Bluesky’s Core Features Took a Day-Long DDoS Hit

Bluesky’s outage matters because a sustained DDoS can knock out the parts of a social platform people rely on most: feeds, notifications, threads, and search. The standard response is to treat this as a temporary availability issue, but the real risk is that a decentralized service can still be forced into broad user-visible disruption even when no data is touched. Bluesky said the attack began on April 15 and continued into April 16, with intermittent outages that intensified through the day. The company said it saw no evidence of unauthorized access to private user data and said it mitigated the attack; 313 Team claimed responsibility, but that attribution has not been independently verified. The forward risk is persistence, not theft. If the service remains a visible target, attackers can keep using traffic floods to degrade trust and availability without needing to breach accounts or systems.

Part of the PlainSec briefing for 2026-04-18

Every edition of this story: Bluesky’s Core Features Took a Day-Long DDoS Hit

Sources