You were the one that called it spyware. Your opinion is valid, but my opinion was that Lemmy users tend to exaggerate when talking about closed source software. People are so quick to trash on anything not FOSS, then when asked about sources to back claims up, they are mostly anecdotal and not directly related to the additional claims. Case-in-point, someone asked why you called it spyware, and you responded with the first two points referencing a clauses of a privacy policy that is nearly identical to every social media platform in existence today, and the last point referencing security flaws. The security flaws, in the past, were mostly around cookie stealers (which isn't Discord's fault, literally any browser is at risk if you download malware), and some chromium bugs. A lot of the "hacks" that went around were just scare-pastas that were just made up too. So, no, I don't think there are notable, active flaws that are currently being abused by third-parties as you claim, because Discord has a financial interest to keep their platform secure. If there were active holes being exploited and they just sat around and did nothing, it would upset shareholders, which you noted they did have.
So while you are entitled to your opinion, I do challenge you to consider the other sides of the argument, and consider that closed source software users may have good reasons to use such software. Also do consider that some of the points you made are hyperbolic and that you may be moving the goal posts a bit with your claims.
I wish you well, take care.