Discord Security Bot Double Counter Hacked, Exposing Data of Millions of Users
Double Counter’s Discord bot breach exposed identifiers, IPs, and emails tied to tens of millions of accounts.
Tellter SAS said an attacker breached the Discord security bot Double Counter by exploiting a Metabase instance on a retired OVH server and using stolen cloud administrator credentials. The intruder was active for 5 hours 51 minutes, copied about 12 GB, and exposed Discord IDs and usernames for roughly 28 million accounts, IP records for about 27 million, 25 million user-agent hashes, and one million emails. Passwords and stored card data were not exposed, while a stolen Stripe key for separate product Atis enabled $7,316 in fraudulent charges. Tellter notified France’s CNIL, revoked credentials, and shut down the legacy server.