mass.report research

investigation

Unmasking Spycord

How the Spycord operator moved from qvfear to fearshoots, fearrrx and swrlzxx—and why the evidence points to a persistent doxxing and privacy-abuse threat actor.

By mass.report Research10 min read

This investigation assesses the Spycord operator as a persistent online-abuse actor, documents the qvfear-to-fearshoots infrastructure bridge, and traces later account continuity across GitHub, Discord and public profile hubs. It distinguishes mass.report’s corroborated findings from allegations and direct observations reported by No Text To Speech.

What triggered the investigation

The public investigation began with No Text To Speech’s August 2026 reporting on Spycord and its operator, QV Fear. mass.report then followed the operator’s own public links, repositories, stable platform identifiers and historical code to determine how the earlier qvfear identity connects to the later fearshoots, fearrrx, 3c18x and swrlzxx personas.

The reporting party separately alleged child-sexual-abuse-material-related conduct and reported that the person controlling the newest Discord account made an admission after being confronted. The complete original exchange has not been independently authenticated for this article. This report therefore separates account attribution, NTTS’s observed reporting and the reporter’s allegation instead of treating any one layer as proof of every other claim.

How No Text To Speech exposed Spycord

This investigation was prompted by No Text To Speech (NTTS), whose 8 August 2026 video, “I Investigated Discord’s Creepiest Moderators...,” identified the Spycord operator as QV Fear. NTTS said the inquiry began after a viewer received a Discord message showing that Spycord held 26 images of her. NTTS described the site as a Discord user-ID lookup and profile-aggregation service with a public directory and a separate NSFW category.

In the video, NTTS reported observing 62 directory profiles, a pronounced focus on women and girls, one profile containing 50 images of a woman, a full dox of a person identified as 14, and NSFW video links on a profile identified as 15. mass.report has not reproduced or independently authenticated the suspected illegal material. These details are attributed to NTTS’s direct account of what the channel observed on the then-live service.

NTTS further reported that when the viewer asked QV Fear to remove her photographs, the operator demanded payment—described as money, gift cards, Robux or “anything you can”—and threatened to sell the information to third-party services if she did not pay. We describe this as an alleged coercive pay-for-removal demand, not as a proven legal conclusion. The original messages and provider records should be preserved by Discord and the relevant hosting provider.

Evidentiary and safeguarding boundaries

The review used public pages, public APIs, immutable platform identifiers, historical Git commits and screenshots supplied by the reporting party. Confirmed links are direct self-links from account-controlled pages. High-confidence probable links combine multiple distinctive signals while preserving plausible alternative explanations. Identity leads such as Jordan and Nepal are not treated as established civil-identity facts.

Threat actor assessment

mass.report assesses the subject as a persistent online-abuse actor and the operator of a Discord-focused doxxing and image-aggregation service. The available evidence is more consistent with targeted privacy abuse, humiliation, coercive control and monetized removal demands than with conventional cybercrime carried out for technical access alone. The actor’s threat comes from combining public-data collection, social-platform access, web publishing and victim pressure in one repeatable workflow.

Assessed threat profile
DimensionAssessmentConfidence
Actor typeOnline-abuse, doxxing and privacy-abuse service operatorHigh
Likely objectivesCollection and exposure of victims; humiliation and control; reputation or clout; alleged pay-for-removal monetizationModerate
VictimologyWomen and girls were reportedly overrepresented; NTTS reported profiles of people identified as 14 and 15High for NTTS reporting; not independently authenticated
CapabilitiesDiscord-ID lookup, profile and image aggregation, doxxing publication, web deployment, Discord webhook use and historical visitor-IP collectionHigh
Access modelPrimarily social-platform and public-data collection; source of private media is not establishedModerate
Technical sophisticationLow to moderate: capable of deploying useful abuse tooling, but no evidence of advanced intrusion capabilityModerate
PersistenceHigh: repeated aliases, replacement Discord accounts, multiple hubs and an August 2026 “Spycord back” linkHigh
Operational securityPoor: repeated self-linking, immutable IDs, reused aliases and a live bridge back to qvfear projectsHigh

The demonstrated technical capability is practical rather than advanced. The cluster shows it can build and deploy web applications, organize searchable Discord-derived records, use Discord webhooks and collect visitor IP addresses in historical code. There is no public evidence here of vulnerability exploitation, privileged access, malware deployment by the subject or sophisticated intrusion tradecraft. “Threat actor” in this report describes the operator’s sustained harmful conduct and infrastructure, not an unsupported claim that the actor is an advanced hacker.

The likely harm model is cumulative: locate a target through Discord, aggregate identifying information and images, publish a durable profile, expose or threaten exposure of sensitive material, and make removal dependent on the operator’s discretion. Where a target is a minor, the safeguarding risk becomes acute even without proving how the media was obtained. NTTS’s report of money, gift-card and Robux demands indicates a possible monetization layer attached to that pressure.

NTTS also described a person named Terror as an associate and alleged that Terror advertised a remote-access trojan on Telegram. That is an ecosystem lead, not evidence that QV Fear developed, distributed or used the malware. The later portion of the NTTS video examines a wider network of leaking servers and additional operators; those actors and acts are not attributed to QV Fear unless a direct link is documented.

From qvfear to fearshoots

The historical alias is not supported only by NTTS’s naming. On 10 August 2026, the live fearshoots.ace.me profile displayed the name fearshoots and linked “Spycord back,” a Spycord Discord invite and a now-offline page labelled “qvfear web & github projects.” The same profile advertised Discord law.rf, Telegram aeoulos and X account spycordfr. Because these identifiers appear together on one account-controlled hub, they are documented self-claims at the time of capture rather than mere username matches.

Current qvfear / fearshoots infrastructure bridge
IdentifierRole or labelAssessment
fearshoots.ace.meCurrent profile hubDirect source
fear.subeditor.works“qvfear web & github projects”; now offlineDirectly linked historical hub
disface.vercel.app“Spycord back”Directly linked service
law.rf / discord.gg/GptR9ha4BG / discord.gg/spycordDiscord handle and invitesSelf-published; provider verification required
aeoulosTelegram handleSelf-published
spycordfrX accountDirectly linked

The archived qvfear project portfolio

A screenshot supplied to mass.report preserves the now-offline fear.subeditor.works portfolio. The page identifies itself as qvfear, describes the collection as experimental web and GitHub projects, and displays “Discord: qvfear.” Most importantly for attribution, the card titled “System Maintenance template | qvfear” tells users to contact qvfear at Discord user ID 1033929243215806594—the same immutable Discord ID independently recovered from the fearrrx/3c18x account trail.

Archived screenshot of the qvfear project portfolio showing Discord qvfear and a grid of web projects authored by qvfear.
Archived capture of fear.subeditor.works. The portfolio repeatedly labels projects as authored by qvfear and publishes Discord user ID 1033929243215806594.Screenshot supplied to mass.report
Security-relevant projects claimed by the qvfear portfolio
ProjectPortfolio descriptionWhat it supports
AgentRG | Deep ResearchAutonomous web-research and information-finding agent using GeminiClaimed interest in automated OSINT and research
Subreddit ScraperBrowse subreddits, download media and view discussionsClaimed scraping and bulk-media collection capability
Vanta KeyValidator for Gemini, OpenAI, Anthropic, OpenRouter and DeepSeek API keysClaimed API-key validation tooling
Invis InkSteganography studio for hiding messages inside plain text or imagesClaimed steganography capability
PhoneSintPhone-number lookup with carrier, location and risk analysisClaimed phone-intelligence and OSINT capability
waifu.pics Discord botDiscord bot using the waifu.pics APIClaimed Discord-bot development capability

The portfolio supports the assessment that the operator had broad, practical web-development, scraping, OSINT and Discord-automation interests. It does not by itself prove that every listed project was functional, independently authored, deployed against victims or used by Spycord. The strongest evidentiary value is attribution: the archived page binds the qvfear name to the same immutable Discord ID already present in the later account cluster.

This bridge materially improves the alias chain: QV Fear/qvfear is an earlier operator identity; fearshoots is a current self-presentation that points back to qvfear projects and active Spycord-branded infrastructure; fearrrx, 3c18x and swrlzxx are the later personas assessed elsewhere in this report. Provider records are still needed to prove continuous control across every account and date.

Current infrastructure and stated reactivation intent

The current infrastructure is not merely historical. At capture time, @spycordfr linked fearshoots.ace.me and a current Discord invitation. Telegram @aeoulos displayed the law persona and linked discord.gg/spycord; that invitation resolved to a server named Spycord.

On 10 August 2026, @spycordfr publicly wrote that a mistake in the code and database had removed “80% of the logged users,” said some records remained, and stated: “Give me a month or 2, I’ll be back with the tool but fully fixed.” The account added that it would not republish the site “for now.” Because the X profile directly self-links the fearshoots hub, this is strong evidence of continued service control and stated reactivation intent, not merely a similarly named third-party comment.

GitHub breadcrumbs

GitHub account 3c18x, immutable user ID 225708812, published a README commit that directed readers to Instagram swrlzxx. The full commit hash is 4fecc3c856db77a8da25e4b6f228dd7835e52311. The account also used the fearrrx persona and published historical Discord identifier 1033929243215806594.

GitHub account 33am, immutable user ID 168169181, is assessed as a high-confidence probable alternate account. The 3c18x account followed exactly one GitHub account—33am—and both histories used the rare UTC+05:45 commit offset associated with Nepal Time, alongside overlapping 3x18 and fear-style aliases. These signals support common control but are not individually conclusive.

GitHub attribution anchors
AccountImmutable IDEvidenceAssessment
3c18x225708812README commit self-linked Instagram swrlzxx; fearrrx and Discord bridgeConfirmed cluster link
33am168169181Only account followed by 3c18x; shared UTC+05:45 and alias patternHigh-confidence probable
swrlzxxNot recoveredDeleted account linked by HackerOne and guns.lolConfirmed historical link

The current GitHub profile for 33am uses the stylized display name Aeoulos. The live fearshoots hub independently advertises Telegram aeoulos, and that Telegram profile links discord.gg/spycord. This rare cross-platform alias match materially strengthens—without by itself conclusively proving—the assessed common control of 33am and the current Spycord cluster.

Discord account continuity

Three Discord snowflakes span the cluster's observed history. ID 1033929243215806594 was published by the fearrrx/3c18x persona. ID 1166330633363140768 was directly linked by the hotcheetolicker YouTube channel and the guns.lol hub. The reporting party observed ID 1533211982327713920 in the relevant server using display name swrlzxx and username ich_beobachte_dich_in_der_u8.

Discord account continuity
User IDSnowflake creationPublic or observed bridge
103392924321580659424 Oct 2022 02:25:41 UTCPublished by fearrrx/3c18x persona
116633063336314076824 Oct 2023 11:01:32 UTCSelf-linked by guns.lol and YouTube hotcheetolicker
15332119823277139201 Aug 2026 20:37:02 UTCReporter-observed current swrlzxx account

The latest-account bridge depends on the original server observation rather than an independent public self-link. A provider preservation request should include the server, channel and message IDs surrounding the reported admission, not merely screenshots or display names.

The self-linking guns.lol hub

The strongest central artifact is guns.lol/swrlzxx. Its internal document ID was 6794c4a10fa705ce4bbc166d, public UID 415600 and observed account creation time 25 January 2025 11:01:53 UTC. The profile described swrlz as he/him and a web developer, graphic designer, music producer, content creator, software developer and pixel artist.

From one account-controlled page, the operator linked Instagram swrlzxx, Discord ID 1166330633363140768, SoundCloud swrlzxx, Roblox 7906337812, deleted GitHub swrlzxx, Reddit u/swrlzxx, YouTube channels Swrlzxx, no1cez and yosyrexchill, plus three cryptocurrency addresses. This makes the hub connective evidence rather than mere username coincidence.

Cryptocurrency addresses published by the hub
AssetAddressObserved public-chain activity
BTCbc1q3mpvylv7vvzrfupu52ecgpwfmr374yupsanurtNo transactions or balance at review
LTCLMKZ7Tp5FaViiKdQcBqHAXdgEF5q1VTm1NReceived and later spent 0.00086006 LTC; zero balance
ETH0xc858affb3a3fcc25c1fe9827a5491adc42a5bcadNo transactions or balance at review

A fourth entry displayed with a Monero-style M icon repeated the Ethereum address. The 42-character EVM address is not a valid Monero address, so the entry was mislabeled or a placeholder rather than evidence of a separate wallet.

The watermarked Tenor upload

Tenor uploader ryaneats published post 12394650772939061537, media key rAKlNVQNuSE, titled Swrlzxx Discord GIF and tagged swrlzxx, discord, anime, chainsaw man and angel. The 498×280, 7.8-second animation visibly carries the watermark @swrlzxx. Tenor displayed its creation as 25 July 2025 17:32:03 without exposing a timezone.

The “Jordan” testimonial lead

Mocha's production marketing site used the same uncommon artwork for a hard-coded testimonial attributed to Jordan — Designer. The static avatar URL was https://static.getmocha.com/testimonials%3Ajordan.png, and the testimonial began: “I used Mocha to prototype a full stack app and launch it the same day.”

A normalized visual comparison between the Mocha avatar and candidate square crops from the 98-frame Tenor animation produced a best correlation of 0.934. The visible @swrlzxx watermark and matching composition make this a meaningful provider-held first-name lead. It does not establish that Jordan is a legal name, that the testimonial was independently verified, or that the current account operator submitted it.

Historical IP-collection code

Historical Git commits beginning 32638b923305 and 98f07fa1453 contained browser code that queried ipify for a visitor's IP address and sent a line formatted as IP Address: … to Discord webhooks. The webhook IDs were 1433370090992177162 and 1436705296222392552. The code was later removed and the repository head was clean during review.

This is evidence of historical network-information collection capability and intent in those commits. It is not evidence that every visitor was collected, that the webhooks remained controlled by the same person, or that the functionality was connected to the separate CSAM allegation.

The wider account cluster

Public APIs and self-linked profiles supplied further stable identifiers. The table below separates stable provider IDs from mutable display names and profile claims.

Provider-stable identifiers and account bridges
ProviderAccount or IDBridge
YouTubeUCRRINs-5XpUMViDDjfvvFvg / @SwrlzxxDeclared Discord therealswrlzxx and Instagram swrlzxx
YouTubeUCIX_0VSagMi2QjOYDwD6NKw / @hotcheetolickerLinked Instagram swrlzxx and Discord 1166330633363140768
YouTubeUCParc4aG0wM6t8SEjJZ4n3g / @no1cezDirect guns.lol link
Roblox7906337812 / swrlzxxDirect guns.lol link; created 23 Jan 2025
Chess.com429766079 / swrlzxxCountry NP; API verified=false
SoundCloud1507715668 / swrlzxxDirect guns.lol link
Fish Audioe17814829cff4627b33ee31d9673c9faCompatible audio persona
Internet Archive@swrlzxx / idkrandohamSix observed uploads using the same persona
Facebook61574588894886 and 61574951967033swrlzxx/Swrr-branded profiles
HackerOneswrlzxxLinked Butter Web Editor, Discord, Instagram and deleted GitHub/X accounts
Redditu/swrlzxxDirect guns.lol link; account banned for an unknown reason
Vercel CommunityyosyrexchillProbable historical persona; post supplied Discord handle ight.bett

Archived account captures

The following screenshots were captured from the rendered public pages on 10 August 2026 after each page was allowed to finish loading and its visible text was checked. They preserve the account state if the operator deletes or edits the pages. A screenshot records what a page displayed at capture time; provider records and immutable IDs remain stronger evidence of account control.

GitHub profile for 3c18x displaying Discord user ID 1033929243215806594.
GitHub 3c18x publicly displaying Discord user ID 1033929243215806594.Browser capture by mass.report, 10 August 2026
GitHub profile for 33am using the stylized display name Aeoulos.
GitHub 33am using the stylized display name Aeoulos, matching the Telegram handle published by fearshoots.Browser capture by mass.report, 10 August 2026
fearshoots ace.me profile linking law.rf, aeoulos, spycordfr, Spycord and qvfear projects.
The fearshoots hub directly links current handles, Spycord infrastructure and the historical qvfear project portfolio.Browser capture by mass.report, 10 August 2026
guns.lol profile for swrlzxx displaying a Discord account and multiple linked platforms.
The swrlzxx guns.lol hub after its entrance overlay was dismissed, showing the Discord card and linked-platform icons.Browser capture by mass.report, 10 August 2026
X profile spycordfr linking fearshoots ace.me and a Discord invite.
X account @spycordfr self-linking fearshoots.ace.me and a current Discord invite.Browser capture by mass.report, 10 August 2026
X post by spycordfr discussing lost database users and a plan to restore the Spycord tool.
On 10 August 2026, @spycordfr said a code and database mistake removed 80% of logged users and stated an intention to return with the tool in one or two months.Browser capture by mass.report, 10 August 2026
Telegram contact profile aeoulos displaying law and linking the Spycord Discord invite.
Telegram @aeoulos displaying law⁹⁹⁹ and linking discord.gg/spycord.Browser capture by mass.report, 10 August 2026
Discord invitation page for the Spycord server.
The live discord.gg/spycord invitation resolved to a server named Spycord at capture time.Browser capture by mass.report, 10 August 2026
Facebook profile Reall Swrlzxx showing Discord therealswrlzxx and Instagram swrlzxx.
Facebook profile Reall Swrlzxx (Swrr) self-publishing Discord therealswrlzxx and Instagram swrlzxx.Browser capture by mass.report, 10 August 2026
YouTube channel Swr at handle Swrlzxx displaying the therealswrlzxx Discord name.
YouTube @Swrlzxx advertising Discord therealswrlzxx in the channel description.Browser capture by mass.report, 10 August 2026
YouTube channel hotcheetolicker showing linked profiles.
The hotcheetolicker YouTube channel, which publicly linked Instagram swrlzxx and Discord user ID 1166330633363140768.Browser capture by mass.report, 10 August 2026
Quora profile Swrlzxx self-describing as male and 16 and reusing the swrlzxx social handle.
Quora Swrlzxx self-identifying the same Discord, YouTube and Instagram persona and making an unverified age claim.Browser capture by mass.report, 10 August 2026
HackerOne profile Swrlzxx linking butterwebeditor.vercel.app.
HackerOne profile Swrlzxx linking the Butter Web Editor Vercel application.Browser capture by mass.report, 10 August 2026
Roblox profile ID 7906337812 using username swrlzxx.
Roblox profile ID 7906337812 visibly using @swrlzxx.Browser capture by mass.report, 10 August 2026
Tenor user ryaneats showing a GIF based on the swrlzxx angel artwork.
Tenor user ryaneats displaying the distinctive angel artwork associated with swrlzxx.Browser capture by mass.report, 10 August 2026
Reddit page stating that the swrlzxx account has been banned.
Reddit’s rendered state for u/swrlzxx: “This account has been banned.” Reddit does not publicly state the reason.Browser capture by mass.report, 10 August 2026

Chronology

Public account and evidence timeline

  1. Oldest recovered Discord ID created

    Discord ID 1033929243215806594.

  2. Middle Discord ID created

    Discord ID 1166330633363140768, later self-linked by YouTube and guns.lol.

  3. yosyrexchill posts on Vercel Community

    The post supplied Discord handle ight.bett and showed an authenticated YoSyrexChill workspace.

  4. Wallet, Roblox and guns.lol activity

    LTC receipt preceded creation of Roblox 7906337812 and guns.lol UID 415600.

  5. Chess.com profile created

    Account country set to Nepal; API returned verified=false.

  6. Current Swrlzxx YouTube channel joins

    Channel later advertised the Discord and Instagram persona.

  7. Watermarked Tenor GIF uploaded

    ryaneats uploaded the Swrlzxx Discord GIF containing @swrlzxx.

  8. Newest observed Discord account created

    Discord ID 1533211982327713920.

  9. Newest account joins observed server

    Reporter observed the account using the swrlzxx display persona.

  10. NTTS publishes Spycord investigation

    The video identifies the operator as QV Fear and reports victim targeting, minor profiles and a pay-for-removal demand.

  11. fearshoots hub links qvfear and Spycord

    The live ace.me profile links Spycord infrastructure and a now-offline page labelled qvfear web & github projects.

  12. Spycord account states intent to return

    @spycordfr said a code/database error removed 80% of logged users, some records remained, and the tool would return in one or two months.

What the evidence supports

What remains unverified

No surname, residential address, school, telephone number or date of birth has been verified. Jordan remains a first-name lead rather than a confirmed legal identity. Nepal is supported by Chess.com country NP and the UTC+05:45 commit offset but conflicts with self-selected United States and United Kingdom profile locations.

A Quora profile directly tied itself to the persona and self-described the operator as male and 16 years old. That claim is unverified, may be stale and does not support inferring a date of birth. It does require safeguarding review before publication or contact.

The repeated Facebook liker identified by the reporting party remains an unrelated-person lead with no direct ownership bridge and is not attributed to the operator. The Reddit ban reason is unknown. The exact wording, context and attribution of the reported admission remain unavailable in this draft.

Provider preservation and reporting

The highest-value preservation targets are the three Discord IDs, two GitHub immutable user IDs and deleted swrlzxx account, three stable YouTube channel IDs, Tenor post/uploader identifiers, the Mocha testimonial submission, two Facebook profile IDs, Roblox 7906337812, guns.lol internal ID and UID, and the Internet Archive account and upload records.

Provider notices should distinguish observed facts from allegations and request registration, verified contact, access, deletion and historical-link records through appropriate legal process. Suspected illegal material should be reported using original platform URLs and message identifiers without copying or redistributing the material.

Corrections and methodology

This article separates confirmed self-links, high-confidence probable associations, reporter observations and unverified leads. Mutable handles are paired with immutable IDs wherever available. Public API disagreements are resolved in favour of the authoritative provider response—for example, Chess.com's API returned verified=false despite an external collection labelling the account verified.

Material corrections will be appended with dates and an explanation of whether they affect the central account-attribution assessment. New evidence should be evaluated against the same direct-link, stable-identifier and alternative-explanation standard.

Sources and attribution

  1. [1]

    GitHub profile 3c18x

    GitHub · accessed 2026-08-10

  2. [2]

    GitHub profile 33am

    GitHub · accessed 2026-08-10

  3. [3]

    Self-linking swrlzxx profile hub

    guns.lol · accessed 2026-08-10

  4. [4]

    YouTube channel Swrlzxx

    YouTube · accessed 2026-08-10

  5. [5]

    YouTube channel hotcheetolicker

    YouTube · accessed 2026-08-10

  6. [6]

    Tenor uploader ryaneats

    Tenor · accessed 2026-08-10

  7. [7]

    Tenor post 12394650772939061537

    Tenor · accessed 2026-08-10

  8. [8]
  9. [9]

    Roblox public user API for 7906337812

    Roblox · accessed 2026-08-10

  10. [10]

    Chess.com public player API for swrlzxx

    Chess.com · accessed 2026-08-10

  11. [11]

    Internet Archive profile swrlzxx

    Internet Archive · accessed 2026-08-10

  12. [12]

    HackerOne profile swrlzxx

    HackerOne · accessed 2026-08-10

  13. [13]

    Vercel Community post by yosyrexchill

    Vercel Community · accessed 2026-08-10

  14. [14]

    Quora profile Swrlzxx

    Quora · accessed 2026-08-10

  15. [15]

    I Investigated Discord’s Creepiest Moderators...

    No Text To Speech / YouTube · accessed 2026-08-10

  16. [16]
  17. [17]
  18. [18]

    Archived screenshot of the qvfear web and GitHub projects portfolio

    Screenshot supplied to mass.report · accessed 2026-08-10

  19. [19]
  20. [20]

    Telegram contact profile aeoulos

    Telegram · accessed 2026-08-10

  21. [21]

    Spycord Discord invitation

    Discord · accessed 2026-08-10

  22. [22]

    Reall Swrlzxx Facebook profile

    Facebook · accessed 2026-08-10

  23. [23]

    Rendered public-account screenshot archive captured by mass.report

    mass.report · accessed 2026-08-10