Education

The MrBeast Discord Scam: Why Your Friend's Account Is Sending You Casino Links

A friend DMs you a MrBeast giveaway. They did not send it. Here is how infostealer malware takes over Discord accounts without a password, what to do if yours sent the spam, and how to stop it spreading in your server.

The MrBeast Discord Scam: Why Your Friend's Account Is Sending You Casino Links

Someone you have known for three years sends you a message at 4am. It is an image of MrBeast holding a cheque, a line about a $2,500 giveaway, and a link. You know this person. They have never once talked about crypto.

They did not send it. Their account did.

The MrBeast Discord scam is the most visible symptom of a much bigger problem: a wave of account takeovers driven by information-stealing malware, running at a scale that doubled every month through the first half of 2026. This is what is actually happening, what to do if it happened to you, and how to keep it out of a server you run.

What the MrBeast Discord scam looks like

The message arrives as a direct message, or it lands in every channel of every server the compromised account is a member of. The wording rotates constantly, but it is always one of a handful of shapes:

  • "MrBeast is giving away $2,500, first 100 people"
  • "Claim your reward"
  • "You've been selected"
  • "bro check this, I actually got paid"

Increasingly the payload is not text at all, it is an image. A designed graphic with the celebrity's face, a fake payout screenshot, and a URL burned into the picture so that no link filter can read it. MrBeast is the most common face because he is the one every 13 year old on the platform recognises, but Elon Musk and Andrew Tate run a close second. None of them have anything to do with it.

Where the link goes varies, and every branch ends badly:

  • A fake crypto casino that takes a deposit and never pays out.
  • A wallet drainer that asks you to connect a crypto wallet and empties it.
  • A phishing page dressed as Discord or Steam that harvests your login.
  • A Discord OAuth authorization screen that looks official and hands an attacker's app permission over your account.
  • A download, usually pitched as a mod, cheat or free tool, that installs the same malware that started the whole chain.

A real Discord gift link is only ever discord.gift or discord.com/gifts. Anything else, including discordgift.com, disc0rd.gift or discord-nitro-free.com, is a phishing page.

Your friend was not careless with their password

This is the part most people get wrong, and it matters, because it changes what you have to do about it.

These accounts are not being brute forced. They are being taken over by infostealer malware, and infostealers do not want your password. They want your session token.

A session token is the credential Discord stores on your machine so you do not have to log in every time you open the app. It is proof that you already logged in. When malware copies that token off a computer, the attacker can paste it into their own client and be inside the account immediately. No password prompt. No two-factor prompt, because the token represents a session where 2FA was already satisfied.

That is why "but I have 2FA on" is not the reassurance people think it is. Two-factor authentication protects the login. Token theft skips the login.

How the malware gets on the machine

Almost always through something the user installed on purpose:

  • Game cheats and trainers. The single most reliable delivery route. A 2026 campaign tracked as Powercat did nothing but masquerade as cheat software for popular PC games, targeting Discord, Roblox, Minecraft and crypto wallets in one pass.
  • Cracked software and "free" versions of paid tools.
  • Mods and launchers from a link in a DM rather than the official page.
  • Malicious browser extensions, which can read session data directly.
  • Phishing pages that ask you to "verify" and quietly deliver a file.

The tooling is cheap and commoditised. VVS Stealer, a Python-based stealer documented by Palo Alto's Unit 42 in early 2026, sold on Telegram for around 10 euro a week. For that, it decrypts Discord tokens, queries Discord's API for account details, billing information and MFA status, grabs browser credentials, and takes screenshots. Buying account takeover capability now costs less than a sandwich.

Then the account becomes a spam node

Once the attacker is in, the account is not used to talk to you. It is automated. It fires the same scam image into every server the victim is in and every DM thread they have open, usually within minutes, usually while they are asleep. The account is a distribution asset, and the victim's real value to the attacker is their reach: their friend list and their server memberships.

How big this actually is

Published numbers from a Discord protection service running across roughly 375,000 servers show compromised accounts identified per month:

Month (2026)Hacked accounts identified
April40,000
May80,000
June160,000

A doubling every month. Over four million fraudulent images were deleted in June alone, and the number of unique scam images grew 95% since February, which tells you the attackers are generating fresh visual variants continuously rather than recycling old ones. That detail matters: any defence built on matching a fixed list of known images is losing ground every week.

Discord's own side of the picture: between March 2025 and March 2026 the platform actioned more than three million accounts under Deceptive Practices, the category covering phishing, malware distribution, credential theft and financial scams.

If your account sent the spam

Order matters here. Changing your password first, while the malware is still running, just hands the attacker your new one.

Get the malware off the machine first

Run a full scan with a reputable antivirus product. If the compromise traces back to a cheat, crack or sketchy mod, uninstall it. If you cannot be confident the machine is clean, do every step below from a different device you trust.

Log out everywhere

Discord Settings, then Devices. Review the active sessions, and use Log out of all known devices. This is the step that actually invalidates the stolen token. Skipping it means the attacker keeps their session no matter what you do to your password.

Change your Discord password

Long, unique, not reused anywhere else. Do this from the clean device.

Secure the email account behind Discord

Attackers frequently change the account email to lock the owner out. Change that password too, and put 2FA on the mailbox. If Discord emailed you about an email change, that message contains a Start account recovery button, and you have 48 hours from the change to use it.

Revoke authorized apps

Settings, then Authorizations. Remove anything you do not recognise. An OAuth app that a victim approved from a scam page keeps its access even after a password reset.

Turn on 2FA if it is not already on

It does not stop token theft, but it closes the ordinary login route and it is required before you can moderate most serious servers anyway.

Tell people

Post in the servers you are active in and message the friends who got the DM. Tell them not to click anything that came from you in the last day. Your account's credibility was the weapon, and warning people is the only thing that disarms it.

If you run a server

From a moderator's seat this attack has a signature that is very different from ordinary spam, and that signature is what you defend against.

The account posting it is not new. It is often a member of two years with roles and history, which means every defence keyed to account age or join date does nothing. What gives it away is the burst: the same content, in several channels, in a few seconds, from an account that has never behaved that way.

So the rule you want is not "block this link". It is "no member posts the same thing in four channels in ten seconds". Attackers can regenerate the image and rotate the domain endlessly. They cannot make the burst look like conversation.

In Fenrai, that is a moderation rule built from recent-activity conditions. A few shapes worth having, all of which you can build in Dashboard > Moderation > Rules:

Cross-channel burst. This one ships as a template called Catch cross-channel spam: 3 or more channels and 3 or more repeated messages within 10 seconds, then purge the recent messages and mute. Purging matters as much as the mute, because leaving the images up leaves the links live.

Image plus link from a quiet account. Trigger on message sent, conditions: has image, has link, and messages in window above your normal chat rate. Action: delete and log. Start this one on log only for a few days and read what it catches before you let it act.

Known lure phrases. A content pattern condition covering the recurring wording, things like "giving away", "claim your reward", "free nitro", "steam gift". It will not catch the image-only variants, which is exactly why it is the third rule and not the first.

Everything to a log channel. Set the moderation report channel in Dashboard > Moderation > General. When a trusted member gets hit, you want the case history to show a burst at 4am from an account that had a clean record, because that is what tells you to treat it as a compromise rather than banning a real member.

Handle the aftermath as a compromise, not a betrayal. The member was a victim. Mute, purge, and tell them to run the recovery steps above, including logging out of all devices, before you unmute. If you only ban, you lose a member and the attacker loses nothing.

The full setup, including what Discord's own AutoMod does and does not cover, is in how to stop scam links in your Discord server. Reference for triggers, conditions and actions is in the moderation docs.

Common questions

Is the MrBeast Discord giveaway real? No. MrBeast does not run giveaways through Discord DMs, and neither does anyone else worth trusting. Real giveaways never require you to connect a crypto wallet, scan a QR code or download software.

Can someone hack my Discord if I have 2FA? Yes, through token theft. 2FA protects the login step, and a stolen session token bypasses the login step entirely. This is why logging out of all devices is the critical recovery action.

I clicked the link but did not enter anything. Am I fine? Probably, but check two things: your authorized apps list, in case the page was an OAuth prompt you clicked through, and your downloads folder, in case something arrived automatically. Then run an antivirus scan.

Why is it always MrBeast? Name recognition among exactly the age group that uses Discord most. The same campaigns swap in Elon Musk and Andrew Tate depending on which audience they are aiming at.

Should I ban the member who spammed my server? Mute and purge first. The account is compromised, not malicious. Ban only if the account comes back after recovery and does it again.

The short version

The MrBeast giveaway is bait. The real attack happened days earlier, when someone installed a cheat or a cracked tool and lost their Discord session token to malware. The spam is just the attacker converting that access into reach.

For you: log out of all devices, in that order, before anything else. For your server: detect the burst, not the link, because the link changes every hour and the burst never does.

Sources: Bitdefender, Unit 42 on VVS Stealer, ThreatLocker on the Powercat campaign, Discord support: hacked or compromised accounts.