Discord says links to files uploaded to its servers will expire after 24 hours to reduce the amount of malware distributed using its CDN, starting later in 2023
Sergiu Gatlan / BleepingComputer :
Context & Ripple Effects
Discord's move follows reporting that collaboration platforms' own hosting and APIs were being used to evade detection, including malware spread through Slack and Discord infrastructure. Researchers had also identified Discord's CDN as a growing malware-distribution channel, particularly for data-stealing threats.
The change matters because Discord is narrowing the lifetime of a commonly shared hosting URL rather than merely moderating individual files. It targets the persistence that makes a platform CDN useful to both ordinary sharing and malicious campaigns.
First-order effects
- Files uploaded to Discord will no longer remain reachable through the same link beyond 24 hours, reducing the utility of long-lived Discord-hosted URLs for malware delivery.
- Discord users and developers that rely on durable direct file links will need to re-upload files or use another hosting path when links expire.
Second-order effects
- Threat actors distributing payloads through Discord will have to refresh links more often or shift to other hosting services, increasing operational friction but not eliminating malware delivery.
- Security teams can treat older Discord file URLs as less likely to remain live, while collaboration platforms face greater pressure to limit abuse of their own CDNs and APIs.
Third-order effects
- If widely adopted, expiring links could make short-lived, access-controlled file delivery a standard abuse-prevention trade-off for communication platforms, reducing the value of their infrastructure as durable public hosting.
- The likely structural tension is between safer default file delivery and interoperability: platforms that impose tighter link lifetimes may push users with archival or automated-sharing needs toward specialized storage services.
The trend: Communication platforms are increasingly redesigning infrastructure defaults to reduce the persistence and abuse potential of their built-in distribution channels.