A member losing their Steam account or their wallet in your server isn't a moderation statistic β it's the message you get at midnight asking how you let it happen. Wardn follows links to where they actually land, reads the QR code inside an image, and removes the post before your fastest member clicks.
What the member sees
bit.ly/nitro-drop
Everything else on a moderation checklist is an annoyance with a cleanup cost. This is the category where being ten minutes late is the difference between a deleted message and a drained wallet.
By the time a mod wakes up, the people who were going to click have clicked. Deleting the message afterwards is bookkeeping, not protection.
Not the veterans. The person who joined last week, doesn't know your staff list, and believes a badge in a display name.
Fairly or not, 'I got scammed in your Discord' becomes a thread. Trust in the server drops faster than the member count does.
Different scripts, same shape: urgency, a free thing, and a page that wants a login.
"π Free Nitro for the first 50 people, claim before it expires!"
The tell: Look-alike domain, an account created hours ago, and the identical message already sitting in six other servers.

"A clean-looking image: 'Scan to claim your reward.'"
The tell: Wardn reads the code inside the picture. It resolves to a wallet-connect page, so the image never reaches the channel.
"A real member, in your server for a year, suddenly DMs everyone the same link."
The tell: Behaviour that doesn't match their own history: 40 identical DMs in two minutes from someone who posts twice a week.
"'Hi, I'm from the mod team β verify your account here to avoid a ban.'"
The tell: Nobody on your actual staff list, an impersonated display name and avatar, and a verification flow you don't run.
"'Middleman needed for a trade, paying in advance' in your marketplace channel."
The tell: The same script your mods have banned before, posted by an account with no trade history in your server.
"A .zip 'cheat pack' or 'game mod' dropped in a help channel."
The tell: Unknown file, brand-new poster, and a filename pattern that's shown up in three other servers this week.
A scam post is evidence. Wardn treats it that way instead of quietly deleting it and forgetting.
Members who opened the link get a DM telling them exactly what to change and where.
The same domain, shortener and image hash are pulled from every channel it reached, not just the one you saw.
The campaign shape is remembered, so the next variant β new domain, same script β is caught on sight.
One digest in your mod channel: what hit, who it reached, what was done, and the undo button if you disagree.
Scam waves usually arrive with a burst of fresh accounts β the join pattern is often the earliest warning you get.
No. Wardn works on your server's channels. What it can do is spot the account behaviour that precedes a DM wave and flag it before the DMs go out.
Undo restores the message and the member in one tap, and the correction trains it. Trusted domains your community uses daily get learned in the first week.
Blanket-blocking shorteners annoys everyone and stops nothing determined. We resolve them instead and judge the destination.
Sub-second on posting. The whole point of this category is that a delayed correct decision is still a loss.
Tell us what's been hitting you lately β links, QR images, fake staff, DM waves. We onboard five servers per batch and quote each one on its own volume and setup.
Lockdown that doesn't punish every real member who happened to join today.
The overnight wall of garbage, and how to stop rewriting filters for it.
What a moderation bot has to get right in 2026 β and where the classics stop.
Why wordlists lose to one swapped character, and what reads intent instead.
The training loop: every override your mods make becomes a rule you never write.
NSFW, gore and slurs handled the same way at 3am as at 3pm.