Raids are automated now: 50 accounts join in a minute, spam every channel, DM your members. "Raid bot" searches keep climbing, which means the tooling to attack is as easy as the tooling to defend. This is the defence playbook, in order of effort.

Layer 1: Discord's own settings (5 minutes)

  • Moderation level Medium (verified email required to speak).
  • AutoMod: block mention spam (5+ mentions), common spam keywords, invite links.
  • 2FA required for moderator actions.
  • Turn off DMs between members by default (Server Settings → Privacy).

Layer 2: A verification gate

Raid accounts are fresh and lazy — a button verification step stops most of them before they can type. Verification bots compared here; alt-detection (Double Counter) if the attackers persist.

Layer 3: Anti-nuke

The dangerous raid is the inside one — a compromised mod account mass-banning and deleting channels. An anti-nuke bot watches action rates and strips permissions automatically. Noxyr's anti-nuke ships free with trusted users/roles and stays off until you enable it: turn it on from the dashboard.

Layer 4: The lockdown drill

Decide before the raid: who runs lockdown, which bot command pauses invites, which channel becomes the announcement point. Practise once. During a raid: pause invites, slowmode 30s on public channels, ban wave by join-time, then review the audit log.

Recovery

  • Audit log → filter by the attacker accounts → reverse what you can.
  • Rotate any leaked webhooks (delete and recreate).
  • Post a short honest note in #announcements; silence breeds panic.

Full security stack comparison: best Discord security bots.