Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

If someone is sending messages from your Discord account, changing your profile, joining servers, or triggering security alerts, treat the account as compromised. A stolen browser session or Discord token is one possible cause, but the same symptoms can result from a stolen password, malicious OAuth authorization, phishing, or malware. Start recovery from a device you trust: secure your email, reset your Discord password, enable MFA, remove unfamiliar Authorized Apps, scan the suspected device, and report the incident through Discord’s official support route.

Signs your Discord session may have been stolen

These signs indicate unauthorized access, but they do not prove that a cookie or token was the specific artifact stolen:

  • Messages, friend requests, crypto scams, free-Nitro offers, giveaway links, or phishing URLs were sent without your involvement.
  • Your account joined servers or sent invitations unexpectedly.
  • A moderator account changed roles, permissions, webhooks, bots, invites, bans, or kicks.
  • Your username, avatar, email address, password, or MFA settings changed.
  • You received an unexpected password-change, login, or email-change notification.
  • An unfamiliar application appears under Authorized Apps.
  • You see unexplained Discord purchases or other billing activity.
  • The compromise followed a cracked game, cheat, unofficial Discord client, fake update, unsolicited file, or “free Nitro” download.
  • Several unrelated accounts were compromised from the same computer. This is especially concerning for infostealer malware.

Discord warns that malicious links and downloads can steal credentials and personal data. See its compromised-account guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do this first: contain the compromise

  1. Stop using the suspected computer for recovery. If you downloaded suspicious software, saw a malware alert, or believe an infostealer is involved, do not repeatedly enter replacement passwords or MFA codes on that device. Use a known-clean phone or computer if possible.
  2. Secure your email account. From the clean device, change its password to a unique one, enable MFA, review recent sign-ins and active sessions, and remove unfamiliar forwarding rules, recovery addresses, phone numbers, app passwords, and third-party access. Search for Discord security emails and preserve them as evidence.
  3. Reset your Discord password. Use a long password that has never been used elsewhere. Discord says that resetting the password generates a new account token, making this a critical containment step. It does not, however, clean an infected computer or secure other services.
  4. Enable MFA. Discord recommends two-factor authentication. Store backup codes securely. MFA is highly effective against password-only attacks, but it cannot undo an already-authorized session and is not a guarantee if malware controls the device.
  5. Review Authorized Apps. On desktop or the web, open User Settings with the cogwheel, then select Authorized Apps. On mobile, tap your avatar, open the cogwheel, and select Authorized Apps. Remove unfamiliar or recently added applications. Removing an OAuth authorization does not prove that malware or a stolen session has been eliminated.
  6. Warn contacts and server members. Use another communication channel where possible. Tell people not to open links or files sent during the incident. Delete scam messages and, if you moderate a server, inspect invites, permissions, roles, webhooks, bots, integrations, and audit logs.
  7. Report the compromise to Discord. Use the official hacked-account form at dis.gd/hackedaccount. Discord says its staff will not contact you directly through the Discord app for support, ask for your password or token, or demand payment for recovery.
  8. Check billing and other accounts. Review Discord purchases, email, password-manager, banking, gaming, social, cloud, work, school, and cryptocurrency accounts.

Recover an account when the email address changed

Check the original email inbox immediately for a message titled “Discord Email Address changed”. Discord says it may contain a temporary option to change the address back. The link can expire, and Discord says support cannot issue a new recovery link after it expires. If it fails, still submit the hacked-account ticket through Discord’s official route.

#1 Best Overall
Sale
HID Corporation 1346 ProxKey III Key Fob Proximity Access Card Keyfob, 1-1/4" Length x 1-1/2" Height x 15/64" Thick (25)
  • Lifetime warranty!
  • Small enough to fit on a key ring
  • Universal compatibility with HID proximity card readers
  • Provides an external number for easy identification and control Can be placed on a key ring for conv
  • Supports formats up to 85 bits, with over 137 billion codes

Never pay a person claiming to be a Discord employee, recovery agent, or security specialist. Do not provide passwords, tokens, MFA codes, backup codes, or payment details to anyone who contacts you in Discord, social media, or a server.

Cookie hijacking versus Discord token theft

A cookie is browser-held data that helps a website maintain a logged-in session. A session or authorization token is a credential representing an authenticated client or account session. A browser-based Discord login can involve cookies and other browser storage, while Discord’s safety materials commonly refer to the account token.

Online terms such as “cookie logger,” “token stealer,” and “session hijacker” are often used loosely. The terminology does not establish what happened. A stolen authenticated session may let an attacker act without entering the password again, but that does not mean every stolen cookie bypasses every MFA control. Treat the event as an account and endpoint incident rather than trying to identify or handle the stolen data yourself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not search for instructions to extract, copy, view, or replay Discord cookies or tokens. Discord says users should never share an authorization token or password.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Can changing the password fix a stolen session?

Password resetting is necessary, and Discord says it creates a new account token. It may invalidate the compromised Discord token, but it is not a complete cleanup:

  • It does not remove malware from the computer.
  • It does not secure the email account.
  • It does not rotate passwords for other services.
  • It does not automatically remove malicious OAuth authorizations.
  • It does not prove that every browser session or third-party account is safe.

If an attacker still controls the endpoint, newly entered credentials or replacement sessions may be stolen again. Clear cookies if you need to force fresh browser logins, but do not treat browser cleanup as a substitute for password rotation, authorization review, session protection, and malware removal.

Clean the computer and other devices

Windows

Windows 10 and Windows 11 include Windows Security and Microsoft Defender Antivirus. Microsoft documents this offline-scan path:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Save your work.
  2. Open Windows Security.
  3. Select Virus & threat protection.
  4. Select Scan options.
  5. Choose Microsoft Defender Offline scan.
  6. Select Scan now.
  7. Allow the computer to restart and scan.
  8. Review the result in Protection history.

Microsoft Defender Offline scans after a restart and outside the normal Windows environment, which can make it harder for persistent malware to hide or interfere. Update Windows and your browsers, remove suspicious browser extensions, uninstall recently installed untrusted software, and review startup applications or scheduled tasks only if you can do so safely.

Rank #3
ETEKJOY 100 PCS 125KHz RFID Key Fob Proximity ID Card Token Tag Keypad Card for Door Entry Access Control System for Security Lock Wholesale, Read Only (Blue)
  • Note: These are 125kHz key fobs (tags). If you want to add them to your lock system, please ensure that your system uses the same frequency of unencrypted 125kHz. Not compatible with other frequencies like 13.56MHz. For example, they don't work for Tuya or TTLock smart locks. Not work for encrypted systems.
  • Compatible with other universal 125kHz tags like EM4100/4102. Not compatible with encrypted tags like HID, Indala, Cobra, APCiK, Paradox, Kaba, Isonas, etc.
  • Read only. Not rewritable. You cannot re-program them. Each key fob is already pre-programmed with a unique ID number. The 10-digit number is engraved on the tag casing.
  • Suitable for 125kHz RFID proximity access control system and ID management system. For example, add it to your RFID door lock if applicable.
  • Approx. Size: 1.4*1.1*0.2 inch. Casing Material: ABS Plastic. Package includes 100 PCS.

A clean scan does not prove that no password, browser session, or OAuth authorization was copied. A detection also does not prove Discord was the only affected service. If malware persists, or multiple accounts were compromised, back up only necessary personal files and consider resetting or reinstalling Windows. Microsoft lists reset or reinstall as an option when malware has caused irreversible changes.

macOS, Android, and iOS

Update the operating system, remove unfamiliar applications and browser extensions, review browser notifications and permissions, and use the platform’s built-in security checks where available. Revoke suspicious app permissions. On mobile, investigate sideloaded apps, malicious links opened in the browser, QR-code scams, email compromise, and possible phone-account or SIM takeover.

Do not factory-reset before preserving essential evidence and confirming that backups will not restore a malicious app or configuration. The key rule is to change recovery credentials from a device you have reasonable grounds to trust.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect every account that may have been exposed

If suspicious malware or a stolen browser profile is involved, prioritize accounts in this order:

Rank #4
10pcs RFID Key Fobs 125khz RFID Writable T5577 fob tag T5577 Proximity ID Card Token Key Tag Rewritable for Access Control Systems & Security Lock
  • Standard 125Khz ID RFID keyfob, support 125khz proximity ID cards token tag duplication. Frequency : 125kHz; Sensing Distance: 2.5 to 10 cm (1 to 4 inch); Data Storage Life: 10 Years
  • Note: These are blank key tags without pre-programmed card numbers. You cannot directly add them to RFID locks or use a card reader to read them. Before using, please write data(card numbers) into them by a 125kHz RFID card writer first.
  • Product Size: 40*30*4mm(1.57*1.18*0.16 inch). High-Quality Copper Coil inside. Casing Material: ABS Plastic. Waterproof and heat-resistant.
  • Chip: ATMEL T5577 (compatible with other universal 125kHz tags). Frequency: 125kHz; It's rewritable, and it can write in 125khz id format and H-ID WG 125khz format, can be customised to 26-bit Prox format. Compatible with T5567 T5577 EM4305.
  • Applications: Hotel key chain, Access control systems, time attendance system, ticketing, packing card. This T5577 proximity key card can copy duplicate em4100 TK4100 ID Card Keychains tags.
  1. Primary email.
  2. Password manager.
  3. Banking and payment accounts.
  4. Steam, Epic Games, Xbox, PlayStation, Riot, Twitch, and other gaming accounts.
  5. Social media.
  6. Cloud storage.
  7. Cryptocurrency wallets and exchanges.
  8. Work, school, and administrator accounts.
  9. Any service that reused the Discord password.

For each important service, change the password from a clean device, revoke active sessions, remove unfamiliar OAuth apps, rotate API keys or app passwords, verify recovery details and MFA methods, and review recent activity and transactions.

Distinguish credential exposure from session exposure. A stolen browser session can expose multiple services that were logged in within the same browser profile, even when those services used different passwords.

If you own or moderate a Discord server

A compromised moderator account can be used to impersonate you or change server settings. Remove malicious messages, inspect recent invites, review audit logs, and verify roles, permission overwrites, webhooks, bots, integrations, and member changes. Temporarily restrict suspicious links and new-member permissions while investigating. Warn members not to download files or follow links sent during the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Unauthorized purchases

Contact Discord billing or support and include the requested billing information. Discord warns that a direct chargeback may result in account suspension while it investigates and directs users toward its billing support process. If your card or payment account may be compromised, contact the issuer promptly as well. Do not delay reporting genuine financial fraud merely to preserve a Discord account; follow the current instructions and terms of both Discord and your financial institution.

Best Value
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Preserve evidence safely

Save Discord security emails, approximate dates and times, screenshots of unauthorized activity, suspicious download names and URLs, server invite links, application names, malware-detection results, billing records, support ticket numbers, and relevant server audit-log entries.

Redact passwords, tokens, MFA codes, payment details, and unnecessary personal information. Never forward stolen session data as “proof.”

What not to do

  • Do not send passwords, tokens, backup codes, MFA codes, or payment information to supposed Discord staff.
  • Do not download unofficial “token reset,” “Discord recovery,” or “account cleaner” tools.
  • Do not keep changing passwords on a computer that may still be infected.
  • Do not assume an antivirus scan proves complete recovery.
  • Do not assume MFA repairs an already-authorized session.
  • Do not pay a social-media “hacker recovery” service without independent verification.
  • Do not assume that a Discord compromise came from Discord itself. A separate October 2025 incident involved Discord’s customer-service vendor 5CA; Discord described it as a vendor compromise, not a breach of Discord.

How to prevent another compromise

  • Use a unique, strong Discord password and never reuse it.
  • Enable MFA and store backup codes securely.
  • Keep the operating system, browser, Discord app, and security tools updated.
  • Avoid cracked software, cheats, unofficial clients, fake updates, unsolicited files, and “free Nitro” offers.
  • Never scan login QR codes sent by strangers, giveaway accounts, alleged moderators, or supposed support staff. Discord says changing the password immediately after accidentally scanning a suspicious QR code invalidates the current account token.
  • Review Authorized Apps periodically.
  • Protect the email account used for Discord with a unique password and MFA.
  • Use a password manager and avoid storing all services in an unprotected browser profile.

Do you need paid antivirus software?

Buying security software is not required to recover a Discord account. First use a clean device, rotate credentials, review authorizations, and run the built-in security tools.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On Windows, start with Windows Security and Microsoft Defender Offline. Malwarebytes may be useful as an optional second opinion or for ongoing protection; its current plans and prices vary by country, device count, and billing term. Its paid features can include real-time protection, scheduled scans, and web protection, but Malwarebytes cannot revoke a Discord session, secure email, or repair server damage. Avoid running multiple real-time antivirus products simultaneously; Microsoft warns that this can cause conflicts.

Escalate to a reputable local incident-response or computer-repair professional if malware persists, several accounts are compromised, or you cannot safely reset or reinstall the system.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.