How to stop compromised accounts from spamming scam links on Discord
When a trusted member's account is taken over, its first message is often a scam link pasted into every channel. Here's how to spot it, stop it in seconds, and help the member get their account back.
Why compromised accounts are so hard to stop
Spam from a compromised account doesn't look like spam from a bot. The account is real, often years old, has roles and passed your verification long ago. Members trust it, because they know the person behind it. Scammers rely on exactly that: a "free Nitro" link from a friend gets far more clicks than one from a stranger.
Accounts usually get taken over in one of a few ways:
- A fake login page, often a "free Nitro" or "vote for my server" site that looks like Discord.
- A QR code sent with a story ("scan this to verify"). Scanning it with the Discord app logs the scammer in.
- Malware posing as a game to "test" or a tool to download, which steals the account's login token.
The scammer then runs a script that posts in every channel it can reach and DMs the account's friends, so the scam spreads to the next account.
Signs that an account has been compromised
- It suddenly posts in many channels within seconds, often the same message.
- The message doesn't sound like the person: a giveaway, a "free Nitro" or Steam gift, an "is this you in this video?", or a job or crypto offer.
- The link points to a lookalike domain: a misspelt "discord" or "steamcommunity", extra words, or an unusual ending.
- It posts in channels the person never uses, or at hours they're never online.
- Members report DMs from the same account at the same time.
See Free Nitro and Steam gift scams for real examples.
Layer your defences
No single setting stops every scam. These layers work together, from the one that catches the most to the ones that limit the damage:
- A honeypot trap channel. A channel everyone is told never to post in, at the top of your channel list. Scripts post there first, and a bot bans them within a second, deleting their recent messages everywhere. Read what a honeypot channel is.
- Duplicate message detection. The same message in 3 or more channels within seconds is something people don't do. Stingsby can treat it like a trap hit; turn it on in
/config. - Discord AutoMod. Turn on the rules for suspected spam and mention spam, and block words that only scams use in your community. It won't keep up with every new domain, but it stops the obvious ones.
- Server safety settings. Require 2FA for moderator actions, so a compromised moderator account can't ban or delete; set the verification level to at least Medium; keep the explicit media filter on.
- Fewer permissions for
@everyone. No Mention @everyone, Manage Webhooks or Manage Messages for regular members: a compromised account can only do what its roles allow. - Raid alerts. Some waves arrive as many new accounts at once. Get your moderators pinged, and pause invites or DMs while you deal with it. See raid and DM spam alerts.
Stingsby's /security scan checks most of these for you and scores your server from 0 to 100, with a fix for each problem. See the 14 checks.
What to do when it happens
- Remove the account first, ask questions later. Ban, softban or time it out, so it can't post or DM from your server. With a honeypot this has already happened by the time you look.
- Delete its messages in every channel. A ban can delete up to 7 days of messages. Stingsby's
/clear userremoves one user's messages across all channels at once. - Warn your members not to click the link, and to tell staff if they did. If the account DMed people, say so.
- Check the Audit Log for anything else the account did, especially if it had any staff permissions.
- Check how it got in. If several caught accounts joined through the same invite, delete that invite. Stingsby's join log and ban reports show which invite each member used.
Helping the member get their account back
The person behind the account is usually a victim, not a spammer. Tell them, through a friend or once they're back in control:
- Change the password straight away. This also replaces the login token the scammer may have stolen.
- Turn on two-factor authentication (User Settings → My Account).
- Remove unknown apps in User Settings → Authorized Apps, and check the devices that are logged in.
- If they downloaded something, scan their computer for malware before logging in again, or the token will just be stolen again.
- If they can't log in any more, contact Discord support.
Then unban them. Stingsby DMs every caught account with these same steps before acting, so they know why they were removed and how to come back.
More guides
- What is a Discord honeypot channel, and how do you set one up?A honeypot channel is a trap only spam scripts fall into. How it catches compromised Discord accounts, why real members stay safe, and how to set one up.
- Free Nitro and Steam gift scams on Discord: how they spread and how to stop themWhat free Nitro and Steam gift scams on Discord look like, how they spread from account to account, how to spot a fake link, and what to do if you clicked.
- Discord anti-spam compared: AutoMod, filters, verification and honeypotsDiscord AutoMod, spam filter bots, verification gates and honeypot traps compared: what each catches, what it misses, and how to combine them.