http://e26whn2524322mkxb3cbyk27ev2ihhq2biz35hty7gzgsyrwrygq27yd.onion/posts/blog/security/digging-into-the-behaviour-of-a-self-authenticating-mastodon-scraper-bot.html
This bot , unusually, was providing a token, just not a valid one. This, as you might expect, elicited an almost irresistable sense of curiosity: what was being provided as a token, and why was it being presented?