Spam attacks have nothing to do with 3rd party clients.
Obligatory "I don't work at Discord, just actively develop against their API" goes here.
So far (to my knowledge) discord hasn't made any effort to prevent modding of its official client. Most people just do it to inject css etc.
That being said I don't think slack/discord should be a thing for open source communities.
There are also a number of cases where a few third party clients that let you modify the background, font, etc. came with malicious code to steal tokens.