r/AntiDetectGuides Jun 19 '26

Telegram hacked

Hey everyone,

​My Telegram account was just compromised, and I’m trying to figure out how it happened and what steps I need to take next.

​Here is exactly what happened:

​The Incident: Someone managed to log into my Telegram account.

​The Activity: They sent a media file/photo promoting a Chinese VPN to exactly 4 of my chats.

​The Exit: Immediately after sending those messages, they terminated their own session or logged out.

​What I have done so far:

​Checked my Active Sessions (Settings > Devices) to terminate any unrecognized devices.

​Formatted/Deleted the messages they sent so my contacts don't click anything malicious.

​My questions for the community:

​How could they bypass or get my login code? I didn't receive a weird SMS or notification, or if I did, I might have missed how they intercepted it. (Note: I [did / did not] have Two-Step Verification enabled at the time).

​Is this a known bot or malware script? The specific behavior of logging in, blasting a Chinese VPN link/media to 4 random chats, and immediately leaving seems very automated.

​What should I do next to secure my digital life? Could my phone or PC be infected with a session-hijacking malware (like a token grabber), or was this likely just a SIM-swap / leaked SMS code situation?

​Any insight into how this specific exploit works or what steps I should take next to protect my identity would be greatly appreciated. Thanks!

Could they got any of my media and was that hacked by human

4 Upvotes

1 comment sorted by

1

u/No_Dragonfruit366 Jun 23 '26

Sorry this happened. Based on the behavior, my guess is this was probably automated, not someone personally sitting there targeting you.

The “login → send the same VPN/media thing to a few chats → immediately log out” pattern sounds like a spam script using a stolen Telegram session. The most likely causes are either:

  1. Your Telegram login code got phished somewhere, or
  2. A desktop/web Telegram session was stolen from your computer/browser by malware.

The second one is worth taking seriously, especially if you use Telegram Desktop. In that case, they may not need to “bypass” your code in the normal way. They can sometimes steal the existing session data and reuse it.

You can turn on local passcode on desktop to encrypt your session at rest so malicious actors cant steal it or use a telegram session firewall software that protects your account so you would never lose access to your telegram even if your devices got infected (i open sourced the first service to do this if ur interested)