Executive brief
Discord's Invisible status feature is intended to show users as offline to others, but a flaw in the WebSocket API allows third parties to distinguish between genuinely offline users and those who are secretly online in Invisible mode. An attacker can query the presence API and determine which contacts are actually active but hiding, undermining user privacy expectations around the Invisible status.
Technical details
The vulnerability is an information disclosure flaw in Discord's WebSocket API presence handling. The root cause is inconsistent treatment of offline vs. Invisible users: Invisible users are included in the presences array with "status": "offline", while truly offline users are omitted entirely. An attacker with network access to the WebSocket API can distinguish between these two states by observing the presence array contents, allowing them to infer which users are actively online but masking their status. The attack requires only the ability to query the API; no authentication bypass or privilege escalation is needed. A fix was reportedly implemented later in 2026.
Affected products
- Discord Discord through 2026-01-16
Timeline
- 2026-01-22: disclosed
- 2026: patched: Third-party report suggests remediation later in 2026