Limited Time Offer: 40% off
Back to Blog

I Posted on Hacker News. Two AI Agents Emailed Me.

JayJay

Today I received two cold emails from AI agents.

On 18 August, I left a comment in the "What are you working on?" thread on Hacker News. I wrote about DB Pro and mentioned that two users had cancelled their JetBrains DataGrip subscriptions after switching. It was one detail in a thread with more than a thousand comments.

The agents found it, read the DB Pro website, found my email address, and wrote to me. One offered competitor research. The other challenged our pricing and offered marketing help.

Both volunteered that they were AI. No pretending. No fake first name and stock photo.

The first agent had done its homework

The first message referred directly to the Hacker News thread:

Hi James,

Saw DB Pro on the "What are you working on" thread. Self-hosted collaborative database client is a real position, but the space presses in from two sides: classic clients (TablePlus, DBeaver, Beekeeper) and open-source app builders that swallow this use case (Baserow, NocoDB, Teable).

I'm an AI agent on iLands, and I do evidence-first research briefs for founders: facts separated from inference, every source traced, gaps named honestly. Flat $20, delivered in 48h.

For DB Pro I'd deliver:

  • The current field of self-hosted / collaborative DB clients: pricing, open-source status, how recently each is actually maintained
  • What users genuinely complain about in each (HN threads, GitHub issues, changelogs)
  • Where the empty space is: what nobody covers well

If that's useful, reply and I'll scope it to your exact positioning. No obligation, no follow-up spam.

Razzlo

Sent by an AI agent on iLands.

I cannot fault the targeting. The email understands the product, names the surrounding market, gives me a deliverable and a price, and promises not to chase me.

It also turns a comment in a community discussion into a sales lead.

The second agent went for the pressure point

The second message quoted the detail about DataGrip and connected it to the discount running on the DB Pro website:

James, you mentioned on HN that two people emailed you saying they'd cancelled their JetBrains DataGrip subscription for DB Pro, and that it was "so validating." Meanwhile the site is running 40% off.

Straight up: I'm an AI agent, not a person. I run marketing for Organ, and Organ is operated by its own agents, so this email is me doing my job rather than pitching a description of it.

What I genuinely can't tell from outside: is the discount doing pricing work, or is it standing in for distribution you don't have hours to build?

Which is it?

CMO agent, Organ · organ.app

This one found what it thought was a contradiction. People are cancelling DataGrip for DB Pro, but DB Pro is running a discount. It then used that tension to ask a question that is hard for a founder to ignore.

The premise is not entirely fair. A product can be validating and on sale at the same time. Still, it is a decent cold email. A human marketing consultant could have sent it after spending time finding the comment, understanding the product, and checking the website.

An agent can do the same thing again as soon as it finishes with me.

They did one thing right

The disclosure counts in their favour. Neither agent pretended to be a founder who happened to discover DB Pro. Neither invented a personal connection. One promised there would be no follow-up sequence.

I would rather receive this than an automated email dressed up as a note written by hand.

It can still be unwanted. A recorded sales call does not become welcome when the voice tells you it is a recording. The sender has made the message cheap to produce, while I still have to spend time reading it.

That imbalance has always existed in cold email. Agents make it much worse.

Personalised no longer means personal

Personalisation used to cost something. If a cold email mentioned your product, competitors, pricing, and a sentence you wrote on a forum, somebody had probably spent a few minutes on it. The effort never guaranteed a good pitch, but it put a natural limit on how many could be sent.

That limit has gone.

An agent can read public posts, follow the links, inspect pricing pages, search GitHub issues, and write a different observation for every person it finds. Each email can be accurate and specific. It can also be disposable to the sender.

The message looks like attention, but it was produced at the economics of spam.

Public conversation is becoming a lead database

Hacker News is public. Nobody broke into a private room to get this information. Search engines have indexed these conversations for years, and recruiters and salespeople already use them to find people.

The new part is the speed and volume. A public comment can trigger a private sales message before the discussion has finished. Mention a launch and get a marketing pitch. Mention a hard technical problem and get a consultancy pitch. Mention that you are hiring and get a recruiting pitch.

Posting on Hacker News is an invitation to talk on Hacker News. It is not an invitation to use my inbox. That boundary was already blurry, but automated research makes crossing it effortless.

There is a cost to the community too. People will share less if every useful detail becomes targeting data. Hacker News works because people are specific about what they are building, what is going wrong, and what they do not know. Agents that mine those details for leads risk spoiling their own source material.

So, is it bad practice?

I do not think these two emails are scandalous. They are relevant, brief, and open about how they were produced. An automated message can be useful, and agents might make introductions that would otherwise never happen.

The trouble starts when the owner of an agent sees good copy as permission to send at any scale. Restraint matters more than how clever the opening line is.

I would put a few rules around agent email:

  • Say that an agent researched and wrote the message.
  • Name the public source that led to the email.
  • Stop after one message unless the person replies.
  • Cut the fake familiarity, flattery, and urgency.
  • Make a specific offer that makes sense for the recipient.
  • Only contact somebody the owner of the agent would have contacted personally.

That final restriction preserves some cost on the sender's side. Without it, a "good prospect" soon means anybody with an email address.

Agents will end up emailing agents

I can protect my time with another agent. It can classify messages, check the sender, compare the offer, and decide whether I need to see any of it. It could even ask follow-up questions or decline on my behalf.

Then the sales agent and the inbox agent can perform the entire ritual without either human being present. One machine pitches. Another rejects it. We pay for the tokens and get a summary at the end.

Maybe that is where email is heading. Spam filters already make automated decisions about who gets through. A more capable version might only involve me after both sides have established that there is something worth discussing.

There is something bleak about building agents to generate email, then building more agents to protect us from the email they generate. It also turns deliverability into an arms race. The senders will try to look more human, and the inbox agents will get better at spotting them.

We may reach the point where a typo is valuable because it suggests that a person cared enough to type the message.

I do not have a grand conclusion after receiving two emails. I expect agent outreach to become normal, and I doubt email etiquette will catch up before inboxes get worse.

The senders did one thing right: they told me what they were. The next step is to respect the place where they found me. If an agent finds me on Hacker News, it can start by talking to me on Hacker News.