Hackers have stolen over 2 million identity photos from Discord users and are now demanding ransom from the popular messaging platform.Hackers have stolen over 2 million identity photos from Discord users and are now demanding ransom from the popular messaging platform.

Discord Reportedly Faces Extortion After 2.1 Million of User ID Photos Stolen

Discord Reportedly Faces Extortion After 2.1 Million of User ID Photos Stolen

The breach happened on September 20, 2025, when attackers broke into Discord’s customer support system and grabbed sensitive personal documents including driver’s licenses and passports.

The attack targeted Discord’s Zendesk support system, exposing 2,185,151 photos belonging to 2.1 million users who submitted ID documents for age verification. Discord waited nearly two weeks before publicly announcing the breach on October 3, 2025.

What Information Was Stolen

The hackers accessed more than just photos. They also grabbed names, email addresses, Discord usernames, and messages users sent to customer support. Some users had their IP addresses exposed along with limited payment information—specifically the last four digits of credit card numbers and purchase history.

Discord confirmed that full credit card numbers, passwords, and regular chat messages between users were not accessed. The breach only affected people who contacted Discord’s Customer Support or Trust & Safety teams.

According to security researchers, the attackers claim they have 1.5 terabytes worth of data. That’s an enormous amount of personal information now in the hands of criminals.

How the Hack Happened

The breach didn’t target Discord’s main systems directly. Instead, hackers used social engineering tactics—manipulating people rather than exploiting software bugs—to compromise the third-party support provider.

A group calling themselves Scattered Lapsus$ Hunters has taken credit for the attack. This coalition combines tactics from well-known hacking groups like Scattered Spider, Lapsu$, and ShinyHunters. They posted screenshots on Telegram showing they had access to Discord’s internal tools and administrative panels, mocking the company’s security measures.

How the Hack Happened

Source: @vxunderground

However, there’s confusion about who actually pulled off the hack. The group later suggested a different team they know was responsible for the breach.

Age Verification Laws Create New Risks

This breach highlights major concerns about new age verification requirements. The UK passed the Online Safety Act in July 2025, forcing platforms like Discord to verify users’ ages by checking government IDs. Several US states followed with similar laws—Ohio and Arizona enacted their versions in late September 2025.

Discord promised users that ID photos would be “deleted directly after your age group is confirmed.” But the stolen data came from users who appealed age verification decisions, meaning Discord’s support system kept copies of these documents.

Privacy advocates warned this would happen. When companies collect and store large amounts of sensitive identity documents, they create attractive targets for hackers. This Discord breach proves those fears were justified.

Impact on the Crypto Community

The breach poses serious risks for cryptocurrency users on Discord. Many crypto projects, NFT communities, and blockchain networks use Discord as their main communication hub. Developers, traders, and investors regularly discuss sensitive topics in these spaces.

Hudson Rock’s Chief Technology Officer Alon Gal explained the danger: “If it leaks, this db is going to be huge for solving crypto related hacks and scams because scammers don’t often remember using a burner email and VPN and almost all of them are on Discord.”

The stolen data could help criminals identify crypto influencers, traders with significant holdings, and project developers. Hackers could use this information for targeted phishing attacks, identity theft, or extortion schemes. Someone’s real name, location details from ID photos, and Discord activity creates a detailed profile criminals can exploit.

The timing is particularly bad since Discord has over 200 million monthly users, with a significant portion involved in crypto and blockchain communities.

Better Solutions Exist

Technology companies don’t need to collect and store millions of ID photos to verify age. Zero-knowledge proofs offer a privacy-friendly alternative that mathematically confirms someone’s age without revealing their full identity or storing sensitive documents.

Concordium, a blockchain platform, launched a mobile app in August that uses this technology. Users can prove they’re over 18 without sharing their actual ID with any company. Google Wallet also integrated zero-knowledge proofs for age verification in April 2025.

These systems prevent the accumulation of document photos on servers that can be hacked. If Discord had used zero-knowledge proofs instead of collecting ID images, this breach would have exposed far less sensitive information.

Discord’s Response and User Actions

Discord immediately cut off the compromised support provider’s access and brought in computer forensics experts. The company notified law enforcement and data protection authorities about the breach.

Affected users are receiving emails from noreply@discord.com—Discord’s only official channel for breach notifications. The company warned it will never call users about this incident. Users should watch for phishing emails pretending to be from Discord, as scammers often exploit data breaches to steal more information.

This marks Discord’s third security incident in 2025. The platform previously dealt with Epsilon Red ransomware distribution in July and a malware attack through its Content Delivery Network in August.

The Bottom Line

This breach demonstrates exactly what privacy advocates feared about mandatory ID collection. When companies store millions of sensitive documents in centralized databases, they create irresistible targets for hackers. The 2.1 million Discord users who trusted the platform with their government IDs now face potential identity theft risks.

For crypto users, the situation is particularly concerning given Discord’s central role in blockchain communities. Better privacy technology exists and companies should adopt it before more personal information falls into criminal hands.

Market Opportunity
SPACE ID Logo
SPACE ID Price(ID)
$0.06804
$0.06804$0.06804
+3.35%
USD
SPACE ID (ID) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Fed Acts on Economic Signals with Rate Cut

Fed Acts on Economic Signals with Rate Cut

In a significant pivot, the Federal Reserve reduced its benchmark interest rate following a prolonged ten-month hiatus. This decision, reflecting a strategic response to the current economic climate, has captured attention across financial sectors, with both market participants and policymakers keenly evaluating its potential impact.Continue Reading:Fed Acts on Economic Signals with Rate Cut
Share
Coinstats2025/09/18 02:28
Iran’s Central Bank Spends $500M on Crypto Amid Rial Crisis

Iran’s Central Bank Spends $500M on Crypto Amid Rial Crisis

Iran's Central Bank has reportedly acquired more than $500 million in cryptocurrency assets over the past year to mitigate the ongoing currency crisis.
Share
coinlineup2026/01/22 08:59
Unlocking Massive Value: Curve Finance Revenue Sharing Proposal for CRV Holders

Unlocking Massive Value: Curve Finance Revenue Sharing Proposal for CRV Holders

BitcoinWorld Unlocking Massive Value: Curve Finance Revenue Sharing Proposal for CRV Holders The dynamic world of decentralized finance (DeFi) is constantly evolving, bringing forth new opportunities and innovations. A significant development is currently unfolding at Curve Finance, a leading decentralized exchange (DEX). Its founder, Michael Egorov, has put forth an exciting proposal designed to offer a more direct path for token holders to earn revenue. This initiative, centered around a new Curve Finance revenue sharing model, aims to bolster the value for those actively participating in the protocol’s governance. What is the “Yield Basis” Proposal and How Does it Work? At the core of this forward-thinking initiative is a new protocol dubbed Yield Basis. Michael Egorov introduced this concept on the CurveDAO governance forum, outlining a mechanism to distribute sustainable profits directly to CRV holders. Specifically, it targets those who stake their CRV tokens to gain veCRV, which are essential for governance participation within the Curve ecosystem. Let’s break down the initial steps of this innovative proposal: crvUSD Issuance: Before the Yield Basis protocol goes live, $60 million in crvUSD will be issued. Strategic Fund Allocation: The funds generated from the sale of these crvUSD tokens will be strategically deployed into three distinct Bitcoin-based liquidity pools: WBTC, cbBTC, and tBTC. Pool Capping: To ensure balanced risk and diversified exposure, each of these pools will be capped at $10 million. This carefully designed structure aims to establish a robust and consistent income stream, forming the bedrock of a sustainable Curve Finance revenue sharing mechanism. Why is This Curve Finance Revenue Sharing Significant for CRV Holders? This proposal marks a pivotal moment for CRV holders, particularly those dedicated to the long-term health and governance of Curve Finance. Historically, generating revenue for token holders in the DeFi space can often be complex. The Yield Basis proposal simplifies this by offering a more direct and transparent pathway to earnings. By staking CRV for veCRV, holders are not merely engaging in governance; they are now directly positioned to benefit from the protocol’s overall success. The significance of this development is multifaceted: Direct Profit Distribution: veCRV holders are set to receive a substantial share of the profits generated by the Yield Basis protocol. Incentivized Governance: This direct financial incentive encourages more users to stake their CRV, which in turn strengthens the protocol’s decentralized governance structure. Enhanced Value Proposition: The promise of sustainable revenue sharing could significantly boost the inherent value of holding and staking CRV tokens. Ultimately, this move underscores Curve Finance’s dedication to rewarding its committed community and ensuring the long-term vitality of its ecosystem through effective Curve Finance revenue sharing. Understanding the Mechanics: Profit Distribution and Ecosystem Support The distribution model for Yield Basis has been thoughtfully crafted to strike a balance between rewarding veCRV holders and supporting the wider Curve ecosystem. Under the terms of the proposal, a substantial portion of the value generated by Yield Basis will flow back to those who contribute to the protocol’s governance. Returns for veCRV Holders: A significant share, specifically between 35% and 65% of the value generated by Yield Basis, will be distributed to veCRV holders. This flexible range allows for dynamic adjustments based on market conditions and the protocol’s performance. Ecosystem Reserve: Crucially, 25% of the Yield Basis tokens will be reserved exclusively for the Curve ecosystem. This allocation can be utilized for various strategic purposes, such as funding ongoing development, issuing grants, or further incentivizing liquidity providers. This ensures the continuous growth and innovation of the platform. The proposal is currently undergoing a democratic vote on the CurveDAO governance forum, giving the community a direct voice in shaping the future of Curve Finance revenue sharing. The voting period is scheduled to conclude on September 24th. What’s Next for Curve Finance and CRV Holders? The proposed Yield Basis protocol represents a pioneering approach to sustainable revenue generation and community incentivization within the DeFi landscape. If approved by the community, this Curve Finance revenue sharing model has the potential to establish a new benchmark for how decentralized exchanges reward their most dedicated participants. It aims to foster a more robust and engaged community by directly linking governance participation with tangible financial benefits. This strategic move by Michael Egorov and the Curve Finance team highlights a strong commitment to innovation and strengthening the decentralized nature of the protocol. For CRV holders, a thorough understanding of this proposal is crucial for making informed decisions regarding their staking strategies and overall engagement with one of DeFi’s foundational platforms. FAQs about Curve Finance Revenue Sharing Q1: What is the main goal of the Yield Basis proposal? A1: The primary goal is to establish a more direct and sustainable way for CRV token holders who stake their tokens (receiving veCRV) to earn revenue from the Curve Finance protocol. Q2: How will funds be generated for the Yield Basis protocol? A2: Initially, $60 million in crvUSD will be issued and sold. The funds from this sale will then be allocated to three Bitcoin-based pools (WBTC, cbBTC, and tBTC), with each pool capped at $10 million, to generate profits. Q3: Who benefits from the Yield Basis revenue sharing? A3: The proposal states that between 35% and 65% of the value generated by Yield Basis will be returned to veCRV holders, who are CRV stakers participating in governance. Q4: What is the purpose of the 25% reserve for the Curve ecosystem? A4: This 25% reserve of Yield Basis tokens is intended to support the broader Curve ecosystem, potentially funding development, grants, or other initiatives that contribute to the platform’s growth and sustainability. Q5: When is the vote on the Yield Basis proposal? A5: A vote on the proposal is currently underway on the CurveDAO governance forum and is scheduled to run until September 24th. If you found this article insightful and valuable, please consider sharing it with your friends, colleagues, and followers on social media! Your support helps us continue to deliver important DeFi insights and analysis to a wider audience. To learn more about the latest DeFi market trends, explore our article on key developments shaping decentralized finance institutional adoption. This post Unlocking Massive Value: Curve Finance Revenue Sharing Proposal for CRV Holders first appeared on BitcoinWorld.
Share
Coinstats2025/09/18 00:35