Preparing a bought Telegram account
An account you did not register arrives with a history you did not write and, often, sessions you cannot see. This is the order of operations that turns it into yours - and the signals that say it never will be.
Updated: August 2026 · 7 min read
Most accounts are lost in the first hour, not the first month. A purchased account changes hands with the previous holder still knowing everything needed to take it back, and the usual reaction - log in, look around, start working - burns the two advantages you have: the ability to audit before anything moves, and the ability to walk away before you have invested in it.
What follows is an order of operations. It is worth reading before you buy rather than after, because two of the steps depend on things you must have ready in advance.
What you are actually buying
A Telegram account is not a username and password. It is a set of authorizations - long-lived keys, one per device that has ever signed in - attached to a phone number that a carrier still controls. Buying the account means buying one of those keys. It does not mean the others stopped working, and it does not mean the number is yours.
- Sessions you cannot see yet. Every device the seller used holds its own key. Nothing about the sale revokes them.
- A cloud password that may already exist, set by someone else, with a recovery address pointing at their mailbox.
- The number's real owner, who is whoever can receive its SMS - which may be the seller, an SMS-rental service, or the person the account was taken from.
- A history: chats, groups, whatever the account did before you, and whatever complaints that behaviour attracted.
- A device identity baked into the key, which is why the delivery format matters - see tdata and session formats.
The job of intake is to reduce that list to: one key, held by you; one password, set by you; one recovery address, in your mailbox. Anything left over is someone else's claim on the account.
Have the proxy ready before the first login
This is the step people do last and should do first. The very first connection an account makes under your control sets the network pattern for everything after it, and connecting once from your office IP or a random VPN is not undone by fixing it later.
- Buy a static dedicated proxy in the country of the account's phone number before the account arrives. Not a rotating pool, not your own connection - see which proxies to buy.
- Verify the exit: confirm the country and check the address against a reputation service while a refund is still possible.
- Only then attach the proxy to the account, and let the first connection go through it.
The first session: import, do not explore
Import the account through the platform rather than signing in manually somewhere first. A tdata archive carries the device identity the account was built with, and importing it preserves that key instead of minting a new one; a fresh sign-in from an unfamiliar client announces a new device on an account that has just changed hands, which is precisely the pattern that draws attention.
Then leave it alone. The temptation is to read the chats, check the username, join something. Every one of those actions is an action on an account whose ownership you have not yet secured - and if the previous holder is still watching, you have just told them the account is live and worth taking back.
Keep one driver. Two tools operating the same key at once produce the duplicate-key error and can invalidate the authorization outright - the reasoning is under one key, one driver.
Terminate every session you did not create
This is the step that decides ownership, and the one most often skipped because the account appears to work without it. It does work - for the seller too.
Open the account's active sessions and terminate everything except the one you just created. Do not try to guess which entries are harmless: a session you cannot account for is by definition not yours. If the list is long or the device names are unfamiliar, that tells you something about how the account was kept.
Take the password and the recovery address
A cloud password is what stands between a stolen SMS code and a lost account, so it has to be yours rather than merely changed. The distinction is not cosmetic: changing an existing password leaves the previous owner's recovery email attached, which leaves them a path back in. Remove the password entirely, then set a new one from scratch, then attach your own recovery address by hand.
The mechanics, the quarantines Telegram imposes afterwards, why automation cannot attach the email for you, and what a sign-in stalling at the password prompt means are all covered by the guide that owns this subject: the cloud password.
Quarantine: the part that feels like doing nothing
With the key exclusive and the password yours, the account still should not go to work. Give it a quiet period in which it exists, connects through its proxy and does nothing else. Two things are being tested. First, whether anyone tries to take it back: a reclaim attempt usually happens early, and you would much rather see it on an idle account than on one carrying live conversations. Second, whether the account is under a restriction the seller did not mention and you have not yet triggered.
How long is a judgement call and the market's advice on “aging” is folklore rather than method - the honest treatment is under aging is a market term. What is not a judgement call is the sequence: quarantine after taking ownership, never before, because a quiet account you do not yet control is just an account someone else can still reach.
- Watch for sessions reappearing - a session you did not create showing up again means the number is still delivering codes to someone else.
- Watch for a freeze or restriction landing without you doing anything, which points at history you inherited rather than behaviour you caused.
- Do not add the account to campaigns, do not send the first message, do not join anything on a schedule.
Hand it to warming, not to production
After quarantine the account still is not a working account. It is an account with an unknown behavioural baseline, a new network and a new operator, which from Telegram's point of view is close to a fresh registration regardless of its age. Treat the first weeks as warming, let the caps and windows apply, and read the action journal rather than assuming silence means health.
This is also where the economics of buying quietly collapse. The premium on an aged account is sold as skipping the ramp, but the ramp still has to happen: new device, new proxy, new behaviour. What you actually bought was the registration date, not a shortcut.
When to write the account off
Some accounts should be abandoned rather than rescued, and the cheapest moment to decide that is before you have invested weeks of warming and a live conversation history. Any of the following is enough on its own:
- Sessions you terminated come back. Someone else can still authorize, which means they can still receive codes. Nothing you do inside the account fixes that.
- A sign-in reaches the password prompt and stops. The code was obtained and used by someone who is not you; the password is all that held.
- The seller can still reach the recovery email and will not or cannot detach it.
- The account arrives frozen or restricted, or becomes so during quarantine without any action from you - see frozen, banned, restricted.
- The number's country has no matching proxy you can actually buy.
Writing off a cheap account early is a smaller loss than discovering the same facts later with a warmed reputation and your customers' conversations inside it. That asymmetry - low price, high consequence - is the whole argument for registering your own instead.
Frequently asked questions
Can I skip the quarantine if the seller gave a guarantee?
A guarantee covers the seller's obligation to replace a dud, usually within a couple of days. It does not cover the failure this procedure is designed for - the account working perfectly while someone else retains the ability to take it back. Those are different risks, and only one of them is refundable.
The account already has a cloud password. Should I just change it?
No. Changing a password keeps the recovery email attached, and if that mailbox belongs to the seller they keep a route back in. Remove the password entirely, set a new one from scratch, then attach your own recovery address. The mechanics and the quarantines that follow are in the cloud password guide.
Do I need a separate proxy for every bought account?
Yes, on the same rule as any other account: one static IP per account, in the country of its number. Accounts sharing an exit are trivially linkable, and a bought account is exactly the kind you do not want linked to the rest of your fleet if its history turns out to be bad.
Is buying accounts against Telegram's terms?
There is no clause that names buying or selling accounts, which we checked directly rather than repeating. That absence is not protection: the normal behaviour of a freshly purchased account - new device, new network, immediate activity - runs into ordinary anti-abuse regardless. The detail is under what the terms actually say.
How do I know whether an account was stolen?
Usually you cannot, which is the core problem. One large marketplace documents an origin field on each listing whose values include phishing and stealer alongside self-registration, and offers a filter to exclude them - that is the industry describing its own supply. Use the filter where it exists, and treat provenance as unknown where it does not.
Does Teleliner do any of this automatically?
Partly. Import preserves the account's existing key rather than minting a new one, the proxy is bound to the account and verified before it starts, and the platform will set a cloud password and surface a sign-in stalled at the password prompt. Terminating unknown sessions and attaching a recovery email are deliberately manual - Telegram requires a confirmation code for the email, and evicting sessions is a decision, not a default.