On October 4, 2026, the Discord security bot Double Counter suffered a breach that exposed user data after hackers infiltrated its cloud infrastructure. During the attack, about 12 GB of database content was copied, and the compromised bot token was used to send unsolicited server invitations across approximately 50 large Discord servers.
How the Breach Happened
The attacker gained access via a legacy OVH server that Double Counter no longer used for live operations. Though disconnected from active service, the server still ran a Metabase analytics tool that was reachable from the internet. A vulnerability allowed attackers to forge an administrator session and grab credentials. Among those credentials were a cloud service-account key with admin privileges and a command-line session stored by an administrator.
Using those credentials, the help landed a path into production systems—despite using identities that didn’t appear suspicious in normal logs. Once inside, the attacker added an SSH key, exported a database into storage, and gained a shell within a bot container where the Discord bot token was exposed. That token was then leveraged to elevate privileges in Double Counter’s support server, reverse staff bans, and distribute server invitations under the bot’s identity.
Scale and Impact of Data Exposure
The eventual fallout was serious. Immediate access was shut down when Double Counter invalidated the exposed token around 1:39 PM UTC. But that didn’t stop the attacker—within two minutes they managed to access the freshly rotated token using the still-compromised admin session. They later stole the administrator database password, and stole additional data between 3:09 and 3:34 PM. Full containment finally occurred after all sessions and credentials were revoked by around 5:55 PM.
The data compromised is substantial: about 28 million Discord IDs and usernames, 27 million IP and location records, user-agent hashes tied to roughly 25 million accounts, and around one million unique email addresses. Because these datasets overlap, the total number of affected users is less than the sum of those figures. Passwords and payment card data were not included in the breach. An unrelated breach involving a Stripe key led to $7,316 in fraudulent charges on a company card attached to a different service. Two customer charges were later refunded.
What’s Being Done to Fix It
After discovering the breach, Double Counter shut down the outdated OVH server, revoked cloud credentials, rotated exposed secrets like tokens and webhooks, and moved sensitive databases behind private networks. They also implemented secret-access logging and continuous monitoring to help detect future intrusions more quickly.
Investigators reviewed 14 cloud projects and found no evidence of deliberate backdoors. The breach stemmed from infrastructure left from old hosting arrangements, not a failure within Discord’s own systems.
Patchwork fixes were deployed, but the incident exposed lingering risks in relying on deprecated infrastructure and insufficient isolation of administrative sessions.
The fallout from this breach underscores a painful reality for bot providers and cloud operators: good security hygiene means removing unused infrastructure, separating environments, and treating all credentials—even those on legacy systems—as dangerously powerful if left unguarded. For Discord users, this is a jolting reminder that third-party bots can be a weak link. Going forward, bot developers and cloud teams must prioritize credential protection, secret management, and strict access controls. Monitoring reused identity sessions and controlling exposure points like publicly reachable tools must become standard—not optional. What’s at stake isn’t just data, but trust in the ecosystem.