Double Counter, the company behind a widely used Discord moderation and anti-spam bot, has disclosed a breach that exposed records on tens of millions of accounts after an intruder found a way into its cloud infrastructure on October 4, 2026. The company says Discord’s own systems were never touched — the compromise was entirely on Double Counter’s side — but the scale of exposed data and the attacker’s ability to briefly impersonate the bot itself make this a notable supply-chain-style incident for anyone running third-party bots in their servers.
An Old Server Became the Doorway In
According to Double Counter’s account, the intrusion didn’t start with a clever new exploit. It started with a forgotten one: an old server hosted at OVH, left over from a previous hosting arrangement, was still running a publicly reachable instance of the analytics tool Metabase. A flaw in how that instance handled sessions let the attacker forge administrator access and reach credentials stored on that same host — including a cloud admin service-account key and a saved administrative command-line session. Double Counter has not tied the incident to a specific published CVE, so the exact root cause within Metabase remains unconfirmed.
Because the attacker used those stolen, legitimate credentials rather than creating new accounts, the activity blended in with normal administrative traffic for longer than a brand-new login would have. Once inside, the intruder added their own SSH key, exported a database copy to a cloud storage bucket, and opened a shell inside one of the bot’s running containers — a move that exposed the live Discord bot token itself.
A Few Hours of Chaos on the Support Server
With the token in hand, the attacker used the bot’s own identity to grant themselves administrator rights on Double Counter’s official support server, reverse a staff member’s ban, and send unsolicited invitations to roughly 50 large Discord communities. Double Counter’s incident response team tried to cut the attacker off by revoking the token and issuing a replacement — but the intruder read the new token within minutes, apparently because the deeper service-account compromise was still active. A second attempt to revoke the service-account key also failed, since the attacker had already pivoted to the stolen administrative session. Access was only fully terminated later that day once every related session was revoked at once.
What Was Actually Exposed
Double Counter’s own disclosure lists the exposed data in granular terms: roughly 28 million Discord user IDs and usernames, about 27 million IP address and approximate location records, user-agent hashes tied to roughly 25 million accounts, and around one million unique email addresses — with heavy overlap between these groups rather than 81 million distinct people. Have I Been Pwned has already indexed roughly 275,000 unique emails from data that circulated publicly. The company states that Discord account passwords and payment card numbers were not exposed, and that cold-storage records covering a further 58 million users were untouched. Separately, a stolen Stripe API key tied to the breach was used to charge about $7,316 fraudulently against an unrelated company account; two legitimate customer charges were refunded.
Cleanup and the Bigger Lesson
In its remediation, Double Counter says it decommissioned the old OVH server entirely, revoked all cloud access, rotated every credential involved, deleted webhooks the attacker could have planted, and moved its databases behind private networking rather than public endpoints. The bot’s authentication token now lives in dedicated secrets storage with logging on every access attempt, alongside new continuous monitoring.
For Discord server administrators, the practical takeaway isn’t really about Double Counter specifically — it’s about the dozens of third-party bots most communities run without a clear view of how those vendors secure their own backends. A bot’s permissions inside your server are only as trustworthy as the infrastructure behind it, and this incident shows how a single forgotten analytics server, left running years after its intended purpose ended, can cascade into tens of millions of exposed records and a hijacked support channel. Server owners relying on third-party bots should periodically review what permissions those integrations hold and watch for official breach disclosures from the vendors behind them.
Leave a Reply
You must be logged in to post a comment.