I think any federated service is more vulnerable, because there’s no central oversight, e.g. of IPs used to create accounts.
Even without any code, you could easily register accounts at the 20 largest instances and upvote yourself. I’m sure some people will have done just that.






I think that the relative lack of content is actually a feature for this reason - sometimes I open Lemmy out of habit, but I see the same content and go do something more worthwhile instead.