Discord Account Hacked? How to Get It Back and Lock It Down

Somebody else is using your account. Here is how to tell, the order to fix it in, what to do if you are already locked out, and the six ways Discord accounts are really taken.

Somebody else is using your account. That is what this page assumes, whether you found out because a server removed you, because a friend sent you a screenshot of a scam link with your name on it, or because you clicked something twenty minutes ago and have felt sick about it since. Work through it in order. The explanations are further down and they can wait.

Start here: can you still log in?

Two very different situations look identical from the outside, and they need different first moves. Answer this before you touch anything.

  • You can still log in. Go to the recovery procedure and start at step one. Resist the urge to change your password first. There is one thing that has to happen before that, and skipping it is the reason people run the whole process twice.
  • Your password or your email no longer works. Go to if you are locked out, and check your email inbox before anything else, spam folder included. The easiest route back expires 48 hours after the change.
  • You are not sure anything happened. Read the next section, then open User Settings and then Devices.

How to tell it is actually your account

People usually find out from somebody else, which is a bad way to find out. These are the signs worth acting on:

  • Friends tell you that you sent them a link, a Nitro offer, a crypto giveaway or a "vote for my team" message. You did not.
  • An email from Discord about a password, email address or phone number change you did not make.
  • A login alert from a country you have never been to, or a device that is not yours.
  • A two factor code arriving when you are not logging in. Somebody has your password and is one step away.
  • Servers in your list that you never joined, or a server that removed you for a message you never wrote.
  • In a server you run: webhooks, bots, roles or channel permissions changing when nobody on the team touched them.

The screen that settles it is User Settings, then Devices. It lists every session currently holding your account, with a rough location and a device name for each. If one of them is not you, that is your answer and the procedure below starts now.

Nobody guessed your password

This is worth ten seconds because it decides what you fix. Discord accounts are almost never brute forced. Guessing is slow, it is rate limited, and it is pointless when three cheaper routes exist.

  • A stolen session token. Once you log in, your Discord client holds a token that proves who you are. Anything that can read that token can use your account from anywhere, with no password and no second factor prompt. Microsoft's research on the current generation of information stealers describes the whole business model: harvesting passwords, cookies and session tokens, then shipping them to the attacker (Microsoft Security Blog, June 2026). Sophos documented the Discord flavoured version of it years ago: token loggers built for one platform, quietly shipping stolen tokens out through a webhook (Sophos).
  • A page that looked like the login screen. You typed your details into a copy. If it asked for your two factor code as well, the person running it typed both into the real Discord while you waited.
  • You were persuaded. Scanning a code, approving a prompt, running a command somebody pasted, installing a tool for a game. Nothing was broken into. It was handed over.

All three end in the same place, and that is why the procedure below starts where it does. If the thing that took your credentials is still running on your computer, changing your password only gives it something new to steal.

The recovery procedure

Ten minutes, in this order, from a device you trust. Every step exists for one reason and the reason is written next to it.

  1. Deal with the machine first, because every step after this one is undone by malware that is still running. If you installed a cracked game, a cheat, a free Nitro tool, or you pasted a command into the Windows Run box because a site told you to fix an error that way, assume that is your answer. Run a full scan (on Windows: Windows Security, then Virus and threat protection, then Scan options, then Full scan). If you cannot say with a straight face that the machine is clean, do the rest of this from a different device and reinstall that one later.
  2. Change your password, because it ends every session that is currently signed in as you. User Settings, then My Account, then Change Password. Use a password you have never used anywhere else. The stolen token dies with the old session.
  3. Sign out everything else, because it is the same job done explicitly and it shows you what was there. User Settings, then Devices, then Log Out All Known Devices. It asks for your password and your two factor code, which is the point.
  4. Turn on multi factor authentication if it is off, because it is what stops the next attempt. User Settings, then My Account. Discord offers security keys and passkeys, an authenticator app, and SMS (Discord support). Pick from the top of the table below. Save the backup codes somewhere that is not the computer you just cleaned.
  5. Deauthorize the apps you do not recognise, because these grants are not sessions and your password change did not touch them. User Settings, then Authorized Apps, then Deauthorize on anything you do not remember approving. Discord's own compromised account guidance lists this as its own step for exactly that reason (Discord support).
  6. Check what was changed while they had it, because the account can be handed back to them quietly. On My Account, confirm the email address and phone number are yours. Check your connections. Check the server list for servers you never joined.
  7. Secure the mailbox itself, because a compromised inbox makes every reset above reversible. New password on the email account, two factor on the email account, and a look at its forwarding rules and recovery address.
  8. If you run or moderate a server, read its audit log, because your account had permissions and they get used. Server Settings, then Audit Log, for anything you did not do: bans, role changes, channel permission edits. Then Integrations, and delete any webhook or bot you cannot account for. A webhook is a URL that posts as your server forever, and it does not care that you changed your password.
  9. Tell the people it reached, because your DMs are the next hop. Delete the messages you can still delete, and say so in the servers where it happened. A moderator who can see that you noticed is a moderator who will let you back in.

The step everyone skips: authorized apps

Changing a password logs out sessions. It does not remove the applications you have authorized, which hold their own separate tokens and keep them. That is why "I changed my password and it is still happening" is such a common sentence.

Be clear about what those grants can and cannot do, because guessing here wastes hours. A third party app cannot post messages as you: Discord has no OAuth scope for that. What it can do is add your account to servers and to group DMs on your behalf, which is what the guilds.join and gdm.join scopes exist for, and it can read the profile and email you granted it. So an account that keeps appearing in servers nobody joined is very often an app you approved and forgot, while an account that keeps sending messages is a live session or a machine that is still infected. Fix both. They are cheap to fix and expensive to diagnose from the outside.

If you are locked out

The attacker's first move is usually to change the email address, because that takes the account out of your reach. Discord anticipated this.

  1. Open the mail Discord sent to your old address when the change was confirmed. It carries a Start Account Recovery button that sets the email back and lets you set a new password. The link is generated for your account and is valid for 48 hours. The page it opens always starts with https://discord.com/wasntme/, and anything else with the same story is a second attack (Discord support).
  2. If the 48 hours are gone, or the mail never arrived, file a report. Discord's route for this is dis.gd/hackedaccount. Send it from the email address that was on the account, and include anything that proves the account is yours: when you made it, what it was called, payment receipts if you ever bought Nitro. File once. A second ticket does not move you up the queue, and replies take anywhere from a day to several weeks.
  3. Assume nobody who contacts you about it is Discord. Discord states plainly that its staff do not reach out to users in the app for support matters, and that a request for your details, your code or a payment is not from them. The people watching a compromised account know it is a moment when you will believe almost anything.

Discord is also honest about the limit here: securing your account is your responsibility, and an account that was left without multi factor authentication may not be recoverable at all. That is not a threat, it is arithmetic. Support cannot tell two strangers apart when both of them can quote the same details.

The six ways accounts actually get taken

1. Information stealer malware

Mechanism. A program on your computer reads browser cookies, saved passwords and application tokens, and uploads them. Your two factor setup is irrelevant, because the token it takes was minted after you passed it.

Usual disguise. A cracked game or paid app, a cheat or a mod menu, a "fix" for an error message, or a command a website asks you to paste into the Run box or a terminal. Microsoft's writeup describes the search result poisoning and the paste-this-command trick as two of the main delivery paths in use right now.

Rule. Never paste a command you did not write to fix a problem you did not have. If you pirate software, do it on a machine your accounts have never touched.

2. Phishing login pages

Mechanism. A copy of the Discord login screen on a domain that reads correctly at a glance. Whatever you type is forwarded to the real site in real time, second factor code included, which is why a code that is only valid for thirty seconds is no defence.

Usual disguise. Free Nitro, a beta test invite, a paid commission, an offer of a job, or a "you have been reported and must appeal" message with a countdown in it.

Rule. Never log in from a link. Open Discord yourself. A passkey or a security key removes this attack entirely, because the key checks the real domain and refuses to answer a copy.

3. Malicious authorized apps

Mechanism. You press Authorize on a real Discord consent screen for an application that is not what it claims. The grant it receives survives your password changes until you revoke it by hand.

Usual disguise. A verification step in a server that looks official, a giveaway entry, a Roblox or Minecraft linking tool, an art commission portal.

Rule. Read the permission list on the consent screen instead of the name above it, and walk through User Settings, then Authorized Apps, once a quarter. Anything you cannot place, remove. Reauthorizing something legitimate takes one click.

4. QR code login abuse

Mechanism. The QR code on Discord's desktop login screen exists so your phone can sign a new computer in. It works from any screen. Scanning a code somebody sent you signs their computer into your account, and the code is only alive for two minutes, which is why these are always urgent (Discord support).

Usual disguise. A Nitro gift, a game key, a server captcha, a poster or a pinned image in a server that was itself compromised.

Rule. Only ever scan a QR code that your own browser is displaying, on a screen in front of you, because you chose to log in. Discord asks you to confirm before it completes the login. That prompt is the last chance to press Cancel, so read it.

5. Credential stuffing

Mechanism. Your email and password from some unrelated site that was breached years ago are replayed against Discord by an automated tool. No targeting, no skill, enormous volume.

Usual disguise. None. This one is invisible until it works. It only works on reused passwords.

Rule. A unique password per site, from a password manager. Google's year long study with New York University and UC San Diego found that even a code sent by SMS blocked 100% of the automated bot attacks it measured, so any second factor at all closes this door (Google Security Blog, May 2019).

6. A compromised friend

Mechanism. The message comes from an account you know, because that account was taken an hour ago and is now working through its friend list and its servers. Trust is the exploit.

Usual disguise. "Can you vote for my team", "I accidentally reported you, talk to this admin", "check out this game I am making". Kaspersky has documented the same pattern operating through hijacked Discord invite links, where the destination changes under a link people already trust (Kaspersky).

Rule. Confirm anything odd through a second channel before you act on it. If a friend's message asks you to log in, download or scan, it is not your friend asking.

Which second factor to use

All of these are better than none. They are not equal.

MethodStrengthWhy it ranks there
Passkey or security keyStrongestThe key is tied to the real site, so a copy of the login page has nothing to relay. CISA calls FIDO and WebAuthn the only widely available phishing resistant form of MFA. Discord supports both, on the account page.
Authenticator appStrongThe code is generated on your device and never travels through a phone network, which removes every weakness in the row below. You can still be talked into typing it into a fake page while somebody forwards it.
SMS codeWeak, and still far better than nothingNIST now classes one time codes sent over the phone network as a restricted authenticator, because the assumption that the number belongs to you fails against SIM swaps and number porting. Google's study measured it blocking 100% of automated bots, 96% of bulk phishing and 76% of targeted attacks.
Backup codesNot a factor, a spare keyThey exist so a lost phone is an inconvenience rather than a lost account. Print them or store them offline. A screenshot in your gallery is a file that malware reads.
Password onlyNot MFAOne leak anywhere, one convincing page, and there is nothing between the attacker and the account.

One honest caveat: none of these stops a stolen session token, because the token is issued after you have already passed the check. That is not an argument against MFA. It is the argument for step one of the procedure.

Sources for the two claims above: CISA, Implementing Phishing-Resistant MFA, NIST SP 800-63B-4, and the Google study linked above. Discord's own note on why it pushes MFA is on its blog.

The clock is the tell

Look back at the six routes above and notice what they share. The Nitro offer ends tonight. The QR code dies in two minutes. The appeal form closes in an hour or the ban is permanent. The commission needs an answer now because the client is waiting.

None of that is decoration. A person who has time to check the domain, ask a friend, or open Discord themselves is a person who does not fall for any of it, so the message is built to remove the time. Treat urgency as the signal rather than the pressure. Nothing real on Discord expires while you go and look it up, and if it does, losing it costs you less than the account.

Hardening, so this is the last time

  • A unique password per site. Use a manager. The point is not strength, it is that a breach somewhere else stays somewhere else.
  • A passkey or a security key on Discord and on your email. Your mailbox is the master key to everything, so it deserves the better factor, not the leftover one.
  • Backup codes stored offline. The failure mode you are avoiding is being locked out by your own security a year from now.
  • Authorized Apps reviewed quarterly. It takes a minute and it is the only cleanup nothing else does for you.
  • No pasted commands, ever. Legitimate software does not ask you to type into the Run box.
  • Treat free Nitro as a category, not an event. Nobody is giving it away. Not the person in your DMs, not the bot, not the poster in the server.

If you own or moderate a server

Your account is worth more than a normal one, and the accounts you moderate are the ones attackers land on next.

  • Turn on the two factor requirement for moderation in Server Settings, under Safety Setup, so a taken moderator account cannot start banning people.
  • Hand out the permissions the job needs and no more. Administrator on a moderator role means one stolen phone is a deleted server. The same goes for bots: a bot with Administrator because it was easier is a bot whose token is now worth stealing.
  • Treat webhook URLs like passwords. Anyone holding one can post as your server with no account and no permissions, and they never expire on their own. Delete the ones nobody uses.
  • Raise the verification level. Low requires a verified email, medium requires that the email has been verified for at least five minutes, and the stricter levels ask for time in the server or a verified phone number (Discord support). It is a speed bump, not a wall, and speed bumps work on automated joins.
  • Use AutoMod for the obvious things (AutoMod FAQ), and know its limit: it matches what a message says, and scam text is rewritten every week.
  • Add a honeypot channel, which catches the behaviour instead of the wording. That is the subject of our guide to honeypot channels, and it is the reason many people end up reading this page.
  • Keep your moderation bot's role above the roles it is expected to act on, or it will detect a raid perfectly and be unable to do anything about it.
  • Read Discord's own raid guidance (How to Protect Your Server from Raids 101). It is short and it is written by the people who see every raid.

The checklist

  • Machine scanned, or the account secured from a different device.
  • Password changed, and used nowhere else.
  • Log Out All Known Devices pressed.
  • Multi factor authentication on, with backup codes stored offline.
  • Authorized Apps reviewed and the strangers removed.
  • Email address, phone number and connections confirmed as yours.
  • Email account secured with its own new password and its own second factor.
  • Audit log read and unknown webhooks deleted, on any server you run.
  • Friends and servers told, and the messages you can still delete deleted.

If a server removed you for a message you never wrote, it was very likely running a honeypot channel: a channel nobody is supposed to post in, which exists to catch this exact situation within seconds of it starting. Being caught by one is a good outcome, and most servers will let you back in once you say what happened. Read how honeypot channels work, or if you run a server yourself, add Tickety and set one up. It is free.

Frequently asked questions

How do I know if my Discord account was hacked?

Open User Settings, then Devices. It lists every session currently signed in as you, with a location and a device name, and one you do not recognise settles it. The other common signs are friends receiving links you did not send, an email about a password or email change you did not make, a two factor code arriving when you are not logging in, and servers in your list that you never joined.

My Discord account is sending links I did not write. What do I do first?

Deal with your computer before you touch your password. If malware is still running, it will simply steal the new session. Run a full antivirus scan, or secure the account from a different device, then change your password, log out all known devices, turn on multi factor authentication, and remove any authorized apps you do not recognise.

I changed my password and it is still happening. Why?

Two common reasons. The malware that took your session is still on the machine and simply took the new one, or an application you authorized still holds its own grant, which a password change does not touch. Clean the machine, then go to User Settings, then Authorized Apps, and deauthorize anything you do not recognise.

Can someone use my account without my password?

Yes. After you log in, your client holds a session token that proves who you are, and anything able to read that token can use the account without a password and without triggering your second factor. That is what most Discord account theft actually is, which is why signing out every session is part of recovery.

Someone changed the email on my Discord account. Can I undo it?

Usually, if you act quickly. Discord emails your previous address after the change is confirmed, and that message carries a Start Account Recovery button which is valid for 48 hours and sets the email back. The page it opens always begins with https://discord.com/wasntme/. After that window, report it through dis.gd/hackedaccount.

Will Discord support restore my account?

They may, through the report form at dis.gd/hackedaccount, but there is no guarantee, and replies take anywhere from a day to several weeks. Discord says openly that securing your account is your responsibility and that an account left without multi factor authentication may not be recoverable. File once, from the email address that was on the account, and treat support as the fallback rather than the plan.

Which two factor method should I use on Discord?

A passkey or a security key first, because it is tied to the real site and cannot be relayed by a fake login page. An authenticator app second. SMS last, since NIST now treats phone network codes as a restricted method because of SIM swapping, though it still blocks the automated attacks completely.

I was banned from a server for a message my hacked account sent. Can I get back in?

Often, yes. Many servers use a honeypot channel that removes the account automatically and sends a direct message explaining why, sometimes with a rejoin link attached. Secure your account first, then message the moderators and tell them what happened. Being able to say what you fixed is what gets people back in.

Copyright © 2026 Tickety.top - All Rights Reserved.