- Anti-nuke
- Explainers
How Discord servers get nuked, and how to stop it
By The Bastion team. , 4 min read.
In short
A nuke needs one account with power and about ten seconds. You can't make every admin account unhackable, so the fix is a limit: nobody gets to delete more than a few things before their powers are taken away.
What a nuke looks like
A nuke is when someone with power wrecks a server on purpose. Channels are deleted, roles are deleted, and members are banned in bulk. It's usually done by a script, so the whole thing is over in seconds. By the time anyone reads the first alert, there's nothing left to protect.
The three ways it happens
- A hacked admin account. This is the common one. A staff member scans a QR code, opens a fake gift link or runs a file someone sent them, and the attacker is now signed in as them. Everything that person could do, the attacker can do.
- A staff member who turns. Someone falls out with the team, or was never who they said they were. They already have the permissions, so nothing looks unusual until they start.
- A bot with too much power. Someone adds a bot that asks for Administrator. Either the bot was built to do damage, or its owner's account gets taken over later.
There's a quieter fourth route worth knowing. An attacker with Manage Roles gives @everyone a dangerous permission, or gives it to a low role nobody watches. Then they come back later on a different account and use it.
Why permissions alone don't stop it
Discord's permissions are all or nothing. A person with Manage Channels can delete one channel or every channel. Discord doesn't tell the two apart, because it has no idea which one you meant to allow.
You need your admins to have real power, or they can't do their job. So the question isn't who has permission. It's how much anyone gets to do before something steps in.
Limits, counted per person
That's what an anti-nuke bot does. It reads Discord's audit log, which records who did what, and it counts damaging actions for each person.
In Bastion, on the Balanced level, the numbers look like this. Each action has one limit for a minute, which catches a fast attack, and one for an hour, which catches someone spacing it out.
| Action | A minute | An hour |
|---|---|---|
| Deleting channels | 3 | 8 |
| Deleting roles | 3 | 8 |
| Banning members | 5 | 16 |
| Kicking members | 5 | 16 |
| Creating webhooks | 3 | 10 |
Deleting one channel is normal housekeeping. Deleting three in a minute isn't, so Bastion acts on the third. The full list of limits is on the Anti-Nuke page.
Mixed attacks
A careful attacker stays under every single limit: two channels, two roles, a few bans. So each action is also worth points. Deleting a channel is 25, deleting a role is 25 and banning a member is 20. If one person reaches 100 points within ten minutes, that counts as an attack too. Two channel deletes and two role deletes make exactly 100. See the attack score.
What happens to the attacker
By default, Bastion puts them in quarantine. Every role they have is taken away and saved, and they get one role that can see nothing. They're still in the server, but they can't touch it.
Quarantine is the default for a reason. A real admin tidying up old channels will sometimes go over a limit. If that happens, /quarantine remove gives their roles back and nothing is lost. A ban is much harder to take back.
A bot can't be quarantined, so a bot that goes over a limit is kicked.
Closing the quiet routes
- Dangerous permission changes are undone. If someone edits a role to add Administrator, Manage Roles, Ban Members or a similar power, Bastion puts the role back and punishes whoever did it. The same goes for handing those powers out through one channel's settings.
- Bots need the owner's say. The Join Gate removes any bot added by someone who isn't the owner or a trusted person.
- Mass prunes are caught. A prune that removes 5 or more members is treated as an attack.
The parts only you can do
No bot can cover these for you.
- Put the security bot's role at the top. Discord never lets a bot act on someone with a higher role. If an admin role sits above Bastion, Bastion can only warn you about what that admin is doing.
- Keep the trusted list tiny. Trusted people skip every limit. That's useful for the owner, and a risk for everyone else, because a hacked trusted account isn't stopped.
- Give out Administrator sparingly. Most moderators need to time people out and delete messages. Very few need to delete channels.
- Teach your staff the QR rule. Nobody legitimate will ever ask them to scan a QR code or sign in through a link in a DM.
If the worst still happens
Stopping an attack on the third delete still leaves you two channels short. On the free plan you recreate them by hand, and lockdown is there if you need to freeze the server while you look.
With Pro, a backup holds a saved copy of your roles, channels and permissions, and restore brings back whatever's missing. Messages and members aren't part of a backup. Panic mode does the lock and the restore for you the moment an attack is caught.
TipRun /status after setup. It checks the role position and the permissions that anti-nuke depends on, and it tells you what to fix.
Protect your server today
Free to add. Three minutes to set up.