The whole breach came down to a single forgotten server. On Oct. 4, an attacker broke into the infrastructure behind Double Counter, a security bot running in more than 600,000 Discord communities. The entry point was an old company server that had never been taken offline and was running a tool with a known security vulnerability.
In response, Discord has temporarily stopped new installations of Double Counter. Server owners who were planning to add the bot this week can’t do so.
What the attacker took
The damage is serious. Approximately 28 million accounts were linked to the stolen data, which contained usernames, IP addresses, approximate locations and ISP details.
Around one million email addresses are thought to have been copied in full. The attacker also used a stolen payment key to run up charges totaling $7,316.
Getting the data out didn’t take long. In just 25 minutes, 12GB was pulled from the system.
Six hours inside the bot
Taking over the bot completely took about six hours. During that window, the hacker seized control of Double Counter and used it to post invites to their own server in roughly 50 communities.
The irony is what makes this incident hurt. Server admins install Double Counter, a security bot, specifically to keep bad actors out. For a while, it served as a bad actor’s advertising channel instead.
Where Discord stands
Discord only blocked new installs once the incident had been publicly disclosed. It also stressed that its own internal systems were not the target. A third-party application was what got breached.
Discord cares about that distinction. The 28 million accounts linked to the stolen data may not find it very reassuring.
Discord is now working with the bot’s developers to work out how far the breach reached. More measures may follow, depending on what they find.
Communities that already have Double Counter installed can keep it for now, but new servers can’t add it. It all goes back to one old company server that nobody ever shut down.






















STAY ALWAYS UP TO DATE