Discord Security Bot Breach
On October 4, 2026, Double Counter, a prominent security bot for Discord, experienced a significant data breach. Approximately 12 GB of user data was compromised when an attacker infiltrated its cloud infrastructure, leading to unauthorized postings across nearly 50 major Discord servers.
The breach was swiftly addressed, with Double Counter restoring services by 19:19, according to their incident report. An audit of 14 cloud projects revealed no backdoors, confirming the breach was isolated to Double Counter’s systems and not Discord’s.
How the Breach Occurred
The intrusion was traced back to an outdated OVH server from Double Counter’s previous hosting arrangement. Despite being disconnected from active services, it hosted a publicly accessible Metabase analytics tool. A vulnerability allowed the attacker to create an administrator session and gain access to sensitive credentials stored on the server.
These credentials included a cloud service-account key with full administrative rights and an administrator’s command-line session logs. By leveraging existing identities instead of creating new ones, the attacker initially avoided detection.
Details of the Cyber Attack
The attack commenced at 12:03, with the attacker adding an SSH key, exporting a database into a storage bucket, and opening a shell within a bot container, exposing the Discord token. Although the initial database export wasn’t downloaded, the stolen token enabled the attacker to manipulate server permissions.
Efforts to invalidate the token at 13:39 were insufficient, as the attacker quickly accessed the new token. Subsequent actions included changing the database admin password and duplicating records between 15:09 and 15:34. The attack concluded when all compromised sessions were revoked at 17:55.
Impact and Response
The breach affected approximately 28 million Discord IDs and usernames and 27 million IP addresses, along with user-agent hashes and email addresses. Investigators consider the entire IP table compromised due to uncertainty about specific rows.
Despite the breach’s scale, Discord passwords and stored payment information were not accessed. A separate incident involving a stolen Stripe key resulted in $7,316 in unauthorized charges, but affected customers were refunded.
To secure their systems, Double Counter decommissioned the vulnerable server, revoked cloud access, rotated credentials, and implemented stronger security measures, including secret storage and continuous monitoring.
These actions reflect a commitment to bolster security and prevent future incidents.
