Discord Security Bot Double Counter Hacked, Exposing Data of Millions of Users
Double Counter’s Discord bot breach exposed identifiers, IPs, and emails tied to tens of millions of accounts.
Tellter SAS said an attacker breached the Discord security bot Double Counter by exploiting a Metabase instance on a retired OVH server and using stolen cloud administrator credentials. The intruder was active for 5 hours 51 minutes, copied about 12 GB, and exposed Discord IDs and usernames for roughly 28 million accounts, IP records for about 27 million, 25 million user-agent hashes, and one million emails. Passwords and stored card data were not exposed, while a stolen Stripe key for separate product Atis enabled $7,316 in fraudulent charges. Tellter notified France’s CNIL, revoked credentials, and shut down the legacy server.
- Initial access used a Metabase flaw on a retired internet-facing OVH server.
- Copied data covers about 28 million Discord IDs, 27 million IP records, and one million emails.
- Passwords were never stored; VPN logs and separate cold storage were not copied.
- A stolen Stripe key for Atis caused $7,316 in fraudulent charges.
- The attacker stayed nearly six hours and retook a rotated bot token within two minutes.
Full article576 words · extracted from gbhackers.com · click to collapse
The Discord security bot Double Counter experienced a targeted infrastructure breach that compromised personal information linked to millions of accounts.
According to an incident report by operator Tellter SAS, an attacker accessed cloud credentials, hijacked the bot, copied about 12 GB of database contents, and misused a separate payment account.
The attacker remained active in the cloud environment for 5 hours and 51 minutes, from 12:03 to 17:54 UTC. Double Counter restored service at 19:19 after replacing the exposed credentials. An audit of 14 cloud projects found no remaining traces of the attacker.
Discord Security Bot Double Counter Hacked
The intrusion began through a retired OVH server that was disconnected from Double Counter’s operational network but still hosted an internet-accessible Metabase analytics instance.
The report attributes the initial access to a Metabase vulnerability that allowed the attacker to forge an administrator session and access the underlying host. No specific Common Vulnerabilities and Exposures (CVE) identifier was provided.
The compromised server contained valuable credentials, including a service account key with cloud administrator privileges and an administrator’s saved command-line session. By using these legitimate identities, the attacker blended their activities into normal operations.
Once inside the cloud, the attacker added an SSH key and exported a database to a newly created storage bucket. However, they did not download the initial export.
At 12:26 UTC, the attacker accessed a running bot container’s shell and extracted its Discord token. They then granted their account administrator privileges on Double Counter’s support server, reversed a staff-issued ban, and distributed invitations to their own Discord server through about 50 large communities.
According to Double Counter, Containment efforts initially failed because the attacker retained access to the infrastructure. When defenders rotated the bot token, the attacker obtained the new token within two minutes.
They then changed the database administrator password, disrupting legitimate services, and continued to copy database contents until responders terminated the session at 15:34. After revoking the service account key, the attacker switched to the stolen administrator session.
The affected dataset included Discord IDs and usernames associated with approximately 28 million accounts, as well as IP address records with coarse geolocation data related to about 27 million accounts.
Both categories were partially copied and are being treated as exposed. Additionally, the operator confirmed that approximately 25 million user-agent hashes and one million deduplicated email addresses were copied.
However, the operator confirmed that 15 million VPN detection logs were not copied, and separate cold storage containing data for approximately 58 million users and a behavioral database remained unaffected. Notably, Discord never collected passwords, and stored payment card details were not exposed.
A stolen Stripe key belonging to a separate product, Atis, enabled fraudulent charges totaling $7,316 against a company card. Two customers also incurred charges of $3 and $15, which have since been refunded.
In response to the breach, responders revoked credentials, shut down the legacy server, restricted database connectivity, removed public cache exposures, and implemented secret-access logging.
Administrators are advised to inspect audit logs and delete suspicious bot invitations posted between 12:00 and 16:30 UTC on October 4. Users should also be on the lookout for phishing attempts targeting exposed email addresses. Tellter notified France’s CNIL on October 5 and is pursuing legal action.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.