Received a 4 a.m. call? Your Telegram may be hacked 5 minutes later
The phone rang 10 times. Then they hijacked his Telegram account.

Image by Primakov via Shutterstock
- Attackers allegedly kept the victim's phone line busy so Telegram's login call went to voicemail.
- The intruder accessed the voicemail code and entered the account within about five minutes.
- The attacker searched chats and wallet bots, but the victim says no crypto was lost.
- Experts advise disabling voicemail or carrier call features and using app-based or hardware-key authentication.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
You don’t need to click a shady link to get hacked. Sometimes, all an attacker needs is your phone, your voicemail, and 5 minutes while you’re asleep.
At 3:54 in the morning, an ordinary phone call became the first clue that something was badly wrong.
A Telegram user says an attacker gained access to their account without a malicious link, stolen password, or suspicious app. Instead, the attacker allegedly exploited a simple voicemail.
The incident was recently described in a post on X. The user, who says they have been building in crypto for more than a decade, described the experience in detail, surprised that such an overlooked feature as voicemail could be an entry point for hackers.
According to the account, the first sign was a series of calls in the middle of the night.
Voicemail was exploited to read the verification code
“At 3:54 a.m. My phone rings about ten times in a row, No Caller ID,” the user wrote. “That was not harassment. It was the attack: keep my line busy.”
While the calls were coming in, the attacker was allegedly attempting to log into Telegram using the victim's phone number and requesting a verification code through an automated phone call.
With the victim's line occupied, the verification call was allegedly diverted to voicemail, where the automated system read the code aloud. The attacker then accessed the voicemail remotely and retrieved the code. “At 3:59, he is in,” the user wrote.
In this case, the attacker's timing worked against them. The barrage of calls woke the victim, who checked their phone rather than going back to sleep.
“Fortunately, the attack was noisy. The calls woke me up. At 4 a.m. I only wanted to go back to sleep, but I had the presence of mind to check my notifications,” the user recalled.
“Telegram was showing a new login from a device I didn't know. That check is what saved me.”
Attackers were searching for crypto and reading messages
According to the victim, the intruder searched through old Telegram conversations and interacted with wallet bots, apparently looking for cryptocurrency.
“In those few minutes, he had already typed /balance, then /start on every old wallet bot he could find in my chats,” the user wrote.
The bots were no longer active and, according to the victim, no funds were lost.
However, the damage could have been huge. The attacker had enough access to set their own 2-factor authentication password on the account, according to the post.
“I got lucky to handle it quickly – he was in for about 5 minutes,” the user wrote in a follow-up.
“I don't hold anything valuable on Telegram. But the big mess would have been all the scams he would have sent to my contacts, and I am an admin of multiple groups – people trust me, so he might have caused a lot of harm.”
“When I called my operator, he said a lot of people are disabling voicemail these days… probably for this reason,” the user said.
Other users say they’ve seen similar attacks
The X post quickly attracted responses from people describing similar experiences.
One user claimed, “My WhatsApp was taken over this same way. I also have reason to believe this is being exploited fully autonomously.”
Another said they had encountered a similar attempt, but that 2-factor authentication prevented the attacker from taking control.
“Happened to me as well. They didn't get in cause 2FA.”
A third user described a Telegram compromise and said they subsequently locked their SIM card.
“Sadly, this is so common with Telegram. The same happened to me. I locked my SIM card afterward.”
Check what your carrier has enabled
The attack scenario shows an odd security blind spot. The account might be protected by a sophisticated service, while the phone number used to recover or authenticate it sits behind a decades-old carrier feature the owner has never checked.
“The attack abuses lesser-known mobile carrier features likely intended for accessibility. It is important to check with your carrier if such features are enabled.
To stay safe, the researchers recommend contacting the mobile provider to ask which features are enabled and to request that they be disabled.“
Also disable authentication features that rely on mobile networks, such as authentication via calls, SMS messages, and enable stronger MFA features such as authenticator app-based One Time Codes, physical keys,” said the researchers.
We’ve reached out to Telegram for comment and will update this article once we receive a response.