Customer Properly Secure a Purchased Discord Account

  • Balram
  • Author
  • New user
  • 1
1. Login via Token ONLY

  • Action: Do not use the email and password to log in for the first time. This can send security alerts to the OO's email or connected devices. A token login is a stealthy way to gain initial access without tripping alarms.
  • Tool: Use a browser extension specifically for this purpose. A common one is Discord Token Login.

2. Change the Associated Email Immediately (if you have fa)

  • Action: This is your first priority once you are logged in. The email is the primary recovery method for the account.
  • Steps: Go to User Settings > My Account > Email > Edit. Change it to a new, secure email that only you control. You will need to verify the change in the inbox of your new email.

3. Change the Password

  • Action: As soon as the email is changed, change the password.
  • Why it's critical: Changing the password instantly invalidates the old user token you used to log in and, more importantly, logs out all other active sessions. This kicks the OO out from any device they were logged into (PC, phone, etc.).

4. Enable Two-Factor Authentication (2FA)

  • Action: Now that the credentials are yours, enable 2FA immediately. Go to User Settings > My Account > Enable Two-Factor Auth.
  • Method: Use an authenticator app like Google Authenticator or Authy. Do not rely on SMS 2FA if the OO's phone number is still linked.

5. Purge the Account's Social Connections

  • Action: Erase the OO's digital footprint from the account to prevent their friends from contacting you or reporting the account.
    • Change Username & Discriminator: Change the username and avatar to something new.
    • Remove All Friends: Go through the friends list and remove every single person. It's best to block them as well to prevent them from finding the account again.
    • Leave All Servers: Leave every server the account is a member of.

6. Advanced Lockout: Neutralize the Original Email

  • Action: This is a crucial step to permanently sever the OO's last recovery path.
  • Steps:
    1. Go to the main Discord website and click "Register."
    2. Create a brand new, completely separate Discord account using the original owner's email address (the one that was on the account when you bought it).
    3. Verify this new, throwaway account via the email link.
  • Result: Now, if the OO tries to "Forgot Password" using their original email, the reset link will go to this new, useless account that you control, NOT the valuable account you just secured. The original account is now completely detached from that email address.


7. Final Security Sweep

  • Action: Perform a final check to close any remaining backdoors.
  • Steps:
    • Go to User Settings > Authorized Apps. Revoke access for every single app and bot listed there.
    • Go to User Settings > Devices. Confirm that only your current device is listed. Changing the password should have already cleared this, but it's good to double-check.
After completing all these steps, the account is fully under your control and secured against recovery attempts from the original owner.
 
You must log in or register to reply here.
Top