investigation
Unmasking Spycord
How the Spycord operator moved from qvfear to fearshoots, fearrrx and swrlzxx—and why the evidence points to a persistent doxxing and privacy-abuse threat actor.
This investigation assesses the Spycord operator as a persistent online-abuse actor, documents the qvfear-to-fearshoots infrastructure bridge, and traces later account continuity across GitHub, Discord and public profile hubs. It distinguishes mass.report’s corroborated findings from allegations and direct observations reported by No Text To Speech.
What triggered the investigation
The public investigation began with No Text To Speech’s August 2026 reporting on Spycord and its operator, QV Fear. mass.report then followed the operator’s own public links, repositories, stable platform identifiers and historical code to determine how the earlier qvfear identity connects to the later fearshoots, fearrrx, 3c18x and swrlzxx personas.
The reporting party separately alleged child-sexual-abuse-material-related conduct and reported that the person controlling the newest Discord account made an admission after being confronted. The complete original exchange has not been independently authenticated for this article. This report therefore separates account attribution, NTTS’s observed reporting and the reporter’s allegation instead of treating any one layer as proof of every other claim.
How No Text To Speech exposed Spycord
This investigation was prompted by No Text To Speech (NTTS), whose 8 August 2026 video, “I Investigated Discord’s Creepiest Moderators...,” identified the Spycord operator as QV Fear. NTTS said the inquiry began after a viewer received a Discord message showing that Spycord held 26 images of her. NTTS described the site as a Discord user-ID lookup and profile-aggregation service with a public directory and a separate NSFW category.
In the video, NTTS reported observing 62 directory profiles, a pronounced focus on women and girls, one profile containing 50 images of a woman, a full dox of a person identified as 14, and NSFW video links on a profile identified as 15. mass.report has not reproduced or independently authenticated the suspected illegal material. These details are attributed to NTTS’s direct account of what the channel observed on the then-live service.
NTTS further reported that when the viewer asked QV Fear to remove her photographs, the operator demanded payment—described as money, gift cards, Robux or “anything you can”—and threatened to sell the information to third-party services if she did not pay. We describe this as an alleged coercive pay-for-removal demand, not as a proven legal conclusion. The original messages and provider records should be preserved by Discord and the relevant hosting provider.
Evidentiary and safeguarding boundaries
The review used public pages, public APIs, immutable platform identifiers, historical Git commits and screenshots supplied by the reporting party. Confirmed links are direct self-links from account-controlled pages. High-confidence probable links combine multiple distinctive signals while preserving plausible alternative explanations. Identity leads such as Jordan and Nepal are not treated as established civil-identity facts.
Threat actor assessment
mass.report assesses the subject as a persistent online-abuse actor and the operator of a Discord-focused doxxing and image-aggregation service. The available evidence is more consistent with targeted privacy abuse, humiliation, coercive control and monetized removal demands than with conventional cybercrime carried out for technical access alone. The actor’s threat comes from combining public-data collection, social-platform access, web publishing and victim pressure in one repeatable workflow.
| Dimension | Assessment | Confidence |
|---|---|---|
| Actor type | Online-abuse, doxxing and privacy-abuse service operator | High |
| Likely objectives | Collection and exposure of victims; humiliation and control; reputation or clout; alleged pay-for-removal monetization | Moderate |
| Victimology | Women and girls were reportedly overrepresented; NTTS reported profiles of people identified as 14 and 15 | High for NTTS reporting; not independently authenticated |
| Capabilities | Discord-ID lookup, profile and image aggregation, doxxing publication, web deployment, Discord webhook use and historical visitor-IP collection | High |
| Access model | Primarily social-platform and public-data collection; source of private media is not established | Moderate |
| Technical sophistication | Low to moderate: capable of deploying useful abuse tooling, but no evidence of advanced intrusion capability | Moderate |
| Persistence | High: repeated aliases, replacement Discord accounts, multiple hubs and an August 2026 “Spycord back” link | High |
| Operational security | Poor: repeated self-linking, immutable IDs, reused aliases and a live bridge back to qvfear projects | High |
The demonstrated technical capability is practical rather than advanced. The cluster shows it can build and deploy web applications, organize searchable Discord-derived records, use Discord webhooks and collect visitor IP addresses in historical code. There is no public evidence here of vulnerability exploitation, privileged access, malware deployment by the subject or sophisticated intrusion tradecraft. “Threat actor” in this report describes the operator’s sustained harmful conduct and infrastructure, not an unsupported claim that the actor is an advanced hacker.
The likely harm model is cumulative: locate a target through Discord, aggregate identifying information and images, publish a durable profile, expose or threaten exposure of sensitive material, and make removal dependent on the operator’s discretion. Where a target is a minor, the safeguarding risk becomes acute even without proving how the media was obtained. NTTS’s report of money, gift-card and Robux demands indicates a possible monetization layer attached to that pressure.
NTTS also described a person named Terror as an associate and alleged that Terror advertised a remote-access trojan on Telegram. That is an ecosystem lead, not evidence that QV Fear developed, distributed or used the malware. The later portion of the NTTS video examines a wider network of leaking servers and additional operators; those actors and acts are not attributed to QV Fear unless a direct link is documented.
From qvfear to fearshoots
The historical alias is not supported only by NTTS’s naming. On 10 August 2026, the live fearshoots.ace.me profile displayed the name fearshoots and linked “Spycord back,” a Spycord Discord invite and a now-offline page labelled “qvfear web & github projects.” The same profile advertised Discord law.rf, Telegram aeoulos and X account spycordfr. Because these identifiers appear together on one account-controlled hub, they are documented self-claims at the time of capture rather than mere username matches.
| Identifier | Role or label | Assessment |
|---|---|---|
| fearshoots.ace.me | Current profile hub | Direct source |
| fear.subeditor.works | “qvfear web & github projects”; now offline | Directly linked historical hub |
| disface.vercel.app | “Spycord back” | Directly linked service |
| law.rf / discord.gg/GptR9ha4BG / discord.gg/spycord | Discord handle and invites | Self-published; provider verification required |
| aeoulos | Telegram handle | Self-published |
| spycordfr | X account | Directly linked |
The archived qvfear project portfolio
A screenshot supplied to mass.report preserves the now-offline fear.subeditor.works portfolio. The page identifies itself as qvfear, describes the collection as experimental web and GitHub projects, and displays “Discord: qvfear.” Most importantly for attribution, the card titled “System Maintenance template | qvfear” tells users to contact qvfear at Discord user ID 1033929243215806594—the same immutable Discord ID independently recovered from the fearrrx/3c18x account trail.

| Project | Portfolio description | What it supports |
|---|---|---|
| AgentRG | Deep Research | Autonomous web-research and information-finding agent using Gemini | Claimed interest in automated OSINT and research |
| Subreddit Scraper | Browse subreddits, download media and view discussions | Claimed scraping and bulk-media collection capability |
| Vanta Key | Validator for Gemini, OpenAI, Anthropic, OpenRouter and DeepSeek API keys | Claimed API-key validation tooling |
| Invis Ink | Steganography studio for hiding messages inside plain text or images | Claimed steganography capability |
| PhoneSint | Phone-number lookup with carrier, location and risk analysis | Claimed phone-intelligence and OSINT capability |
| waifu.pics Discord bot | Discord bot using the waifu.pics API | Claimed Discord-bot development capability |
The portfolio supports the assessment that the operator had broad, practical web-development, scraping, OSINT and Discord-automation interests. It does not by itself prove that every listed project was functional, independently authored, deployed against victims or used by Spycord. The strongest evidentiary value is attribution: the archived page binds the qvfear name to the same immutable Discord ID already present in the later account cluster.
This bridge materially improves the alias chain: QV Fear/qvfear is an earlier operator identity; fearshoots is a current self-presentation that points back to qvfear projects and active Spycord-branded infrastructure; fearrrx, 3c18x and swrlzxx are the later personas assessed elsewhere in this report. Provider records are still needed to prove continuous control across every account and date.
Current infrastructure and stated reactivation intent
The current infrastructure is not merely historical. At capture time, @spycordfr linked fearshoots.ace.me and a current Discord invitation. Telegram @aeoulos displayed the law persona and linked discord.gg/spycord; that invitation resolved to a server named Spycord.
On 10 August 2026, @spycordfr publicly wrote that a mistake in the code and database had removed “80% of the logged users,” said some records remained, and stated: “Give me a month or 2, I’ll be back with the tool but fully fixed.” The account added that it would not republish the site “for now.” Because the X profile directly self-links the fearshoots hub, this is strong evidence of continued service control and stated reactivation intent, not merely a similarly named third-party comment.
GitHub breadcrumbs
GitHub account 3c18x, immutable user ID 225708812, published a README commit that directed readers to Instagram swrlzxx. The full commit hash is 4fecc3c856db77a8da25e4b6f228dd7835e52311. The account also used the fearrrx persona and published historical Discord identifier 1033929243215806594.
GitHub account 33am, immutable user ID 168169181, is assessed as a high-confidence probable alternate account. The 3c18x account followed exactly one GitHub account—33am—and both histories used the rare UTC+05:45 commit offset associated with Nepal Time, alongside overlapping 3x18 and fear-style aliases. These signals support common control but are not individually conclusive.
| Account | Immutable ID | Evidence | Assessment |
|---|---|---|---|
| 3c18x | 225708812 | README commit self-linked Instagram swrlzxx; fearrrx and Discord bridge | Confirmed cluster link |
| 33am | 168169181 | Only account followed by 3c18x; shared UTC+05:45 and alias pattern | High-confidence probable |
| swrlzxx | Not recovered | Deleted account linked by HackerOne and guns.lol | Confirmed historical link |
The current GitHub profile for 33am uses the stylized display name Aeoulos. The live fearshoots hub independently advertises Telegram aeoulos, and that Telegram profile links discord.gg/spycord. This rare cross-platform alias match materially strengthens—without by itself conclusively proving—the assessed common control of 33am and the current Spycord cluster.
Discord account continuity
Three Discord snowflakes span the cluster's observed history. ID 1033929243215806594 was published by the fearrrx/3c18x persona. ID 1166330633363140768 was directly linked by the hotcheetolicker YouTube channel and the guns.lol hub. The reporting party observed ID 1533211982327713920 in the relevant server using display name swrlzxx and username ich_beobachte_dich_in_der_u8.
| User ID | Snowflake creation | Public or observed bridge |
|---|---|---|
| 1033929243215806594 | 24 Oct 2022 02:25:41 UTC | Published by fearrrx/3c18x persona |
| 1166330633363140768 | 24 Oct 2023 11:01:32 UTC | Self-linked by guns.lol and YouTube hotcheetolicker |
| 1533211982327713920 | 1 Aug 2026 20:37:02 UTC | Reporter-observed current swrlzxx account |
The latest-account bridge depends on the original server observation rather than an independent public self-link. A provider preservation request should include the server, channel and message IDs surrounding the reported admission, not merely screenshots or display names.
The self-linking guns.lol hub
The strongest central artifact is guns.lol/swrlzxx. Its internal document ID was 6794c4a10fa705ce4bbc166d, public UID 415600 and observed account creation time 25 January 2025 11:01:53 UTC. The profile described swrlz as he/him and a web developer, graphic designer, music producer, content creator, software developer and pixel artist.
From one account-controlled page, the operator linked Instagram swrlzxx, Discord ID 1166330633363140768, SoundCloud swrlzxx, Roblox 7906337812, deleted GitHub swrlzxx, Reddit u/swrlzxx, YouTube channels Swrlzxx, no1cez and yosyrexchill, plus three cryptocurrency addresses. This makes the hub connective evidence rather than mere username coincidence.
| Asset | Address | Observed public-chain activity |
|---|---|---|
| BTC | bc1q3mpvylv7vvzrfupu52ecgpwfmr374yupsanurt | No transactions or balance at review |
| LTC | LMKZ7Tp5FaViiKdQcBqHAXdgEF5q1VTm1N | Received and later spent 0.00086006 LTC; zero balance |
| ETH | 0xc858affb3a3fcc25c1fe9827a5491adc42a5bcad | No transactions or balance at review |
A fourth entry displayed with a Monero-style M icon repeated the Ethereum address. The 42-character EVM address is not a valid Monero address, so the entry was mislabeled or a placeholder rather than evidence of a separate wallet.
The watermarked Tenor upload
Tenor uploader ryaneats published post 12394650772939061537, media key rAKlNVQNuSE, titled Swrlzxx Discord GIF and tagged swrlzxx, discord, anime, chainsaw man and angel. The 498×280, 7.8-second animation visibly carries the watermark @swrlzxx. Tenor displayed its creation as 25 July 2025 17:32:03 without exposing a timezone.
The “Jordan” testimonial lead
Mocha's production marketing site used the same uncommon artwork for a hard-coded testimonial attributed to Jordan — Designer. The static avatar URL was https://static.getmocha.com/testimonials%3Ajordan.png, and the testimonial began: “I used Mocha to prototype a full stack app and launch it the same day.”
A normalized visual comparison between the Mocha avatar and candidate square crops from the 98-frame Tenor animation produced a best correlation of 0.934. The visible @swrlzxx watermark and matching composition make this a meaningful provider-held first-name lead. It does not establish that Jordan is a legal name, that the testimonial was independently verified, or that the current account operator submitted it.
Historical IP-collection code
Historical Git commits beginning 32638b923305 and 98f07fa1453 contained browser code that queried ipify for a visitor's IP address and sent a line formatted as IP Address: … to Discord webhooks. The webhook IDs were 1433370090992177162 and 1436705296222392552. The code was later removed and the repository head was clean during review.
This is evidence of historical network-information collection capability and intent in those commits. It is not evidence that every visitor was collected, that the webhooks remained controlled by the same person, or that the functionality was connected to the separate CSAM allegation.
The wider account cluster
Public APIs and self-linked profiles supplied further stable identifiers. The table below separates stable provider IDs from mutable display names and profile claims.
| Provider | Account or ID | Bridge |
|---|---|---|
| YouTube | UCRRINs-5XpUMViDDjfvvFvg / @Swrlzxx | Declared Discord therealswrlzxx and Instagram swrlzxx |
| YouTube | UCIX_0VSagMi2QjOYDwD6NKw / @hotcheetolicker | Linked Instagram swrlzxx and Discord 1166330633363140768 |
| YouTube | UCParc4aG0wM6t8SEjJZ4n3g / @no1cez | Direct guns.lol link |
| Roblox | 7906337812 / swrlzxx | Direct guns.lol link; created 23 Jan 2025 |
| Chess.com | 429766079 / swrlzxx | Country NP; API verified=false |
| SoundCloud | 1507715668 / swrlzxx | Direct guns.lol link |
| Fish Audio | e17814829cff4627b33ee31d9673c9fa | Compatible audio persona |
| Internet Archive | @swrlzxx / idkrandoham | Six observed uploads using the same persona |
| 61574588894886 and 61574951967033 | swrlzxx/Swrr-branded profiles | |
| HackerOne | swrlzxx | Linked Butter Web Editor, Discord, Instagram and deleted GitHub/X accounts |
| u/swrlzxx | Direct guns.lol link; account banned for an unknown reason | |
| Vercel Community | yosyrexchill | Probable historical persona; post supplied Discord handle ight.bett |
Archived account captures
The following screenshots were captured from the rendered public pages on 10 August 2026 after each page was allowed to finish loading and its visible text was checked. They preserve the account state if the operator deletes or edits the pages. A screenshot records what a page displayed at capture time; provider records and immutable IDs remain stronger evidence of account control.
















Chronology
Public account and evidence timeline
Oldest recovered Discord ID created
Discord ID 1033929243215806594.
Middle Discord ID created
Discord ID 1166330633363140768, later self-linked by YouTube and guns.lol.
yosyrexchill posts on Vercel Community
The post supplied Discord handle ight.bett and showed an authenticated YoSyrexChill workspace.
Wallet, Roblox and guns.lol activity
LTC receipt preceded creation of Roblox 7906337812 and guns.lol UID 415600.
Chess.com profile created
Account country set to Nepal; API returned verified=false.
Current Swrlzxx YouTube channel joins
Channel later advertised the Discord and Instagram persona.
Watermarked Tenor GIF uploaded
ryaneats uploaded the Swrlzxx Discord GIF containing @swrlzxx.
Newest observed Discord account created
Discord ID 1533211982327713920.
Newest account joins observed server
Reporter observed the account using the swrlzxx display persona.
NTTS publishes Spycord investigation
The video identifies the operator as QV Fear and reports victim targeting, minor profiles and a pay-for-removal demand.
fearshoots hub links qvfear and Spycord
The live ace.me profile links Spycord infrastructure and a now-offline page labelled qvfear web & github projects.
Spycord account states intent to return
@spycordfr said a code/database error removed 80% of logged users, some records remained, and the tool would return in one or two months.
What the evidence supports
What remains unverified
No surname, residential address, school, telephone number or date of birth has been verified. Jordan remains a first-name lead rather than a confirmed legal identity. Nepal is supported by Chess.com country NP and the UTC+05:45 commit offset but conflicts with self-selected United States and United Kingdom profile locations.
A Quora profile directly tied itself to the persona and self-described the operator as male and 16 years old. That claim is unverified, may be stale and does not support inferring a date of birth. It does require safeguarding review before publication or contact.
The repeated Facebook liker identified by the reporting party remains an unrelated-person lead with no direct ownership bridge and is not attributed to the operator. The Reddit ban reason is unknown. The exact wording, context and attribution of the reported admission remain unavailable in this draft.
Provider preservation and reporting
The highest-value preservation targets are the three Discord IDs, two GitHub immutable user IDs and deleted swrlzxx account, three stable YouTube channel IDs, Tenor post/uploader identifiers, the Mocha testimonial submission, two Facebook profile IDs, Roblox 7906337812, guns.lol internal ID and UID, and the Internet Archive account and upload records.
Provider notices should distinguish observed facts from allegations and request registration, verified contact, access, deletion and historical-link records through appropriate legal process. Suspected illegal material should be reported using original platform URLs and message identifiers without copying or redistributing the material.
Corrections and methodology
This article separates confirmed self-links, high-confidence probable associations, reporter observations and unverified leads. Mutable handles are paired with immutable IDs wherever available. Public API disagreements are resolved in favour of the authoritative provider response—for example, Chess.com's API returned verified=false despite an external collection labelling the account verified.
Material corrections will be appended with dates and an explanation of whether they affect the central account-attribution assessment. New evidence should be evaluated against the same direct-link, stable-identifier and alternative-explanation standard.
Sources and attribution
- [1]
GitHub · accessed 2026-08-10
- [2]
GitHub · accessed 2026-08-10
- [3]
Self-linking swrlzxx profile hub
guns.lol · accessed 2026-08-10
- [4]
YouTube · accessed 2026-08-10
- [5]
YouTube channel hotcheetolicker
YouTube · accessed 2026-08-10
- [6]
Tenor · accessed 2026-08-10
- [7]
Tenor post 12394650772939061537
Tenor · accessed 2026-08-10
- [8]
Mocha testimonial avatar attributed to Jordan
Mocha · accessed 2026-08-10
- [9]
Roblox public user API for 7906337812
Roblox · accessed 2026-08-10
- [10]
Chess.com public player API for swrlzxx
Chess.com · accessed 2026-08-10
- [11]
Internet Archive profile swrlzxx
Internet Archive · accessed 2026-08-10
- [12]
HackerOne · accessed 2026-08-10
- [13]
Vercel Community post by yosyrexchill
Vercel Community · accessed 2026-08-10
- [14]
Quora · accessed 2026-08-10
- [15]
I Investigated Discord’s Creepiest Moderators...
No Text To Speech / YouTube · accessed 2026-08-10
- [16]
fearshoots profile hub linking Spycord and qvfear projects
ace.me · accessed 2026-08-10
- [17]
Historical qvfear web and GitHub projects hub (offline at review)
subeditor.works · accessed 2026-08-10
- [18]
Archived screenshot of the qvfear web and GitHub projects portfolio
Screenshot supplied to mass.report · accessed 2026-08-10
- [19]
Spycord X profile and reactivation statement
X · accessed 2026-08-10
- [20]
Telegram contact profile aeoulos
Telegram · accessed 2026-08-10
- [21]
Discord · accessed 2026-08-10
- [22]
Reall Swrlzxx Facebook profile
Facebook · accessed 2026-08-10
- [23]
Rendered public-account screenshot archive captured by mass.report
mass.report · accessed 2026-08-10