SATURDAY, OCTOBER 10, 2026|No. 18216
Technology · Cybersecurity

Discord Security Bot 'Double Counter' Suffers Major Data Breach

The Discord security bot 'Double Counter' was hacked, exposing the data of approximately 28 million users, including Discord IDs, usernames, IP addresses, and email addresses.

A graphic representing a security breach on a digital platform.
A graphic representing a security breach on a digital platform.
1 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
0 countries
Related coverage

Discord Security Bot 'Double Counter' Hacked, Exposing Data on Roughly 28 Million Accounts

Double Counter, a Discord server protection bot, suffered a multi-stage hacking attack that exposed approximately 28 million Discord IDs and usernames, around 27 million IP addresses, and roughly 1 million email addresses. The attacker exploited a vulnerability in an analytics tool on a decommissioned legacy server to gain administrator privileges, remaining in the system for about six hours and exfiltrating roughly 12GB of data. Operator Tellter rotated credentials and took databases offline, restoring service the same day, and reported the incident to France's CNIL. Malicious links were posted to roughly 50 large servers, and financial damages totaled $7,316.

Key Elements

Double Counter Tellter Discord Have I Been Pwned Metabase Stripe France's CNIL

Discord Security Bot 'Double Counter' Hacked, Exposing Data on Roughly 28 Million Accounts

Double Counter, a Discord server protection bot service, was hit by a multi-stage hacking attack that exposed large-scale user data, including approximately 28 million Discord IDs and usernames. Tellter, the French company that operates the service, said the attacker remained in the system for about six hours and exfiltrated roughly 12GB of data.

The intrusion vector was a legacy server Tellter had previously used in an OVH hosting environment. Although the server had been decommissioned and was no longer connected to Double Counter's production service, it remained accessible from the internet and had a self-hosted Metabase analytics tool installed. The attacker exploited a vulnerability in this tool to forge an administrator session, then used that session to obtain administrator-level credentials stored on the server.

Using the stolen credentials, the attacker extracted bot tokens from Double Counter's production containers. The attacker then granted their own Discord account administrator privileges on Tellter's support server, and when staff banned the account, the attacker used the bot to unban it. Because legitimate credentials were used, the attacker's activity initially went undetected. Even after Tellter detected the anomaly and took action, the attacker continued the assault, including changing the database administrator password.

The leaked data includes approximately 28 million Discord IDs and usernames collected by Double Counter, around 27 million IP addresses and approximate location data, roughly 25 million user agent hashes, and about 1 million email addresses. Have I Been Pwned, a data breach notification site, reported that it received a public notice from Double Counter and confirmed that a data bundle containing approximately 275,000 email addresses and Discord usernames had been leaked externally. For paying subscribers, names, countries of residence, and postal codes were also included in the exposed data.

Beyond data exfiltration, the attacker posted invite links directing users to their own server on roughly 50 large Discord servers that use Double Counter. Additionally, a portion of the secret keys for Stripe, the payment service used by Tellter's other product Atis, was stolen. The attacker used these keys to run test charges against Tellter's credit card with progressively increasing amounts of $1, $10, $100, and $1,000. The final charge reached $7,316 (approximately 9.8 million won).

After confirming the damage, Tellter deactivated the stolen credentials, rotated encryption keys, took the affected databases offline, and moved them to a private network. All credentials the attacker may have read were also rotated. Service was restored on the 4th, the same day as the incident, and the breach was reported to France's data protection authority, the CNIL, the following day on the 5th.

Tellter has asked server administrators to delete all invite messages sent to other servers between 12:00 and 16:30 UTC on October 4. For general users, the company advised against joining servers promoted in unexpected messages sent by Double Counter. However, Tellter noted that ordinary server members do not need to take any separate action at the Discord account level.

This incident demonstrates how unused legacy systems can become a weak link in corporate security. Even when separated from production services, a single security flaw in legacy infrastructure exposed to the internet—and the tools running on it—can lead to a large-scale data breach, underscoring once again the importance of proper asset decommissioning and access-blocking procedures.

PAN's pipeline reviewed approximately 1 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →

Earlier on PAN

More in Technology →