
Hackers have found a way to take over someone else's Telegram without waiting for the victim to click on anything. They are aided by a simple answering machine. This case was described by a developer who has been working in the crypto industry for over ten years. His account was taken over in five minutes at night, and the login code was dictated to the hacker by voicemail. At 3:54 AM, the phone started ringing. Ten calls in a row from a hidden number. The developer initially thought someone was prank calling. In reality, the calls were the attack: their task was to occupy the line. While the phone was busy, the hacker requested a login to Telegram from another number. The method of code delivery he chose was not the most obvious, a voice call. The Telegram robot called, couldn't get through, and switched to voicemail. It read the code there.
The rest was simple. Many operators allow remote access to voicemail. A standard PIN or caller ID spoofing suffices. The hacker listened to the recording, and by 3:59 AM, he was inside the system. What saved the situation was that the attack was noisy. The calls woke the account owner. At 4 AM, he checked the notifications, where Telegram reported a login from an unfamiliar device. He closed the unauthorized session within a couple of minutes. By that time, the hacker had not wasted time: he had already gone through all the old wallet bots in the chats and sent them the commands /balance and /start. He was looking for money linked to the account. The bots had long been inactive, so he found nothing. However, he managed to set his own two-factor authentication password on the account.
What could have prevented the hack. The developer compiled a list of what would have broken this scheme. The main thing is to enable two-step verification in Telegram and link a backup email. If the account has a password, the code alone will not help the hacker. Next, voicemail. Change the PIN, disable remote access, or remove the function altogether. The same should be done for WhatsApp and any service that can send a code by voice. No seed phrases, keys, or passwords in Favorites. Never. And one more thing: if you receive consecutive calls from a hidden number at night, it's not a reason to be angry, but a reason to be cautious. Check notifications and the list of active sessions. The author of the post admits that in over ten years in the industry, he never thought about his own answering machine and advises everyone to check theirs today.
This material is prepared solely for informational purposes and does not constitute financial advice or a recommendation.




