If Discord.io was using OAuth then this would largely be a non-issue as those tokens could be invalidated or revoked, by Discord, trivially. And they wouldn't have any password data, hashed or otherwise.
Granted, I don't use discord.io , so maybe I'm missing something.