Double Counter, the Discord security bot trusted by more than 600,000 communities, suffered a targeted data breach on 4 October 2026 that exposed personal data linked to roughly 28 million Discord accounts and 1 million email addresses. Operated by Tellter SAS, the anti-alt and VPN-blocking service confirmed the attack began through a vulnerability in a retired Metabase analytics tool and ended with the attacker hijacking the bot’s Discord token, spamming about 50 large servers, and committing $7,316 in payment fraud.
What Is Double Counter and Why Does This Breach Matter?
Double Counter is a popular Discord server protection bot that blocks alt accounts, raids, VPNs, proxies and Tor traffic. Since 2020 it has verified users across 618,000+ servers using device, browser, network and behaviour signals. That scale makes the incident significant for Discord server security and for millions of members who never signed up directly.
How the Attack Unfolded
According to the official security incident report, the attacker first probed a legacy OVH server on 3 October from rotating VPN addresses. At 00:47 on 4 October, they logged in by exploiting a vulnerability in a publicly reachable Metabase instance still running on that retired server. The incident echoes a wider pattern seen in cloud security best practices failures involving forgotten infrastructure.
From Legacy Server to Cloud Control
On the server they found two cloud credentials: an administrator service-account key and a saved command-line session. The attacker used the service-account key at 12:03 to add an SSH key, export a database to a bucket (never downloaded), and open a shell in a running bot container at 12:26 to steal the Discord bot token.
Bot Hijack and Database Exfiltration
With the token, the attacker granted themselves Administrator on Double Counter’s support server, unbanned their account, and from 13:30 posted links to their own Discord server in about 50 large servers. When staff rotated the token, the attacker read the replacement within two minutes, deleted backups, changed the database password, and copied about 12 GB of database tables before the session was terminated at 15:34. The last cloud action was logged at 17:54; service was restored at 19:19 UTC with new credentials.
What Data Was Exposed?
The breach affected multiple overlapping datasets. The company treats partially copied data as fully exposed:
- 28 million Discord user IDs and usernames
- 27 million IP addresses with country, region, city, postal code and ISP
- 25 million one-way user-agent hashes used for alt detection
- 1 million email addresses (about 275,000 unique after deduplication, according to Have I Been Pwned)
- A small number of Stripe-paying subscriber records including names, countries and postcodes
No Discord passwords, stored card numbers or full billing details were exposed. The separate cold-storage database of about 58 million users was not affected. The attacker also used a stolen Stripe key to make $7,316 in escalating test charges against Tellter’s own card and two small customer charges ($3 and $15), both refunded.
What Should Affected Users Do?
Double Counter has notified the French data protection authority CNIL and is pursuing legal action in France and the United States. “We cut off their access, found no persistence, replaced the exposed credentials and restored the service at 19:19. We sincerely apologise to everyone affected,” the company said.
Server Administrators
Delete any Double Counter message sent between 12:00 and 16:30 UTC on 4 October inviting users to another server, and review audit logs for unexpected bot actions.
Discord Members
Check your email on Have I Been Pwned, enable two-factor authentication, avoid joining servers advertised in unexpected bot messages, and stay alert for Discord phishing scams.
FAQ: Double Counter Data Breach
Was Discord itself hacked?
No. Double Counter is a third-party bot; Discord’s own systems were not breached.
Were passwords leaked?
No Discord passwords or full card numbers were exposed, because Double Counter never receives them.
How many emails were exposed?
About 1 million email addresses were in the copied database; Have I Been Pwned identifies 275,000 unique addresses after deduplication.
Is the service safe now?
Yes, Double Counter was restored at 19:19 UTC on 4 October with rotated credentials and continuous monitoring.
Follow Discussion