You set the trap
Run /honeypot setup. Stingsby creates #πγ»dont-poke-the-hive at the top of your channel list and pins a clear warning in it.
Stingsby catches compromised Discord accounts before their scam links spread. It adds one channel your members are told never to use. When a compromised account's script posts there, stingsby bans it within a second and Discord wipes its spam from every channel.
Stingsby is in an early stage of development and isn't open to the public yet. Want it in your server? Ask for early access in the support server.
Stingsby doesn't guess from message speed or wording, so normal chat never sets it off. The only trigger is posting where everyone was told not to.
Run /honeypot setup. Stingsby creates #πγ»dont-poke-the-hive at the top of your channel list and pins a clear warning in it.
Real people read the warning and never post there. Scam scripts on compromised accounts paste into every channel they can reach, so the trap is usually the first one they hit.
The account is banned in one API call and Discord deletes its last 24 hours of messages everywhere. The owner gets a DM explaining why, and your staff get a full report in the log channel.
The honeypot is the first line. Stingsby also catches spam that skips it, warns you about raids, and checks the settings attackers rely on.
Permanent ban plus a clean-up of up to 7 days of the account's messages across the whole server. You choose the window. The account's owner gets a DM with the reason and how to secure their account.
/honeypot setup/configPick what happens to a caught account. Escalating gives a harsher step each time the same account is caught, from a 1-day timeout up to a permanent ban. Brand-new accounts are always banned.
/configEvery ban posts who it was, how old the account is, when they joined and the exact message that triggered it, with an Unban button to undo a mistake in one click.
/configPings your moderators when members join in a sudden wave, several brand-new accounts arrive together, or Discord flags a raid or DM spam, and can pause invites or DMs for you.
/configBans, failed bans, unbans, setting changes, clean-ups and alerts, kept for 90 days and searchable by type or user.
/honeypot logs14 checks on your trap, the bot's permissions and your server's safety settings, scored from 0 to 100 with a fix for each problem.
/security scan/security reportDelete the last messages in a channel, or one user's messages in every channel, by count or by minutes. Pinned messages are kept.
/clear channel/clear userEvery member who joins or leaves: the exact time, how old their account is, and who invited them with which invite. Ban reports show how the caught account got in, so one bad invite stands out.
/config/honeypot logsCatches an account that posts the same message in 3 or more channels within 30 seconds, even if it skips the trap. Only short fingerprints are kept, in memory, for 30 seconds. It's off by default: ask for it in /experimental, and once the bot owner approves it, turn it on there.
/security scan reads your settings and tells you what to fix. It never changes anything.
@everyone?@everyone hold risky permissions, or does another bot have Administrator?Quick answers about how stingsby works, what it can see and how to get it. Anything else? Ask in the support server.
Stingsby is a free Discord bot that catches compromised accounts: real members' accounts taken over by scammers and used to spam fake Nitro gifts, phishing and scam links. It sets a honeypot trap channel, can catch the same message pasted across channels, alerts your staff to raids and checks your server's security settings.
A channel that everyone is told, with a pinned warning, never to post in. People read the warning and stay out. Spam scripts on compromised accounts post in every channel they can reach, so an account that posts there is almost certainly not being used by a person, and stingsby acts on it within a second.
Only a member who posts in the trap despite the warning. The server owner, staff with Administrator, Manage Server or Ban Members, bots and any exempt roles you pick are never caught. Every ban report has an Unban button, and you can choose a softban or a timeout instead of a ban.
AutoMod filters words and links, and scam messages change their wording and links all the time. Stingsby doesn't judge what a message says. It reacts to things people don't do: posting in the trap, or pasting the same message into several channels in seconds. It works well alongside AutoMod.
It ignores every message outside the trap channel. With duplicate detection on, it compares short fingerprints that are kept in memory for 30 seconds, never the text. The only message ever stored is the one that got an account caught, so staff can see why.
Ban Members, Timeout Members, Manage Channels, Manage Messages, View Channels, Send Messages, Embed Links and Read Message History. It never asks for Administrator. Manage Server is only needed if you want it to pause invites or DMs during a raid, or to show who invited each new member in the join log.
Stingsby is in early access. Ask for access in the support server, and once it's in your server, run /honeypot setup. Setup takes about a minute.
Eleven: English, French, Spanish, German, Turkish, Arabic, Brazilian and European Portuguese, Traditional Chinese, Russian and Korean. Each server picks its own, and replies, ban reports, the warning and the DM to caught accounts all follow it.
Stingsby is in an early stage of development and isn't open to everyone yet. Ask for early access in the support server; once it's in your server, run /honeypot setup and you're protected.