Messaging · Secret guide

Leaked Telegram Bot Token: what to do in the first hour

High severityChecked liveLast verified · 5 min read

A Telegram bot token is the only credential a bot has. Whoever holds it can do everything your bot can do: send messages as the bot to anyone who has talked to it, receive the messages people send to it, and use any admin rights the bot has in groups and channels. There is no password to guess and no second factor. Revoke the token in BotFather first, then check what was changed.

Check your GitHub account for leaked secrets — free

Provider
Telegram
Severity
High
Impact
SaaS account access and billing
Checked live by LeakWatch
Yes

What a Telegram bot token looks like

A token is two parts separated by a colon: the numeric ID of the bot, then a secret string that starts with A.

<bot_id>:A…XXXX   (masked)

The numeric part is not secret on its own, since it is the bot’s public ID. The part after the colon is what grants control. Do not confuse it with other Telegram values: a bot username (@something_bot) is public, and an API ID and API hash from my.telegram.org belong to a user account client (a different credential, for apps that log in as a person, not as a bot).

If your leaked token is for a different chat platform, use the Discord bot token or Slack API token guide.

How Telegram bot tokens get leaked

  • Inside a URL. The Bot API puts the token in the path (https://api.telegram.org/bot<token>/sendMessage), so a curl command in a README, a CI log, a crontab or a monitoring alert rule contains it in full.
  • Alerting scripts. Telegram is a popular target for server and backup notifications, and those small shell scripts get committed with the token inline.
  • Bot source code. A Python, Node or Go bot with the token hardcoded to get started, then pushed publicly.
  • Config files and Docker. docker-compose.yml, .env files and Helm values for a self-hosted bot.
  • Screenshots and support threads where a terminal, a webhook URL or a BotFather message with the token is visible.

What to do in the first hour

  1. Revoke the token in BotFather. Open a chat with @BotFather in Telegram, send /revoke, pick the bot, and BotFather issues a new token while the old one stops working immediately. (Do this from the Telegram account that owns the bot; BotFather only lets owners revoke.)
  2. Put the new token in the right place. Store it in an environment variable or secret manager, and restart your bot or script. If you have several scripts that share one bot, update each of them; the bot will look broken until you do.
  3. Check and reset the webhook. The webhook is stored on the bot, not on the token, so it survives revocation. An attacker could have pointed it at their own server to receive every message sent to your bot. Call getWebhookInfo with your new token, compare the URL with yours, and call setWebhook again or deleteWebhook if it is wrong.
  4. Look for signs the token was in use. A bot that polls with getUpdates while someone else polls too gets “409 Conflict” errors. Unexpected messages sent from the bot to your users are another sign. Review the bot’s logs from the period since the exposure.
  5. Check the bot’s own settings. In BotFather, review the bot’s name, description, profile picture, commands and menu button; anything the token can change through the API can be changed by an attacker. Check Domain and any linked web apps too.
  6. Review groups and channels where the bot is an admin. Open each one’s admin settings and read Recent actions. Look for members removed, links changed, messages deleted or pinned, and new admins added. If the bot had admin rights, remove them until you have finished checking.
  7. Tell your users if the bot handled personal data. If your bot received private messages or collected data, think about whether you have a duty to inform the people affected; a qualified adviser can help you decide.
  8. Then clean the repository: remove the value and rewrite history if you want to. See I accidentally pushed an API key to GitHub.

Not sure what else leaked from the same repository? Run a free scan.

Not sure what else leaked? Run a free scan.

Revoke it at Telegram (BotFather)

There is no web console: revocation happens in Telegram itself. Message @BotFather, send /revoke and choose the bot. BotFather replies with the new token, and the old one is dead from that moment. You can fetch the current token later with /token. If you have lost access to the account that created the bot, you cannot revoke it yourself; contact Telegram support through the official channels.

How LeakWatch detects it

LeakWatch looks for a token-shaped value (a numeric bot ID, a colon, then a string starting with A) written next to a Telegram-related name, so a bare token with no context is not reported. This type is checked live: LeakWatch can confirm whether a detected token is still active with a read-only getMe request, which returns only the bot’s public identity. It does not send any message, does not read any updates and does not change any setting.

LeakWatch can check whether a detected key is still active with a read-only request to Telegram. It never reads your data or spends your credits.

FAQ

Can someone read my bot's past messages with the token?

Not the history. The Bot API gives access to new updates, delivered once. But an attacker who sets a webhook or polls getUpdates receives every new message from that point on, which is why the webhook check in step 3 matters.

I regenerated the token, but my bot is still behaving oddly.

Check the webhook and the bot settings (steps 3 and 5). Revoking the token does not undo changes already made through the API, and it does not remove a webhook that was set to another address.

Is a leaked bot token as serious as a leaked API key?

It depends on what the bot does. A bot that only posts alerts is a lower risk than one that handles user messages, payments or has admin rights in a large group. In all cases, revoking takes seconds, so do it.

Get alerted next time a secret leaks — create a free account

LeakWatch is not affiliated with Telegram.