v2.5.3 Release Notes
We've added Black Hole, which stops indiscriminate spam from compromised accounts at the very first message. Verification settings now live inside the protection settings panel, and every feature's settings command has been unified under `settings`. On the dashboard, per-server settings now show server names instead of raw IDs, and the backup viewer has been rebuilt. This release also fixes several commands — including ticket, role panel, and poll commands — that were failing every single time.

|
|
Published: August 12, 2026BotShade has been updated to v2.5.3. This release introduces Black Hole, a new anti-raid feature. We’ve also consolidated verification settings into the protection panel and unified the naming of every settings command. On the dashboard, per-server settings that used to appear as long strings of digits are now shown by name.
Some commands were failing every single time. We apologise for the disruption this caused.
If anything looks off, please let us know via Support.
Table of contents:
- Highlights
- Black Hole — stop indiscriminate spam at the first message
- Verification settings moved into protection
- Settings commands have been renamed consistently
- Pick what to edit from a list
- Per-server settings now show server names
- The backup viewer is actually readable now
- Dashboard improvements
- Security fixes
- Bug fixes
- Compatibility
- Support & community
Highlights
- Black Hole is now available. Posting in a channel you designate is treated as a violation in itself, and the account is actioned on the very first message. It’s designed for compromised accounts that blast spam across every channel in a server.
- Verification settings now live under “Verification System” in
/protection settings./verification setuphas been removed. - Every feature’s settings command has been unified under
settings(for example,/level settingis now/level settings). Your existing settings and permissions carry over unchanged. - Per-server settings on the dashboard now show the server’s name and icon instead of a string of digits. You also no longer have to reselect the server every time you pick a channel or role.
- The backup viewer has been rebuilt. Roles are listed in their actual hierarchy, and channels follow the real category structure.
- Fixed
/ticket settings,/ticket panel,/rolepanel create,/poll createand others failing every single time. - Fixed server protection (Anti-Nuke) failing to catch fast, back-to-back deletions.
Black Hole — stop indiscriminate spam at the first message
When an account is compromised, it typically posts into every channel it can reach, one after another. Anything that has to read and judge the message text takes time — and the spam keeps spreading while that judgement runs.
Black Hole decides based on which channel the message landed in, nothing else. You designate channels where posting is a violation in itself, and anyone who posts there is actioned immediately, regardless of what they wrote.
Which channels to designate
Pick channels nobody normally posts in. For example:
- Rules or announcement channels meant for reading only
- Channels you no longer use, or keep purely as an archive
- A quiet channel created specifically for this purpose
Legitimate members simply won’t post in these channels, so the only accounts that trigger it are the ones posting without regard to where they are. Posts in threads under a designated channel count too.
How to set it up
Run /protection settings and open Black Hole.
- Restricted channels — the channels to designate (you can pick more than one)
- Action — ban (default), kick, or timeout
- Delete message — whether to delete the offending post when it triggers (on by default)
- First-time grace — when enabled, the first offence is only deleted and warned; anything within the next 24 hours is actioned (off by default)
- Exempt roles — roles excluded from this feature
Ban is the default action because it’s the only one that also removes the spam posted in your other channels.
Who is never affected
- The server owner
- Anyone with administrator permission. In practice this is you or your staff, and being actioned for a test post is more disruptive than the risk it covers. If an administrator account is compromised, server protection (Anti-Nuke) is what handles the damage.
- Anyone holding an exempt role
- Anyone on the whitelist
Note that Black Hole takes priority over the protection “exempt channels” setting, since posting in the channel is itself the violation.
No message content access required
Because Black Hole only looks at where a message was posted, it works even on bots that don’t have message content access. It also doesn’t get more expensive to run while a server is being flooded.
The feature is added in the off state on existing bots. Enable it from /protection settings when you want it.
Verification settings moved into protection
Verification — the button new members press to gain access — had its settings split across /verification setup and /protection settings, and the latter was missing several options.
In v2.5.3 there is one place: “Verification System” in /protection settings, with every option available, including the button label and the verification message.
As a result, /verification setup has been removed. The verification page on the dashboard no longer has a command permissions section either, since there is no longer a command to configure. Turning the feature itself on or off still works from the dashboard as before.
Verification remains independent of the protection toggle — turning protection off does not break the buttons on verification panels you’ve already posted.
We also fixed verification panels failing to send when both the embed title and description had been left empty. In that case we now fill in the default wording and send it.
Settings commands have been renamed consistently
Depending on the feature, the command that opens a settings panel was either setting or settings. In v2.5.3 they are all settings.
| Before | From v2.5.3 |
|---|---|
/protection setup | /protection settings |
/log setting | /log settings |
/rolepanel setting | /rolepanel settings |
/welcome setting | /welcome settings |
/ticket setting | /ticket settings |
/responder setting | /responder settings |
/level setting | /level settings |
/role-retention setting | /role-retention settings |
No migration is required on your side. Whether each command is enabled and who can use it carries over exactly as configured. /gaming settings was already plural and is unchanged.
Pick what to edit from a list
/ticket settings and /poll edit required you to type the name of what you wanted to edit, which made them unusable if you couldn’t remember it.
In v2.5.3, omitting the name gives you a list to choose from.
/ticket settings— omit the name to pick from the panels you’ve set up/poll edit— omit the name to pick from your running polls. Give only the name and you get an editing panel showing the current title and description (previously this ended with a “specify a title or description” error)
Specifying both the name and the new content to change it in one go still works exactly as before.
Per-server settings now show server names
Twelve features — logs, embed messages, verification, protection, tickets, role panels, welcome messages, leveling, auto-responder, game integrations, role retention, and AI — let you configure each server separately. Until now, those entries were labelled Server: 123456789012345678, leaving you to match strings of digits by eye.
v2.5.3 shows the server’s icon and name instead. Channels and roles selected inside each entry are shown by name too.
Choosing channels and roles is better as well
- No more reselecting the server. Picking a channel inside “the settings for server A” used to start from a list of servers every single time. We already know which server it is, so that step is gone.
- The selected name is visible before you open the picker. It used to stay as digits until you opened it once.
- Fixed being able to pick a channel or role belonging to a different server. The list is now limited to that server.
- Opening settings for a server the bot isn’t in now shows “the bot isn’t in this server” rather than a raw error.
- Fixed a warning appearing on a freshly added entry before you’d selected anything.
A channel you’ve just created may not appear in the list yet. You can still enter its ID directly in that case, so legitimate input is never rejected.
The backup viewer is actually readable now
The screen for reviewing a saved backup didn’t work as a way to review anything.
- Role hierarchy was lost. Roles derive their meaning from their order — higher roles are stronger, and they’re recreated in that order on restore — yet they were laid out in a way that discarded it. They are now listed top to bottom in one column, with colour, name, and attributes aligned.
- Administrator roles were almost never detected. The administrator check was wrong: a role with any other permission alongside it wasn’t recognised as an administrator.
- Channels didn’t match the real structure. Text and voice channels were split into separate flat lists with the parent category in parentheses, which made the server’s layout impossible to read. They now follow the actual category structure.
Dashboard improvements
- Fixed bouncing between the dashboard and the login screen right after signing in. A “your session needs to be re-established” message would appear, and you couldn’t get out without forcing a reload several times. The cause was treating any single failed request as being signed out.
- The first screen loads faster. There was unnecessary sequential waiting between opening the dashboard and seeing your bot list. We’ve also pinned the request relay to Tokyo so requests from Japan don’t take a detour.
- Internal IDs moved behind developer mode. Now that names are shown, there’s no reason for digits to sit permanently next to them. Enable developer mode in your account settings and IDs are shown in full rather than the last six digits (only the full ID is any use when contacting support).
- Fixed the server list page: icons that always failed to load, an “Owner ID” column that was always empty, and buttons that did nothing. We’ve added a refresh button for servers you’ve just invited the bot to.
- Tidied up the settings screens. Cards nested inside cards have been replaced with rule-based separation, making it clearer where one entry ends and the next begins.
Security fixes
The following were found during internal review. All are fixed, and no action is required on your side.
- Fixed buttons and menus in custom commands being usable by people other than the person who ran the command. Anyone could press a button posted in a channel, and doing so continued the flow with the original runner’s permissions. Only the person who ran the command can use them now.
- Fixed server protection (Anti-Nuke) missing fast, back-to-back deletions. Rapid repetitions of the same kind of operation fell outside detection — meaning the faster the deletion, the more likely it went unnoticed, failing precisely when protection matters most. We also fixed protection silently doing nothing on servers where the bot lacks audit log access.
- Fixed backup commands suggesting information from other servers. Backup names across every server the bot is in were offered as suggestions, including to users without permission. These suggestions could never actually be used — the issue was the disclosure itself.
- Fixed image generation being stallable by sending large amounts of certain characters to
/miq. This could affect image generation for other customers on the same infrastructure. Input is now capped at 500 characters. - The “API request” destination is now re-checked immediately before connecting. There was a brief window between the check and the connection in which the destination could be swapped to bypass restrictions.
- Fixed internal operational records being shown in the logs screen.
- Deleting a bot now deletes its data. Previously only the bot’s registration was removed, leaving balances, levels, custom commands, reminders and more behind indefinitely.
Bug fixes
Commands
- Fixed several commands failing every single time:
/ticket settings,/ticket panel, the ticket AI settings panel, loading role panels,/rolepanel create, and/poll create. The cause was an incorrect internal reference, and we’ve added an automated check so the same class of mistake can’t slip in again. - Fixed verification panels failing to send (see Verification settings moved into protection).
AI
- Fixed “this model isn’t available on your current plan” appearing for every model except DeepSeek V4 Flash, even on BotShade Max. The bot’s copy of the model list was out of date and eight models didn’t exist as far as it was concerned. The real problem was “model not found”, but it surfaced with the same wording as a plan restriction. We also fixed models that BotShade Plus could select on the dashboard being rejected by the bot.
Variables
- Fixed server-wide variables sometimes not saving. It surfaced unpredictably as “the variable I saved isn’t applied” or “it reverted after a restart”.
Compatibility
Your existing bots and command definitions continue to work in v2.5.3. No migration is required.
Three things to be aware of:
- Settings commands have been renamed.
/level settingbecomes/level settings, and so on — see the table in Settings commands have been renamed consistently. Whether each command is enabled and who can use it carries over. /verification setuphas been removed. Configure verification from “Verification System” in/protection settings.- Black Hole is added in the off state. Enable it from
/protection settingswhen you want it.
Support & community
For questions, bug reports, or feature requests, please reach out through either of the following:
- Support page — contact form
- status.botshade.com — service status
Thank you for using BotShade.