Buying Telegram accounts: what is really on the shelf
Marketplaces sell Telegram accounts from $0.37 apiece - and a major one labels part of its own stock as obtained by phishing and malware. What you actually get, who can take it back, and why registering your own is the better trade.
Updated: August 2026 · 11 min read
The pitch is simple: why spend weeks registering and warming accounts when a shop sells them for $0.37 apiece, with “aged” ones a few dollars more? This guide is not a catalogue of shops - it is a look at what that inventory actually is, what the market itself admits about its origin, and why the cheap path usually ends up the most expensive one.
Every price below was checked in August 2026 on the storefronts themselves and will drift. Treat the figures as orders of magnitude and verify before relying on them.
What is actually on sale
Account shops sell two broad tiers. Fresh registrations (“autoregs”) are accounts created recently and in bulk, usually through number-rental services. Aged accounts advertise a registration year, and the year is the price axis: the older the account, the more it costs.
What you buy is a file, not a login: a tdata folder from Telegram Desktop, or a session string plus a JSON of device parameters - tdata and session strings explains what those contain.
| Lot | Price apiece |
|---|---|
| Fresh registration, mixed geo | $0.37 |
| Fresh registration, US / UK number | $0.46-1.11 |
| Fresh registration, RU number | up to $3.50 |
| Aged, registered 2025 | $1.20 |
| Aged, registered 2024 | $1.57 |
| Aged, registered 2023 | $3.70 |
| Aged, registered 2021 | $13.88 |
| Aged, registered 2020, US number | $17.58 |
Two things stand out. A 2020 account costs about 45 times a fresh mixed-geo one - that is how much the market believes age is worth; whether the belief is justified comes later. And guarantee badges (“48-hour replacement”) promise at most one thing - the login works at delivery; the storefront we checked does not publish the fine print behind the badge. Everything after that is your risk, and it transfers at checkout.
Stolen accounts sit on the same shelf
Here is the fact that settles the question for us. One of the largest account marketplaces, lzt.market, documents in its public API an origin field on every listing. The documented values include autoreg, personal, resale and self_registration - and also brute (password-guessed), phishing and stealer (harvested by credential-stealing malware). The API even ships a dedicated filter, not_origin[]=brute,phishing,stealer, so buyers can exclude stolen goods.
Read that as an operator. Stolen accounts are standard shelf inventory, classified and filterable like a shirt size - nobody builds an “exclude stolen” toggle for a problem they do not have. And storefronts that do not label origin are not cleaner; you just lose the label.
Why this bites harder on Telegram than almost anywhere else: identity is bound to the phone number. Whoever controls the number can pass SMS re-verification and recover the account - recovery sides with whoever proves the phone, not whoever holds a session file. The original owner of a stolen account keeps that master key forever.
The number is the loudest handle a seller can keep, and the only one most buyers check. The quieter ones survive an ordinary handover too - including on an account sold in good faith. Hardest to notice first:
- A copy of the authorization key. A session string or a
tdatafolder is a copy, not a transfer: you get a duplicate and the seller keeps the original. It is the same authorization rather than a second one, so it shows up as no separate row in the active-sessions list and adds nothing to the device count. And Telegram delivers login codes inside the app, into the service chat - that is, into the very session whose copy the seller is holding. “Terminate every session you did not create” stays good advice for the unfamiliar devices in that list, but it does not reach this one: there is nothing there to terminate. What closes it is getting an authorization of your own and then revoking the one you were handed - an order with a day's wait inside it, written out once in preparing a bought account. - The sign-in email. A second address, separate from the recovery one, that has Telegram send the login code to a mailbox instead of the phone. Changing the cloud password does not remove it, and an address you did not set delivers every code to the seller.
- The recovery email attached to the cloud password. Setting your own password on top does not detach it, so it still hands over the password itself. Only removing the password entirely and setting it again from scratch, or repointing the address by hand, closes that door.
- The number, as above: whoever can receive an SMS on it can ask for a code whenever they like.
All four end in the same place - a login code - and a code is worth more than it looks. It opens two doors, and neither of them asks for the cloud password. Account deletion is offered on the sign-in screen itself and is immediate: the account is erased and the number goes free, taking the history, the channels and every week of warming with it. Password reset (account.resetPassword) does not destroy the account, it transfers it: the request starts a seven-day timer, and when it runs out two-step verification comes off, every session on the account is signed out, and the account changes hands whole - history, subscriptions, contacts, warming. Whoever asked for it never needed a session of their own; what they hold is the code, and once the password is gone the code is the entire login. Nothing is deleted - the account simply belongs to someone else.
Those seven days are quiet. The account keeps working exactly as before - we watched a full week of one in our own action journal and found nothing that gives the wait away. One of them we have timed end to end: the request went in at 21:10 UTC on 15 August 2026, and two-step verification came off at 22:03 UTC on 22 August 2026.
The single warning arrives at the start, and it is not an email. Telegram sends it as a service message into the account's own chat with Telegram - inside the app, the same place login codes land, so a copy of the key reads it too. We have never seen that notice turn up in an attached mailbox, so watching email is no substitute for watching the account. The message carries a button that declines the request, and any live session can decline it (account.declinePasswordReset) without a password or a code. A decline removes that request and takes the account off the clock; how quickly the same person could put it back on the clock we have not measured, so treat it as time won rather than a door closed. Changing the sign-in email afterwards does not help at all - a reset already in flight runs to its date, and we changed the address on six of the seven accounts this happened to and lost them a week later anyway. How the reset runs and how a decline works has the mechanics; the intake order that actually ends shared access exists in one place, preparing a bought account.
What Telegram's terms actually say
We checked the public texts - telegram.org/tos and the API terms - on 2 August 2026. Neither contains an explicit ban on buying or selling accounts. The rules that do exist are general: no spam or scam, and clause 1.4 of the API terms forbids acting on a user's behalf without their knowledge.
The claim that Telegram “explicitly forbids” account sales is repeated across dozens of articles, yet every chain we traced ends at SEO aggregators citing each other - we could not find a primary source. Telegram itself, meanwhile, auctions usernames on Fragment: the platform evidently distinguishes selling a name from selling an account.
None of this is protection. Telegram does not need a ToS clause to act, because enforcement is behavioural. A freshly bought account produces the exact pattern anti-takeover systems watch for - a new device, a new IP and immediate activity - which is also what a genuinely stolen account looks like on the day it is resold. That alone is enough for restrictions or a freeze, no rulebook required.
“Aging” is a market term, not a Telegram one
“Aging” - letting an account rest after registration before it works, otlyozhka in the Russian-speaking market that runs most of this trade - has no meaning inside Telegram. There is no agreed standard either: recommendations range from 24-48 hours to 1-3 months, and mostly come from people selling aged accounts or warming services. We treat every specific figure in that range as unverified, because it is.
What calendar age cannot buy is history. An account that sat in a tdata archive for three years arrives with an empty dialog list, no contacts and no behavioural track record - a three-year-old blank. Nobody outside Telegram knows the scoring weights, but observed enforcement tracks behaviour and consistency - same device, same IP and geo, human rhythm, gradual ramp - not the account's birthday. Building that record is what warming is for.
A data point from our own fleet: two day-zero accounts were frozen before any automation touched them at all. The decisive variable was the phone number's country and the network profile that comes with it - no amount of resting would have changed that.
Register your own instead
Our recommendation, and how we run our own fleet: register on numbers you obtain yourself and warm every account. The reasons, in order of weight:
- The downside is asymmetric. The worst case of a bought account is not “a dollar lost”. It is the original owner re-verifying the number at the worst possible moment and walking away with a warmed reputation and your customers' conversations inside.
- Buying does not skip the ramp. The one genuine advantage on offer - starting with trust already built - does not survive the handover: the account still meets a new device, a new proxy and a new behaviour pattern, and needs the same careful warm-up as a fresh registration.
- The price gap is smaller than it looks. Renting a number costs cents to a few dollars for most countries and up to about $9-10 for the priciest ones (checked August 2026; the verified per-country list is in the phone numbers guide); bought accounts run $0.37-17.58 - and both routes still pay for a proxy and weeks of warming. The premium buys risk, not time.
- Provenance compounds. A self-registered account has one owner, one live session and your security settings from day one - no copy of the key in somebody else's hands, no
originfield to wonder about.
| Question | Bought account | Self-registered account |
|---|---|---|
| Where it came from | Unknown unless the shop labels origin; stolen stock is documented inventory | Your own chain of custody from day one |
| Who else holds keys | The original owner can re-verify the number; the seller can keep a copy of the key | One owner, one live session |
| What age is worth | Calendar age over an empty history | History accumulates under your own routine |
| Cash cost (checked Aug 2026) | $0.37-17.58 apiece, plus proxy, plus warming anyway | Cents to a few dollars per number for most countries, up to about $9-10 for the priciest, plus proxy, plus warming |
| What can still go wrong | Owner reclaim, freeze on the takeover pattern, dead-on-arrival lots | Enforcement risk remains - reduced, never removed |
The one purchase we consider defensible: a small test batch for experiments, bought where origin is labelled explicitly and quarantined before it touches anything real. As a supply channel for a production fleet - no. If you are buying regardless, take the account over in the right order: preparing a bought account is the intake procedure, and skipping it is how a working account turns out to still belong to its seller.
How this maps onto the platform: Teleliner imports a tdata folder or a session string, de-duplicates by Telegram user id rather than phone number, stores sessions encrypted and runs exactly one live session per managed account. Warming - per-account daily plan, quiet hours in the account's own timezone, daily caps, a full action journal - is built into the platform, and the whole workflow assumes accounts you registered and intend to keep.
Frequently asked questions
Is buying a Telegram account against the terms of service?
As of a check on 2 August 2026, neither telegram.org/tos nor the API terms contains an explicit ban on buying or selling accounts; the widely quoted “explicit prohibition” traces back to SEO articles citing each other. In practice the absence of a rule changes little: a transferred account's first hours look like an account takeover, and Telegram enforces on behaviour, not on receipts.
Can the original owner really take a bought account back?
Yes. Telegram binds the account to the phone number, and whoever controls the number can pass SMS re-verification and recover it. For stolen stock - whose existence a major marketplace documents with its own origin labels - the original owner keeps that option forever, and uses it on their schedule, not yours. A login code on its own opens two doors, and neither asks for the cloud password: account deletion, which erases the account and frees the number, and a password reset, which waits seven days and then hands the account over whole.
How long should an account “rest” before it starts working?
There is no verified figure. “Aging” is a market term with no meaning inside Telegram; recommendations run from 24 hours to 3 months, and most come from people selling aged accounts or warming services. What observably matters is behaviour after activation: a consistent device, a consistent network and a gradual, human ramp.
Are aged accounts safer than fresh ones?
Age without history is a thin signal: an account that sat unused arrives with an empty dialog list and no behavioural track record. The premium pays for the market's belief in age, not for a measured survival rate - we found no data that isolates age from every other factor. The variable you actually control is consistent warming after activation.
What is the lowest-risk way to build a fleet, then?
Register accounts yourself on numbers you obtain, give each one a static proxy, and warm every account before it works. It is slower than buying and roughly comparable in cash cost, but the provenance is transparent and the account builds history under your control from day one. Risk goes down, not to zero - no sourcing method removes enforcement risk.