Back to Blog
critical SEVERITY January 8, 2026

Discord OAuth App Exploitation Wave

Approximately ~750,000 users potentially affected

Data Exposed:
  • Discord tokens
  • Server memberships
  • DM history
  • Connected accounts

What Happened

Malicious Discord bots posing as game stat trackers have been harvesting OAuth tokens. Compromised accounts are being used to spread malware and crypto scams in gaming servers.

What You Should Do

  1. Review authorized apps in Discord User Settings > Authorized Apps
  2. Remove any suspicious or unknown applications
  3. Enable 2FA on your Discord account immediately
  4. Change your password if you used any third-party bots recently
  5. Check for unknown sessions and log them out

Check If You Were Affected

Use GalaxyWarden to scan for your credentials in this and other breaches.

Scan My Email Free →

Protect yourself from breaches

GalaxyWarden scans 15B+ leaked records. Pair it with these tools for complete protection.

Run a DoxxScan
See exactly what hackers can find about you — reports from $6.99
GalaxyWarden Monitoring 24/7
Real-time breach alerts + AI Warden security assistant + continuous dark web monitoring
NordPass NordPass 56% OFF
Unique passwords + autofill + breach alerts
NordVPN NordVPN 74% OFF
Hide your IP + block malicious sites & trackers
NordProtect NordProtect $0.99/mo
$1M identity theft insurance + credit monitoring
View All Partner Deals →

GalaxyWarden services + partner recommendations

W
AI Warden GalaxyWarden
Checking...
Hey! I'm the GalaxyWarden AI Warden. Got questions about DoxxScan or cybersecurity? I'm here to help! Brandon (the founder) reviews all chats and will follow up personally if needed.