discord has a security problem

Sdílet
Vložit
  • čas přidán 27. 08. 2024
  • Discord accounts have been getting hacked and this method in particular caught my eye.
    ↣ Get Members only perks at iamlucid.com
    pls subscribe: iamluc.id
    ★ STAY LUCID
    ↣ Get a real life V-Card
    - iamlucid.com
    ↣ Donate crypto to lucid
    - iamlucid.io
    ↣ WhatsApp Channel
    - iamlucid.chat
    - / discord
    - / iamlucid
    - / iamlucid
    - / iamlucid.com
    #iamLucid
    About iamLucid:
    I make videos on Lucid Dreaming, the Dark web, Self-growth, Virtual reality, and other thought-provoking content because the internet needs it.
    discord has a security problem
    • discord has a security...
    iamLucid
    / iamlucid

Komentáře • 1,2K

  • @iamLucid
    @iamLucid  Před 2 lety +390

    Join the homies and intellectual discussions we have regularly iamlucid.gg

    • @VirtualModz
      @VirtualModz Před 2 lety +1

      lucid get the webhook from the exe file (it should be in there somewhere) and you can get access to pretty much all the channels from their hacking server

    • @ULTRAMAGATRUMP
      @ULTRAMAGATRUMP Před 2 lety +1

      Off topic but are u gonna make zenith vr vids?

    • @FriendlyChemist1
      @FriendlyChemist1 Před 2 lety +1

      Got banned for no reason, need help

    • @cash2742
      @cash2742 Před 2 lety

      Lucid makes the best vids

    • @vijeyyyy431
      @vijeyyyy431 Před 2 lety

      cant bc im banned 😭

  • @Mr.Craftastic
    @Mr.Craftastic Před 2 lety +1187

    Remember bois.
    They can’t steal your money if you don’t have any money.

    • @itzlqmer6084
      @itzlqmer6084 Před 2 lety +14

      @@mo-fo joe dada

    • @theincarnateofkurro
      @theincarnateofkurro Před 2 lety +7

      @@itzlqmer6084 cant make a your dad joke if you're an orphan

    • @Ev3rly
      @Ev3rly Před 2 lety +5

      @@theincarnateofkurro but they can make an orphan joke. They can’t make an orphan joke if you’re dead

    • @theincarnateofkurro
      @theincarnateofkurro Před 2 lety +4

      @@Ev3rly can make a death joke. cant make a dead joke if you never existed

    • @varietyban3552
      @varietyban3552 Před 2 lety +1

      @@theincarnateofkurro so everyone can make a joke on me rn???!?!??!?! 😭😭😱😱

  • @r3za_
    @r3za_ Před 2 lety +1134

    Definitely something that the wider community needs to be aware and cautious of.

    • @Berksys
      @Berksys Před 2 lety +2

      Hello

    • @r3za_
      @r3za_ Před 2 lety +1

      @@Berksys you should be asleep, and so should I 😂

    • @r3za_
      @r3za_ Před 2 lety +1

      @@mo-fo yessir 💪

    • @Berksys
      @Berksys Před 2 lety +1

      @@r3za_ fam, if u fully knew me, u would know i never sleep

    • @Cookiekeks
      @Cookiekeks Před 2 lety +3

      Bro he executed a random .exe file. That's something anyone should be aware of not to do

  • @Revzz
    @Revzz Před 2 lety +500

    2:17 unfortunately, there's this whole community on discord dedicated to joining each others' servers just to get bigger servers and server boosts
    nonetheless, great video bro

    • @skrull8478
      @skrull8478 Před 2 lety +23

      yeah its cringe asf

    • @afriking
      @afriking Před 2 lety +34

      what no pussy and no life value does to someone

    • @viktigboy1976
      @viktigboy1976 Před 2 lety

      i own a 3,5k j4j server. it really helps server development and is a gift to the community!

    • @user-sb7wj1vn4x
      @user-sb7wj1vn4x Před 2 lety

      nobody on your server is there for you, always remember that. pretty pointless if you ask me.

    • @raizel2601
      @raizel2601 Před 2 lety

      @@dayfay PAIN

  • @johnnyfrankenstein0123
    @johnnyfrankenstein0123 Před 2 lety +83

    this is like unlocking your door and opening it for a person holding a machete and then blaming the lock manufacturer for your injury

    • @cushyuu
      @cushyuu Před 2 lety +4

      this would never happen if discord security is good

    • @Matthewkyos
      @Matthewkyos Před 2 lety +15

      @@cushyuu This would never happen if people didn't join random servers with random people who aren't well known in the community

    • @cushyuu
      @cushyuu Před 2 lety

      @@Matthewkyos thats not the cause of it

    • @Matthewkyos
      @Matthewkyos Před 2 lety +1

      @@cushyuu Eh still people's fault for doing it

    • @CreepyTroller
      @CreepyTroller Před 2 lety +9

      @@cushyuu Shit like this wouldn’t happen if people weren’t stupid enough to click untrusted links and download random ass files discord security is not the best but at the end of the day if you’re stupid enough to have this happen to someone it’s their fault not discord’s

  • @ShortHax
    @ShortHax Před 2 lety +630

    Discord danger number 1 for me:
    *Hentai Servers*

  • @Mj-ym4fg
    @Mj-ym4fg Před 2 lety +41

    Everyone gangsta until 5 friends dm you about a hacker, then the hacker dm you

  • @1unk
    @1unk Před 2 lety +245

    4:24 they probably used a bot command to ban you, so they pinged you for the bot to know who to ban

  • @SpecialOpsPepe
    @SpecialOpsPepe Před 2 lety +277

    Wonder if discord will even shut their discord server down, or even take any action at all, if they knowingly neglect to take action against fraud on their own platform I'd imagine that end in a pretty nasty lawsuit.

    • @chrisi3311
      @chrisi3311 Před 2 lety +13

      There is no way for them to prevent this since tokens are saved locally on your device meaning malicious actors can send you a file that you run and it will dig through your computer for the token that is stored
      It is not discord’s fault this is happening to people it is the users. People will just have to learn sadly

    • @SpecialOpsPepe
      @SpecialOpsPepe Před 2 lety

      Never said it was directly, I'm simply pointing out the fact that if they're aware of this happening and don't at the very least try to investigate the wrong doings and take some sort of action, which is something they certainly can do, then they aren't contributing to solving the problem. Especially if there's a server being excessively boosted by stolen accounts which I'd bet is the case here,.

    • @chrisi3311
      @chrisi3311 Před 2 lety

      @@SpecialOpsPepe the servers that boosted so get taken down after it is reported

    • @asciidude
      @asciidude Před 2 lety +2

      Discord is constantly shutting down tons and tons of scam servers - for example (not much of a scam server, but still illegal) the Synapse Roblox exploit server has at least been shut down and the owner's account deleted 100 times

    • @lillious
      @lillious Před 2 lety +2

      Discord isn't responsible for yours or anyone's content uploaded to their servers. Same goes with Facebook and other social media's. Read the terms of use and community guidelines.

  • @pixums
    @pixums Před 2 lety +28

    finally this comes to light i've been telling people about this forever

  • @Megaheropap
    @Megaheropap Před 2 lety +68

    I suggested Discord to add a feature that emails you or texts you if someone logs into your account even if it is through token but they denied the suggestion...

    • @kaaskabaal
      @kaaskabaal Před 2 lety +3

      Id the person loggs in your account you get a email with there ip address

    • @DrShockz
      @DrShockz Před 2 lety +6

      A token isn't a log in. Treat it like they just took your computer and opened discord. A token is just so you don't have to constantly log into discord everytime you open it.

    • @RealTkco
      @RealTkco Před 2 lety +1

      This wouldn't fix it, a token aint a password or logging you in, it is that "sessions" login, if you login you get a token, if that token is snatched then like roblox, you have to logout for it to reset, not sure if that works on discord or not

    • @Megaheropap
      @Megaheropap Před 2 lety

      @@RealTkco When you login to token though you are sending request to them right?

    • @Megaheropap
      @Megaheropap Před 2 lety

      @@Parritz Can't they make one? When loging in with token, they are requesting for the user they are logging into all their information in their account. They can just add a request when someone logs in whether it is through login or token and can send to the user email.

  • @4ui7
    @4ui7 Před 2 lety +66

    can’t believe some mfs are comping discord accounts just to boost their discord server ☠️ there is no worse level of Downbad

    • @wasssted
      @wasssted Před 2 lety +7

      Imagine hacking someone just because you want a girl doing "cute" faces on your pfp...

    • @llllIllIIl
      @llllIllIIl Před 2 lety

      fr, u getting no personal gain but boosts on a server, thats gonna get refunded then banned. so cringe

    • @laughman
      @laughman Před 2 lety

      its not downbad its pathetic and cringe.

    • @ervobeats
      @ervobeats Před 2 lety

      yup

  • @notdayday
    @notdayday Před 2 lety +85

    I can't believe how big discord is, and it literally can not afford time for better security.

    • @chrisi3311
      @chrisi3311 Před 2 lety +9

      Discord can not fix this it’s sad to say but it is true
      Your token to log into discord is saved on your computer meaning that when that file runs on your computer it heads to the file it is saved in takes it and sends it to the discord server

    • @oppressormk2594
      @oppressormk2594 Před 2 lety +4

      @@chrisi3311 Discord should make it so requests to the Discord API by the Discord Client will only be authorized if it is by the IP that logged in and validated said token, it will stop many of these attempts.

    • @toyb-chan7849
      @toyb-chan7849 Před 2 lety +3

      @@oppressormk2594 Better to bind it to some hardware combination of your PC. IP addresses change often.

  • @winter2123
    @winter2123 Před 2 lety +6

    smh people really got nothing better to do, stay safe out there y'all

  • @Cookiekeks
    @Cookiekeks Před 2 lety +5

    *guy executes random executable from the internet*
    *gets hacked*
    "dIsCoRd hAs a sEcuRiTy pRobLeM"

  • @Todd_Klabunde
    @Todd_Klabunde Před 2 lety +4

    this has been happening since like 2019. its not really big news but im glad youre bringing awareness to it. happens on roblox a lot too, people get scammed out of hundreds of dollars.

  • @Skikopl
    @Skikopl Před 2 lety +3

    I dont understand why not more people talk about this issue. Especially Discord, I feel like they are doing nothing against this issue. Great Video lucid, thanks for talking about this.

  • @gabe_itches8461
    @gabe_itches8461 Před 2 lety +7

    Lucid I just wanna tell u that ur a really fucking good speaker I could tbh listen to u for so long without getting bored. Wish my teachers could be more like that

  • @Akab
    @Akab Před 2 lety +149

    The fact that the literally log their stolen accounts on a DISCORD server should make it so easy to find for discord but they still dont... wtf.
    It's like storing the money from a bank heist in the same bank xD

    • @chrisi3311
      @chrisi3311 Před 2 lety +2

      Yep it is pretty sad that they don’t check the discord web socket connections for the data that is being sent

    • @chrisi3311
      @chrisi3311 Před 2 lety

      @@TickingEnum I am talking about the malicious file that people click it sends the information to a discord web-hook usually.
      I understand how Authentication tokens work, what I was saying is discord sadly does not check what is being sent through the web-socket connection

    • @chrisi3311
      @chrisi3311 Před 2 lety

      @@TickingEnum when you are sending the information to the discord web socket they are able to read it since it is going through there server if they realize a web socket is being used maliciously they can shut it down

    • @sebf98s90fh2
      @sebf98s90fh2 Před 2 lety +1

      Ain't it a webhook not a web socket

    • @chrisi3311
      @chrisi3311 Před 2 lety

      @@sebf98s90fh2 it is a webhook for discord under server management in any server you are a admin in. Sorry if I said web socket I was on mobile.

  • @chrisi3311
    @chrisi3311 Před 2 lety +29

    There is no way to prevent this sadly it all comes down to common sense if someone sends you a file through discord just don’t open it even if it is from your friend, The reason why there is no fix to this is because authentication tokens exist to make the login process quicker. With most of the code that is used to token log can all so be used for more sketchy stuff like stealing tokens for other websites since it is pulling the information that your browser has saved.

    • @ReptilianXHologram
      @ReptilianXHologram Před 2 lety

      ...so would you say instead of opening the file through discord that they are trying to link you then you should open the file in another tab and physically type out the address of the link of that file to see where it goes?

    • @chrisi3311
      @chrisi3311 Před 2 lety

      @@ReptilianXHologram no the file that they send you you can make into readable text see we’re the link goes to and then report that link to discord

  • @devarsh2846
    @devarsh2846 Před 2 lety +60

    This is no joke bro, discord has to take this seriously.

    • @drownindesigner
      @drownindesigner Před 2 lety +11

      not discords fault. it's the users for downloading sketchy files

    • @Four-fi1fr
      @Four-fi1fr Před 2 lety +2

      @@drownindesigner Correction: Discord's fault for hiring incompetent developers who put zero effort into making good security. User's fault for their lack of common sense.

    • @itsyaboivoid
      @itsyaboivoid Před 2 lety +2

      @@Four-fi1fr it's not discord fault that ur token is leaked.

    • @Zappy-ray777
      @Zappy-ray777 Před rokem

      @@itsyaboivoid you just,gotta be careful.

  • @arafathchowdhury2437
    @arafathchowdhury2437 Před 2 lety +4

    It's not just discord, any popular platform is subject to this type of attack there isn't much you can really do about it personally, not even discord can do much about it. They can add better safety measures to make it harder but the attacks will still be there. It's not like discord can get rid of authentication tokens or cookies. There just really isn't anything you can do about it besides not downloading random things people send you.

    • @Gamer-ct6hb
      @Gamer-ct6hb Před 2 lety

      That's why i use firefox which has a feature for encrypted password manager which i store my randomly generated passwords in and a auto-delete all cookies option when you close firefox.
      Even a virus could not access my discord account or any other account for that matter
      edit: if you don't wanna do that shit and give up your browser for firefox you could just enable controlled folder access on firefox folders only which will give you a message when a program tries to get into that folder tho i think it can be bypassed by viruses by disabling controlled folder access (But all viruses are dumb as shit so they wont do that)

    • @Zappy-ray777
      @Zappy-ray777 Před rokem

      Be careful out here.

  • @LCKarting
    @LCKarting Před 2 lety +1

    my friend got hacked today on discord, i joined a discord call with 2 other friends and one was screensharing. the messages were about a virus about rating a game or something. I then went ahead and talked with the hacker, didn’t make any suspicions on purpose and asked him what his name was bc i “forgot” and the hacker replied with “lol stop kidding”. a few hours later my friend that had been hacked messaged me back saying “yo wtf i didnt send that shit” ya’ll stay safe out there, DON’T CLICK LINKS THAT LOOK DODGY!

  • @Bread-nx9fo
    @Bread-nx9fo Před 2 lety +1

    bro this is seriously a felony, someone should contact the police or something because this shit can breach international privacy laws, passwords and other shit is sold maliciously online to other people.

  • @sascha284
    @sascha284 Před 2 lety +8

    i was in discord when they showed you the hack :D
    its actually pretty interesting how fast it can happen and that it bypasses stuff like windows defender

    • @DrShockz
      @DrShockz Před 2 lety +2

      All it does is read a file. Not a windows defender problem.

    • @silarious9014
      @silarious9014 Před 2 lety +2

      @@DrShockz It sure as hell is a windows defender problem, they are super anal about any exe you download why it wouldn't do the same for this malware is likely due to the fact that the user disabled defender on downloaded files thus its actually user error.

  • @jaiywlk
    @jaiywlk Před 2 lety +5

    Sees notification on my phone.
    Instantly deletes discord and THEN proceeds to watch lucid video

  • @410gone
    @410gone Před 2 lety +2

    The token is the gateway to the entire API. There is no easy solution to change ALL of it without practically rewriting discord.

  • @mrcaakg8262
    @mrcaakg8262 Před 2 lety +43

    8:30 "It's not anybody's fault besides discords themselves."
    It absolutely is not discord's fault. It is almost entirely the fault of the end user. Running a random executable someone gives you is breaking the #1 rule of using the internet. Even if it's from a friend that you supposedly trust, you have no idea what that executable can be doing, as you cannot see the source code.
    Also, you should Never, never, never, NEVER store credit card information or information regarding your personal address in plaintext. Never. That is a commandment.
    So even if this person had run the executable, had they not stored their personal information, the breach of security would have been much less severe. It's not that hard, just type it in every time you want to pay for something. Better safe than sorry.
    Regardless, there is more than discord could be doing to mitigate this issue. For instance, if someone sends you some sort of file that executes some sort of code or process on your machine, discord could display a caution before you download, along with some basic internet safety tips. But when you say discord is completely at fault, what exactly do you expect them to do? Disable uploading executables? Require executables to be from a verified publisher? Do away with tokens? Filesharing on discord is merely a tool, and a tool can be used for both good or bad. But if you're ignorant and automatically trust every file that is sent your way, you are practically asking to have your account breached/stolen.

    • @tsarbomba2239
      @tsarbomba2239 Před 2 lety +5

      Bruh exactly lmao, this guy is over exaggerating this a lot too, it made me cringe a few times. He acts like its such a big deal and like hes so unlucky that it happened to him when in reality its the internet and if you expect anything less you shouldnt even be on the internet, and then he blames shit on discord themselves rofl

    • @WSH3TM
      @WSH3TM Před 2 lety

      you do understand that your ID translated to base64 gives the first half of your token right? after that its just a few minutes of bruteforce and bobs your uncle. Its not always the user's fault.

    • @mrcaakg8262
      @mrcaakg8262 Před 2 lety +4

      ​@@WSH3TM Regardless if you have the first "half" of the token, which is, in fact, an encoded version of your ID, there are still 32 Base64 characters left that you would have to guess. I'm not sure you realize how many possible permutations a length of 32 Base64 characters can produce, but I will leave you to do the math for yourself. Let's assume that the wordlist you've generated isn't around the number of atoms that exist in the observable universe, do you have any entire how long it takes to bruteforce a secret over the internet? You would have to have an interval between every login attempt to avoid being rate limited or even a timeout, which severely increases the time it would take to bruteforce it.
      Yes, it does contain your user ID in *some* of the token. But Discord isn't stupid. There's a reason it's used, and it's not inherently insecure. The only way, in this case, that you would be able to grab the token is by having admin permissions on the user's local machine at the time of logon. And how do you do that? You guessed it, an executable!

    • @lillious
      @lillious Před 2 lety

      @@WSH3TM This isn't even remotely true. Also goodluck brute forcing that lmao, that will take millions of decades.

    • @WSH3TM
      @WSH3TM Před 2 lety

      Are you crazy? I'm losing brain cells talking to you give me your username and ill let you talk to my friends

  • @hades7059
    @hades7059 Před 2 lety +16

    funny thing is its not even hard to do so grabbing tokens, discord needs to fix up their security shit no kizzy
    edit: it got taken out of context

    • @Cookiekeks
      @Cookiekeks Před 2 lety +2

      What should they do? Not use cookies for authetication? It's not discords fault that people execute random files on their PCd

    • @chrisi3311
      @chrisi3311 Před 2 lety +1

      @@Cookiekeks exactly there is no way for discord to fix this authentication tokens are in Maloney every website/web app. There is not way for discord to fix this hades

    • @Cookiekeks
      @Cookiekeks Před 2 lety

      @@chrisi3311 Exactly.

    • @hades7059
      @hades7059 Před 2 lety

      @@Cookiekeksand its not peoples fault that they open up exe files from people that they trust, the thing that discord could do is that the exe file seems to be suspicious are you sure you want to open it, cuz sure as hell they put it on links.

    • @Cookiekeks
      @Cookiekeks Před 2 lety

      @@hades7059 How the heck should discord warn you when you open random files on your computer? Should it track every file you open??

  • @Monstermakesarts
    @Monstermakesarts Před 2 lety +71

    *Lucid: they kept running, why are they running*
    *Me in my head: WHY aRe YoU RunNing*
    😂
    Make sure to eat and stay hydrated homies

  • @lvckyz
    @lvckyz Před 2 lety +2

    That's why you should most of the times always "Delete payment method" if you're worried about this happening

  • @srussell31
    @srussell31 Před 2 lety +2

    My Discord server isn't huge (865 members) but we've had a couple of "Free Nitro" spam attacks. It was from a new account so I set Dyno bot to autoban newly created accounts to help with security as much as possible. This hacking/spamming/trolling thing is so annoying. Thanks for bringing this to everyone's attention!

    • @itzlqmer6084
      @itzlqmer6084 Před 2 lety +1

      I disabled links and blacklisted csgo nitro

  • @devingibbs3846
    @devingibbs3846 Před 2 lety +11

    this shit was crazy bro
    7:59 😂😂

  • @yami.2333
    @yami.2333 Před 2 lety +41

    I was shocked when it happened and Zead told us about it , and still am . Please stay safe and always question links sent even by your closest friends until discord solves this !

    • @gang12325
      @gang12325 Před 2 lety

      Thats literally why I question every link my friends send me even with my hacking knowledge vpns static ip etc. I still question links

  • @user-ub9md6ce1b
    @user-ub9md6ce1b Před 2 lety +1

    Yeah this is why I don’t put any info into discord. They really need to fix it so people can’t just take some letters and numbers to have ur info

  • @ralrem4005
    @ralrem4005 Před 2 lety +1

    Ngl I don’t get why ppl get hacked so often it’s not difficult to stay safe nowadays.

  • @soulsniper7398
    @soulsniper7398 Před 2 lety +24

    I think when it comes to making your own bot for your discord server, there should be some more verification steps. Most people don't really care about the idea of a strong system. This becomes a problem when it's people you cannot trust making programed bots.

    • @ishid_anfarded_king
      @ishid_anfarded_king Před 2 lety

      official bots already do, you cannot add your own bots to other servers without the administrator approval, however these petty scammers are using NORMAL ACCOUNTS to make bots, which is against tos.

  • @frames695
    @frames695 Před 2 lety +55

    I disagree with you about how it's discord's fault. The user ran that file not knowing about the token/cookie logger. It's no one's fault however I do believe discord can improve their auth system by making the auth token change every time you log in or log out, or just overchange every 24hrs. This will avoid hackers because it will expire the old token and have the new token in place.

    • @withincode6848
      @withincode6848 Před 2 lety +9

      If you run the code though they could easily get persistence and just constantly watch your PC for token changes. All discord can really do is warn people about random files.

    • @xymare1748
      @xymare1748 Před 2 lety +4

      @@withincode6848 yeah honestly, just don't download random fucking things

    • @alaninnovates6353
      @alaninnovates6353 Před 2 lety +1

      You are barking up the wrong tree here. That's pretty unreasonable. A JWT token is stored in their database, each user is assigned it. you aren't thinking about scalability at all. the token should only be changed when a password is changed or such. if everybody token changes every 24 hours or when they log in/out that means millions of database writes JUST to change tokens. think about that, added onto the already millions of messages per day. that would scale horribly and would cause them to need to spend much more on actual computer hardware rather than making more features.

    • @lillious
      @lillious Před 2 lety

      @@alaninnovates6353 tokens are changed every time a user logs in. It's not that hard on their servers lol. Literally all you have to do to prevent them from doing this is (if you've already logged in and they stole the token) log out and log back in on another uncompromised device. The way that you describe a JWT token literally points to the fact you have no idea what you're talking about. Tokens aren't used for anything besides user sessions.

    • @alaninnovates6353
      @alaninnovates6353 Před 2 lety +1

      @@lillious Are they? Last time I checked, they were only changed when you changed your password, which is how the token is generated in the first place. Additionally, JWT's are used for authentication on the backend, sent from the frontend (normally) as a header. Any request to discord's API requires you to have a token. They are not JUST for sessions. They are for the authentication of every single request.

  • @megumin2562
    @megumin2562 Před 2 lety

    A big server got hacked too and all the channels and mods where banned luckily it wasn't the owner but its so crazy how easily you can get hacked just for the hacker to ruin the server . Honestly discord needs to do something soon or it's gonna be one big fine

  • @goodtyme
    @goodtyme Před 2 lety +2

    ive been in multiple servers warning people to not download stuff like that. no offense to your friend but its kinda his fault, its common sense to not download that kind of stuff

  •  Před 2 lety +2

    Token Grabbing is so dangerous

    • @piranhaz
      @piranhaz Před 2 lety

      Fr i remember someone got token logged in my server

  • @bee6687
    @bee6687 Před 2 lety +7

    Ayo lucid! it’s always feels good to see you ly❤️

  • @Giingu
    @Giingu Před 2 lety

    I've talked with several discord employees because i have friends who knows them irl, they keep saying they are working on it but i never see any improvements, this could be fixed EASELY, but they simply dont care, why do you think they dont allow more than one nitro refund? Well, because if you get hacked again, or someone hacks you and you dont notice then they are the ones getting the money. Discord does NOT care about their members, not even the people making their platform work, the server owners.

  • @ACID_MENTE
    @ACID_MENTE Před 2 lety

    bein tgd ain a problem on just discord, issa problem everywhere

  • @12Rosen
    @12Rosen Před 2 lety +4

    This is in no way, shape, or form Discord’s fault. It is not Discord’s fault that they downloaded something and ran it. I should also add that no one just ‘gets hacked.’ If someone gets hacked they always ran something, clicked something, etc.

  • @TriiCkS-YT
    @TriiCkS-YT Před 2 lety +7

    Hes really lucky they didn’t completely take over his pc since it wouldn’t be hard for them to do so

  • @yuhmasy
    @yuhmasy Před 2 lety +1

    Steam scam is taking over discord right now, I'm moderator in a server of 100k members and I ban more than 5 users everyday sending nitro links which is really dangerous if u click it
    Appreciated this video ❤️

  • @leordeansg
    @leordeansg Před 2 lety

    happened to me as well, but discord does not give a fuck "you need to protect your own account" apparently

  • @laughman
    @laughman Před 2 lety +3

    Imagine a place..... where hackers and pedophiles and scammers exist.

  • @ponalo9503
    @ponalo9503 Před 2 lety +3

    ''Discord has a security problem''
    Yep, the floor is made of floor

  • @sziorvana4346
    @sziorvana4346 Před 2 lety +1

    This happened to me a year ago so I know how scary it is, stay out there everyone.

  • @DatBoyJaden
    @DatBoyJaden Před 2 lety

    at this point Don’t trust ANYONE on discord, don’t trust any suspicious message, make sure you monitor how your friends talk and make sure you don’t get scammed because if these people get a hold of your address or IP it’s over. 😕

  • @applekid6275
    @applekid6275 Před 2 lety +4

    I think you just shouldn't download stuff from your discord "friends" because as you can see its no good

  • @i_-am_rico3726
    @i_-am_rico3726 Před 2 lety +5

    Someone needs to reach out to someone that works for discord or some shit because they can’t stick with the same security that they have right now.

  • @goqurts
    @goqurts Před 2 lety +2

    one thing to always remember: NEVER CLICK LINKS FROM RANDOM PEOPLE

  • @pilvax9402
    @pilvax9402 Před 2 lety

    Discord's security system was always trash and always will be. My account was hacked like 9 times and they don't seem to give a shit even after I've emailed them.

  • @sheriffbb
    @sheriffbb Před 2 lety +2

    3:41 bussy 🥶🥶

  • @WiffleYK
    @WiffleYK Před 2 lety +37

    Dang i never knew Discord security was this bad

    • @erixccjc2143
      @erixccjc2143 Před 2 lety +1

      @@Parritz fax, It rlly takes less than 2 lines of code in an exe to completely destroy your windows

    • @gmddolbaeb2191
      @gmddolbaeb2191 Před 2 lety

      @@Parritz it is

  • @wowgodz-5349
    @wowgodz-5349 Před 2 lety +2

    tokens should just change at every login

  • @glenn7046
    @glenn7046 Před 2 lety +2

    When my account got hacked like 2 months ago, I emailed Discord so many times, so many dudes I tried to work with, but none helped me out. a few weeks later my account is deleted. Discord has a serious security and support issue.

  • @zaskou1549
    @zaskou1549 Před 2 lety +8

    Tip to keep your account relatively safe:
    After every purchase on your discord account, clear/delete the credit card information off of it. If you have nitro, fill in the card information the day before you're supposed to be charged, then remove it the day after. It's a pain in the ass, but it will keep your credit card info safe even if someone logs into your account.
    I can't believe discord security is so bad that we have to find ways to prevent hackers on our own.

  • @stretch8323
    @stretch8323 Před 2 lety +4

    Their probably were using Lunar Builder binded to Itrouble, or mercurial. most likely Lunar, how I know is I used to do that, except i never carded someone

    • @sebf98s90fh2
      @sebf98s90fh2 Před 2 lety +1

      I was thinking it's more piratestealer type deal

  • @darraghd493
    @darraghd493 Před 2 lety

    Token Logging, token Generating and more is widespread but it's common on Discord due to it's notoriety and benefits. Tokens are a common authentication method is not a security issue that someone downloaded a file onto their PC and got logged, generating has a low percentage of working so that can easily be ignored for now and it's so easy to change your token; all you have to do is change either your email or your password.

  • @stuff_
    @stuff_ Před 2 lety

    this is why most higher ranked people should have 2fa enabled, token logged accs can be reset after changing password and the token resets

  • @FlashieBoi
    @FlashieBoi Před 2 lety +2

    Bro actually went that far for fucking discord nitro

  • @AjayFinster
    @AjayFinster Před 2 lety +3

    Instead of buying nitro on my main account. I get a google play giftcard and log into a alt and gift nitro to my main so then if my account ever gets hacked they cant get my address etc

  • @hipyoungmomof1
    @hipyoungmomof1 Před 2 lety

    this has been a other issue too with a russian hacker who hack steam and discord accounts from there they promote nitro and csgo skins and knifes its the same message and its really big

  • @DESIADGIO
    @DESIADGIO Před 2 lety +2

    My discord got hacked like 3 weeks ago so I can understand your frustration lol

  • @HeilJake
    @HeilJake Před 2 lety +3

    simply: dont download sketchy shii

  • @fakelonk4605
    @fakelonk4605 Před 2 lety +3

    I actually fell for one of these and my account got compromised. But, revenge story: when they didn't suspect Discord Support would be able to recover my account, I recovered the account and much to my surprise the account had admin in a lot of shady, phishing-esque servers, and I DELETED all of them channel for channel, person for person. Isn't that just hilarious? LOL. Anyways sorry this happened and hope you guys give these shitheads what they deserve.

  • @BullyGarfield.
    @BullyGarfield. Před 2 lety

    boys i just relapsed on nofap. i failed nnn. all good tho we start over. we take those. i will never give up

  • @MrSprite19
    @MrSprite19 Před 2 lety

    I made a ticket 5 months ago to help them make a good security, but they said " We don't need your help.." and stuff

  • @DevilRx
    @DevilRx Před 2 lety +4

    Love From Bangladesh 🇧🇩❤️

  • @MysticGodsDCUOop
    @MysticGodsDCUOop Před 2 lety +6

    Deng I remember when lucid had nice luscious hair in his videos 😭 now I think he don’t care be rolling out the bed n shit lmao

  • @_otroll5393
    @_otroll5393 Před 2 lety

    It’s crazy because they have all these protocols to prevent pulling ips, but zero shits are given to the actual account token itself. It’s kinda bullshit tbh.

  • @Ninesniper
    @Ninesniper Před 2 lety

    I feel like all these social media sites done really give a fuck about anyone besides themselves it’s all about the money and popularity

  • @louischinkey
    @louischinkey Před 2 lety +4

    This was very interesting lucid

  • @ahmar.
    @ahmar. Před 2 lety +4

    If discord allows pedos and other shit, getting hacked should be expected

  • @supremetaco5349
    @supremetaco5349 Před 2 lety +2

    My day always gets better when you upload man. Keep it up.

  • @Whyarenoneofthehandlesavailabl

    Ok so don’t call a hacker they can pull ips from being in a call with you(if you don’t have a vpn) like this so lucid sees this so he knows in case he didn’t

  • @Komatic5
    @Komatic5 Před 2 lety +6

    What’s really frustrating is how much Discord is dragging their feet on these issues

  • @Ivkovifi
    @Ivkovifi Před 2 lety +4

    Excuse me, it is not Discord's fault, it is the fault of the person who runs the virus.exe smh

  • @NotJudgingJudge
    @NotJudgingJudge Před 2 lety

    i had a friend, i meet him over CS:GO, he seemed like a nice guy, we haven been playing lots comp games. He invited me to a server with his friends, we dm us very often , just incase if one of us was curios if somebody had time. AND THEN he send me a file wich said (i deleted the chat) but basicly it was a virus. somehow i didnt got a virus, maybe there was a secret anti virus i didnt knew was there, then one of the server members contacts me and said: "hey your friend hacked my steam account, can you try to get it back?" i messaged him through discord and steam, but this were just his alts, he never responded.
    get to know the person, ask some questions like where your born and whats the name, i know, its sends some creepy vibes, but do so much activites together and if he trusts you, you can trust him.

  • @kry-9983
    @kry-9983 Před 2 lety

    Yeah i got hacked as well a while back, the discord team did NOTHING to help me, I had to get my friend to rehack my acc to get it back

  • @121r4vce4t
    @121r4vce4t Před 2 lety +3

    It's not discord their fault. Authentication tokens are required for everything and discord's authentication tokens are very secure and cannot be brute-forced. Not their fault some 14-year-olds run every .exe file he sees.

    • @theinspector9392
      @theinspector9392 Před 2 lety +2

      Discords security is absolutely horrible and I know multiple computer science majors who agree with that.

    • @121r4vce4t
      @121r4vce4t Před 2 lety

      @@theinspector9392 show me some proof then

  • @1shyne
    @1shyne Před 2 lety +4

    This token-grabbing stuff has been going on for way too long on Discord. Hopefully, Lucid making this video will make Discord realize how huge this flaw is and how much it impacts Discords' users.

  • @Idk-gq3bx
    @Idk-gq3bx Před rokem

    My friend recently got hacked by an account from New York and we live no where near America and once it was hacked it spammed his dms with p*rn bot servers but thankfully his acc is back but discord really needs to fix this security problem

  • @AshieKneeCaps
    @AshieKneeCaps Před 2 lety +1

    Say cap all you want but when that discord sound went off I Gota discord notification lmaoooo

  • @barackhusseinobamaofficial

    He's acting like malware is preventable lmaoo, it isn't discords fault, it's theirs for downloading it.

  • @blackhoodieyt
    @blackhoodieyt Před 2 lety +5

    Anyone from India?? ❤

  • @r1skyVal
    @r1skyVal Před 2 lety

    discords token grabbers are always updating and everyone is a google search away from setting one up. just dont download anything unless ur friend confirms that it is save and you are sure that he is the one

  • @gabey1281
    @gabey1281 Před 2 lety +1

    my discord account actually got hacked almost 4 weeks ago, my email got changed and i've opened so many discord support tickets but still no progress no replies no help from the discord team this is so pathetic i actually gave them any information they needed but they seem like they don't care.

  • @sebf98s90fh2
    @sebf98s90fh2 Před 2 lety +3

    Discord has now gone so far they've even started rolling out a feature where it asks you to accept someone's first dm to you because some snowflakes click anything they see on the internet.

    • @sebf98s90fh2
      @sebf98s90fh2 Před 2 lety

      @NamedBinaryTag I know it's not discords fault I wasn't blaming them

    • @cushyuu
      @cushyuu Před 2 lety

      @UCxjIeYp-d3MRZCqa0tkdQ8Q watch the video poopooo

    • @sebf98s90fh2
      @sebf98s90fh2 Před 2 lety

      @@cushyuu who you talking to

    • @cushyuu
      @cushyuu Před 2 lety

      @NamedBinaryTag thats not my point, the guy i replied to said "random person", its not.

    • @cushyuu
      @cushyuu Před 2 lety

      @NamedBinaryTag oh youre right

  • @deathshot5484
    @deathshot5484 Před 2 lety +1

    My boy uploaded

  • @crystalthewolf8945
    @crystalthewolf8945 Před 2 lety

    Feel this yeah, discord acc randomly got hacked (didn't download anything or do ANYTHING AT ALL) and it was just gone. Got it back, but barely managed to, discord said it was impossible for me to get it back, as they thought I was hacking it, as their security is "next level" convinced them to give it back to me tho

  • @762reaperlol
    @762reaperlol Před 2 lety +1

    You’re never supposed to respond or open it because that’s another way they are able to get your info off that.

    • @demigod5598
      @demigod5598 Před 2 lety

      They can get info just by replying to the message ?

  • @FlipZ.
    @FlipZ. Před 2 lety

    my friend got hacked 3 times like this, and then he messages every every every facking friend the hacker messaged to say it was not him, respect to the people who get hacked :(

  • @nightbot6239
    @nightbot6239 Před 2 lety

    I’ve been hacked 6 times now, 3 accounts had nitro and it was consistent. I lost so many friends because I never got to remember their tags..

  • @1t2ht
    @1t2ht Před 2 lety

    I actually got hacked once on discord, but I didn't download anything. I just one time saw an email by discord saying 10$ was spent on my account, I immediately unlinked my card and luckily got my money refunded.

  • @PaintedDesire
    @PaintedDesire Před 2 lety

    Fun fact if you attempt this the bank will find out, If a federal agency asks for the information from your vpn company they will give them your IP, Vpns actually store your IP.

    • @llllIllIIl
      @llllIllIIl Před 2 lety

      ok so happens if i use a proxy chain or a VPN hosted in countries that have strict privacy laws