
Double Counter Discord Breach Exposes Millions of User Records
Double Counter Discord Breach Exposes Millions of User Records
Attackers accessed Double Counter’s infrastructure, exposing emails, usernames, location data, and other records.
Highlights
- Double Counter has confirmed a security incident involving its Discord bot.
- The breach exposed personal information linked to Discord users.
- Discord has restricted new Double Counter installations following the incident.
A security breach involving Double Counter, a Discord verification and server protection bot, exposed 274.9k unique email addresses and Discord usernames. Double Counter’s investigation found that substantially more user data was accessed.
The attack began through a vulnerable Metabase installation on a retired OVH server and eventually compromised the bot’s Discord token and cloud infrastructure.
What Data Was Exposed in the Double Counter Breach
Have I Been Pwned lists email addresses, usernames, names, and geographic information among the exposed data. Double Counter’s investigation found:
- About 28M Discord user IDs and usernames were partly copied and treated as exposed.
- Approximately 15M VPN detection records were not copied.
- A 5 GB database export was created but never downloaded.
- About 27M IP and coarse location records were partly copied.
- User-agent hashes covering about 25M accounts were copied.
- About 1M email addresses were copied.
- Some paying subscribers' names, countries, and postcodes were exposed.
Discord passwords were never held by Double Counter, while stored payment card details remained with the payment provider. A separate database covering about 58M users and the company’s behavioral data was unaffected.
The attacker was active for 5 hours and 51 minutes and copied about 12 GB of database data.
They obtained Double Counter’s bot token and used it to grant their account administrator access and unban it. The compromised bot was then used to post invitations to the attackers’ Discord server across about 50 large servers, including “Steal a Brainrot.”
Response to the Double Counter Breach
The attack also led to $7,316 USD in fraudulent charges through a stolen Stripe key belonging to the separate Atis product. Two customer charges totaling $18 were refunded, and Double Counter said customer funds remained safe.
Double Counter revoked compromised credentials, reset its bot and webhooks, closed the affected database to the internet, moved its cache database to a private network, audited 14 cloud projects, and added secret-access monitoring. It restored the service at 19:19 UTC on Oct 4 and notified France’s CNIL on Oct 5, 2026. The company is pursuing those responsible in France and the United States.
Meanwhile, Discord confirmed that its systems were not breached and has blocked new Double Counter installations while investigating.
Users have called for stronger action.
@KiyoraVIP pointed out that simply blocking new installations was insufficient for bots collecting excessive personal information. @ShxunGG called for Double Counter to be removed, while @ssniamlx asked for help deleting exposed data.
Members should avoid unexpected server invitations, while affected Doogle, advertiser, and API users should remain alert for phishing attempts. The incident also shows how third-party Discord bots can become a significant security risk when they retain large amounts of user data and hold access to critical platform permissions.

Author
Probaho Santra is a content writer at Outlook India with a master’s degree in journalism. Outside work, he enjoys photography, exploring new tech trends, and staying connected with the esports world.
Related Articles






