# Leaked Telegram Bot Token? Revoke It in BotFather

> Telegram bot token exposed? Revoke it with BotFather, reset the webhook, check bot settings and group admin logs. Step-by-step guide.

Source: https://leakwatch.net/secrets/telegram-bot-token

---

[LeakWatch](/)

[Product](/product)[Live feed](/leaks)[Guides](/secrets)[Blog](/blog)[Free scan](/)

1.  [Home](/)
2.  [Secrets](/secrets)
3.  Telegram Bot Token

Messaging · Secret guide

# Leaked Telegram Bot Token: what to do in the first hour

High severityChecked liveLast verified October 2, 2026 · 5 min read

A Telegram bot token is the only credential a bot has. Whoever holds it can do everything your bot can do: send messages as the bot to anyone who has talked to it, receive the messages people send to it, and use any admin rights the bot has in groups and channels. There is no password to guess and no second factor. Revoke the token in BotFather first, then check what was changed.

[Check your GitHub account for leaked secrets — free](/)

Provider

Telegram

Severity

High

Impact

SaaS account access and billing

Checked live by LeakWatch

Yes

## What a Telegram bot token looks like

A token is two parts separated by a colon: the numeric ID of the bot, then a secret string that starts with `A`.

```text
<bot_id>:A…XXXX   (masked)
```

The numeric part is not secret on its own, since it is the bot’s public ID. The part after the colon is what grants control. Do not confuse it with other Telegram values: a **bot username** (`@something_bot`) is public, and an **API ID and API hash** from [my.telegram.org](http://my.telegram.org) belong to a user account client (a different credential, for apps that log in as a person, not as a bot).

If your leaked token is for a different chat platform, use the [Discord bot token](/secrets/discord-bot-token) or [Slack API token](/secrets/slack-api-token) guide.

## How Telegram bot tokens get leaked

-   **Inside a URL.** The Bot API puts the token in the path (`https://api.telegram.org/bot<token>/sendMessage`), so a `curl` command in a README, a CI log, a crontab or a monitoring alert rule contains it in full.
-   **Alerting scripts.** Telegram is a popular target for server and backup notifications, and those small shell scripts get committed with the token inline.
-   **Bot source code.** A Python, Node or Go bot with the token hardcoded to get started, then pushed publicly.
-   **Config files and Docker.** `docker-compose.yml`, `.env` files and Helm values for a self-hosted bot.
-   **Screenshots and support threads** where a terminal, a webhook URL or a BotFather message with the token is visible.

## What to do in the first hour

1.  **Revoke the token in BotFather.** Open a chat with `@BotFather` in Telegram, send `/revoke`, pick the bot, and BotFather issues a new token while the old one stops working immediately. (Do this from the Telegram account that owns the bot; BotFather only lets owners revoke.)
2.  **Put the new token in the right place.** Store it in an environment variable or secret manager, and restart your bot or script. If you have several scripts that share one bot, update each of them; the bot will look broken until you do.
3.  **Check and reset the webhook.** The webhook is stored on the bot, not on the token, so it survives revocation. An attacker could have pointed it at their own server to receive every message sent to your bot. Call `getWebhookInfo` with your new token, compare the URL with yours, and call `setWebhook` again or `deleteWebhook` if it is wrong.
4.  **Look for signs the token was in use.** A bot that polls with `getUpdates` while someone else polls too gets “409 Conflict” errors. Unexpected messages sent from the bot to your users are another sign. Review the bot’s logs from the period since the exposure.
5.  **Check the bot’s own settings.** In BotFather, review the bot’s name, description, profile picture, commands and menu button; anything the token can change through the API can be changed by an attacker. Check *Domain* and any linked web apps too.
6.  **Review groups and channels where the bot is an admin.** Open each one’s admin settings and read *Recent actions*. Look for members removed, links changed, messages deleted or pinned, and new admins added. If the bot had admin rights, remove them until you have finished checking.
7.  **Tell your users if the bot handled personal data.** If your bot received private messages or collected data, think about whether you have a duty to inform the people affected; a qualified adviser can help you decide.
8.  **Then clean the repository**: remove the value and rewrite history if you want to. See [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github).

Not sure what else leaked from the same repository? [Run a free scan](/).

[Not sure what else leaked? Run a free scan.](/)

## Revoke it at Telegram (BotFather)

There is no web console: revocation happens in Telegram itself. Message `@BotFather`, send `/revoke` and choose the bot. BotFather replies with the new token, and the old one is dead from that moment. You can fetch the current token later with `/token`. If you have lost access to the account that created the bot, you cannot revoke it yourself; contact Telegram support through the official channels.

## How LeakWatch detects it

LeakWatch looks for a token-shaped value (a numeric bot ID, a colon, then a string starting with `A`) written next to a Telegram-related name, so a bare token with no context is not reported. **This type is checked live**: LeakWatch can confirm whether a detected token is still active with a read-only `getMe` request, which returns only the bot’s public identity. It does not send any message, does not read any updates and does not change any setting.

LeakWatch can check whether a detected key is still active with a read-only request to Telegram. It never reads your data or spends your credits.

## FAQ

Can someone read my bot's past messages with the token?

Not the history. The Bot API gives access to new updates, delivered once. But an attacker who sets a webhook or polls `getUpdates` receives every new message from that point on, which is why the webhook check in step 3 matters.

I regenerated the token, but my bot is still behaving oddly.

Check the webhook and the bot settings (steps 3 and 5). Revoking the token does not undo changes already made through the API, and it does not remove a webhook that was set to another address.

Is a leaked bot token as serious as a leaked API key?

It depends on what the bot does. A bot that only posts alerts is a lower risk than one that handles user messages, payments or has admin rights in a large group. In all cases, revoking takes seconds, so do it.

## Related

-   [Discord Bot Token](/secrets/discord-bot-token)
-   [Mailgun API Key](/secrets/mailgun-api-key)
-   [SendGrid API Key](/secrets/sendgrid-api-key)
-   [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github)
-   [Which vendors leak most this week](/leaks/trends)
-   [All secret guides](/secrets)

[Get alerted next time a secret leaks — create a free account](/)

LeakWatch is not affiliated with Telegram.

![Gabriel Diyan, founder of LeakWatch](/brand/Photo-Gabriel-Diyan.webp)

Gabriel Diyan (0xCr0c0)

Cybersecurity student, founder of LeakWatch. I built and run the scanner described here — the detection patterns, the false-positive classifier and the provider validators are mine. [More about who I am](/about).

[GitHub](https://github.com/Leakwatch-Scan) · [X](https://x.com/LeakwatchScan) · [LinkedIn](https://www.linkedin.com/in/gabriel-diyan-80a378375) · [GitHub (personal)](https://github.com/crocogab)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Secret guides](/secrets)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
