate entry in the catalogue of Kremlin-aligned information operations, rather than a footnote to ones already documented. Every individual platform in this chain has its own moderation. Mastodon instances are run by admins who can suspend accounts or defederate from bad-acting servers entirely. Bluesky has its own moderation stack, plus a marketplace of independent labeling services users can subscribe to. Both ecosystems take moderation seriously enough to have built real tooling for it.
None of that tooling was built with the other network in mind. A Mastodon admin who suspends an account on their own server has no lever to reach into Bluesky and pull down the bridged copy sitting there, still posting, still bridged, entirely untouched by a moderation decision made one protocol over. The reverse is equally true. Brid.gy sits in the middle, translating content across that boundary, but it isn’t a moderation layer for either side — it’s a small, largely volunteer-run bridge, and its own creators have said as much directly, acknowledging what CheckFirst characterizes as a lack of the human and technological resources needed to moderate content passing through it efficiently. Nobody built this bridge to be watched. Somebody built it to work.
That’s the actual finding, more than any single account or post: content laundering isn’t new, and cross-posting bots aren’t new, but a moderation gap that exists specifically between two protocols with mature, independent moderation systems of their own is a structural feature nobody thought to defend, because defending it would mean one network’s moderators policing content that technically originates on a network they have no authority over.
The Laundering Chain
Roska Bridge’s content doesn’t originate as raw RT or Sputnik copy dropped straight into a Mastodon post — that’s crude enough that some instances already block sanctioned domains outright, and readers have gotten faster at recognizing a masthead. It runs through an intermediary layer first. Portal Kombat’s constellation of ostensibly independent regional news portals — VIGINUM counted at least 193 of them in 2024, a figure that had grown to 224 by the time EDMO checked back in — exists precisely to strip the Pravda-network byline off Kremlin content and re-present it as local reporting. That’s laundering pass one.
Roska Bridge appears to be laundering pass two. Content that has already been washed through an ostensibly independent news portal gets a second wash through hundreds of ostensibly independent personal social accounts, each with the texture of an individual poster rather than a media outlet, each cross-posted automatically to double the network’s footprint per account created. By the time a reader on Bluesky sees a post, it may be three steps removed from Sputnik: state media to Portal Kombat portal to bridged personal account. Each step is a plausible, ordinary-looking piece of internet furniture. None of them, taken alone, looks like a state information operation. That’s the design.
The Burst-and-Vanish Pattern
The accounts don’t sit and post steadily. CheckFirst describes a pattern of short, intense bursts of activity followed by accounts disappearing, replaced the following month by a fresh batch. That cadence isn’t incidental — it’s load-bearing.
Federated moderation, on both Mastodon and Bluesky, generally depends on reports and review: a post gets flagged, an admin or a labeling service looks at it, a decision gets made. That pipeline takes time, even when it works well. An account that posts hard for a short window and disappears before the review cycle catches up doesn’t get moderated so much as it gets outrun. By the time anyone has built a case against last month’s batch, it’s gone, and a new one bridged from a new instance has already taken its place. Suspending an account after it’s already vanished closes a door nobody’s using anymore. The operation isn’t hiding from moderation. It’s simply faster than the review clock.
What This Is Not
This is not a claim that Brid.gy is complicit, negligent in bad faith, or built as an evasion tool. It’s an open-source bridge, run largely as a volunteer effort, doing exactly the interoperability job it was designed to do — its own team’s acknowledged lack of moderation capacity is a resourcing gap, not a cover story. Plenty of legitimate accounts use the same bridge for entirely ordinary reasons. The vulnerability here belongs to the seam between two governance models, not to any one party’s intentions.
This is also not evidence that decentralized social media is more dangerous than the centralized alternative. Centralized platforms have their own well-documented history of coordinated inauthentic behavior at far larger scale — this platform has covered Spamouflage networks operating on Facebook and X in prior breakdowns, and nothing about federation makes manipulation more likely in the abstract. What federation changes is the shape of the vulnerability: instead of one company’s trust-and-safety team owning the whole problem, the problem now lives partly in a gap between two teams, neither of which owns it alone.
And this is not the same mechanism as The Last Hop, which examined Storm-1516’s use of a credible human amplifier — a sitting vice presidential candidate — to launder a fabricated story into mainstream reach. That operation ran on borrowed human credibility. Roska Bridge runs on borrowed protocol architecture. Both are Kremlin-aligned information operations by the researchers’ own framing; they are not the same tool, and treating “amplification via a trusted person” and “amplification via an unmoderated technical seam” as one undifferentiated category would erase the distinction that makes each one detectable on its own terms.
Finally, CheckFirst’s own hedge deserves to be repeated rather than smoothed over: a structural link to Portal Kombat is not formal proof of one. Shared infrastructure patterns and shared content sourcing are a strong indicator. They are not a subpoenaed org chart, and this piece treats the connection with the same evidentiary caution the researchers applied to it.
Key Findings
- Roska Bridge is a pro-Russian information operation, active since at least September 2025, that cross-posts laundered Kremlin media across Mastodon and Bluesky using the legitimate interoperability tool Brid.gy, per CheckFirst’s July 2, 2026 report.
- Hundreds of Mastodon accounts across at least ten instances — including 870,000-user mastodon.social — are bridged to hundreds of matching Bluesky accounts, with new batches activated roughly monthly.
- Content is laundered in at least two passes: first through Portal Kombat’s network of ostensibly independent regional news portals (193+ sites documented by VIGINUM in 2024, since grown to 224+), then through personal-account cross-posting that further disguises its origin.
- The core vulnerability is a moderation gap between protocols, not within either one — Mastodon admins and Bluesky’s moderation stack each govern their own network, but neither has authority over content bridged in from the other.
- Brid.gy’s own maintainers have acknowledged insufficient resources to moderate content passing through the bridge, a resourcing gap rather than a design flaw or complicity.
- A short-burst, rapid-replacement posting cadence outruns standard report-and-review moderation cycles, letting each account batch complete its work before enforcement can catch up.
- CheckFirst identifies a structural link to Portal Kombat but is explicit this is pattern-based, not formally proven attribution.
Implications
The Influence Tactics Protocol scores manipulation by mechanism rather than by platform, and Roska Bridge is a clean argument for why that has to include infrastructure-level mechanisms alongside content-level ones. A detection approach that evaluates posts for false claims, emotional manipulation, or fabricated sourcing will find plenty to flag in laundered RT copy — but it won’t, on its own, catch the reason this particular operation can operate at scale for ten months: the fact that its distribution model was built around a jurisdictional seam nobody was assigned to patrol. That’s not a claim about any post’s content. It’s a claim about where the post lives and who is, and isn’t, watching that address.
There’s a broader lesson here for anyone building or trusting a federated system. Federation’s whole appeal is that no single entity holds the keys — but every bridge between systems inherits the union of both systems’ blind spots along with the union of both systems’ strengths, unless someone explicitly designs for the seam itself. That’s true of Mastodon and Bluesky today. It will be true of whatever the next pair of interoperating protocols turns out to be, and the fix isn’t “moderate harder” on either side of a bridge that neither side considers fully theirs to moderate. It’s building the seam itself as a governed thing, with someone actually accountable for it, rather than assuming interoperability is a purely technical achievement with no governance dimension of its own.
For an ordinary reader scrolling either network, there’s no visible tell that separates a bridged account from a native one, and that’s rather the point — the bridge is transparent by design, which is exactly what makes it useful for cross-posting a cat photo and useful for laundering a state media talking point. The defense isn’t spotting the bridge. It’s the same defense that has applied to every laundering chain this platform has documented: noticing when a post’s content, tone, and timing match a known state narrative more closely than they match an individual voice, regardless of which protocol delivered it to your timeline.
Conclusion
Nothing about Roska Bridge required breaking anything. Brid.gy worked exactly as its creators built it to work. Mastodon’s admins moderated exactly what fell under their own instances’ authority. Bluesky’s labelers labeled exactly what their service was built to label. Every component performed its function correctly, and a pro-Russian laundering operation ran uninterrupted through the gap between them for the better part of a year regardless. That’s the whole story, and it’s a more unsettling one than a hack would be — a hack implies something failed. Here, everything worked as designed, and working as designed was enough.
This article is part of Decipon’s Manipulation Breakdowns series, examining specific influence operations through the Influence Tactics Protocol.
Sources:
- Roska Bridge: How a pro-Russian IMS exploits vulnerabilities of decentralised platforms to spread propaganda — CheckFirst
- PORTAL KOMBAT: A structured and coordinated pro-Russian propaganda network — VIGINUM / SGDSN
- Russian disinformation network “Pravda” grew bigger in the EU, even after its uncovering — EDMO