VYPR
breachPublished Oct 7, 2026· 1 source

Discord Security Bot Double Counter Breached, Exposing Millions of User Records

A breach at Discord security bot provider Double Counter exposed millions of Discord IDs, usernames, IP addresses, and email addresses due to an attacker exploiting an old server running Metabase.

Double Counter, a popular Discord security bot, has disclosed a significant data breach that exposed the personal information of millions of its users. The incident, which occurred on October 4, 2026, saw attackers gain access to the bot provider's cloud systems, exfiltrating approximately 12 GB of database records. This breach compromised user data including Discord IDs, usernames, IP addresses, location records, user-agent hashes, and email addresses.

The attackers gained initial access through an old OVH server that was part of Double Counter's previous hosting infrastructure. Although this server was disconnected from the live service, it was still running a publicly accessible Metabase analytics tool. A flaw in this tool allowed the attacker to forge an administrator session, granting them access to credentials stored on the server. These credentials included a cloud service-account key with administrator rights and a saved administrator command-line session, effectively turning an unused server into a gateway to production systems.

Once inside, the attacker exploited the compromised credentials to access Double Counter's production systems. They began by adding an SSH key, exporting a database to a storage bucket, and opening a shell within a bot container, which exposed a Discord bot token. This stolen token was subsequently used to spam unwanted invitations across approximately 50 large Discord servers, impersonating Double Counter. While the initial database export was not downloaded, the attacker's ability to access and reuse valid identities made their activity difficult to detect.

The situation escalated as the attackers demonstrated a persistent ability to maintain access. After staff invalidated the stolen bot token, the attackers managed to obtain the replacement token within two minutes by leveraging their continued cloud access. This highlights a critical security failure: changing a single secret is insufficient to contain an attack if the system holding that secret remains compromised. The attackers further escalated their actions by changing the database administrator password and copying records between 15:09 and 15:34.

Double Counter estimates that the breach exposed around 28 million Discord IDs and usernames, and 27 million IP-address and location records. Additionally, user-agent hashes for approximately 25 million accounts and about one million unique email addresses were copied. The company cautioned that these figures represent overlapping groups, and simply adding them would overstate the total number of unique victims. While Discord passwords and stored card numbers were not affected, and cold storage containing data for about 58 million users remained secure, the scale of the exposed data is substantial.

Beyond the Discord user data, the breach also had financial implications. A stolen Stripe key was used to facilitate $7,316 in fraudulent charges against a company card associated with a separate Atis account, with two customer charges being refunded. This indicates a broader compromise that extended beyond the bot's direct operational data.

In response, Double Counter has taken several measures to contain the breach and enhance security. They have shut down the old server, revoked all compromised cloud access, rotated credentials, deleted exposed webhooks, and moved databases behind private networking. The bot token is now managed using dedicated secret storage, and the service is supported by enhanced secret-access logging and continuous monitoring to prevent future incidents.

Synthesized by Vypr AI