Telegram Phishing Scams: Fake Support, Airdrops, QR Codes and Login Theft (2026)

Telegram risk is not only random links from strangers. Better scams borrow trust you already have: admin notices, airdrops, friend votes, exchange support, wallet checks, unban flows. They often need one confirmation from you—not malware.

Fake support and phishing usually trick you into authorizing a login, leaking codes, scanning someone else’s QR, or handing over seed phrases. Treat DMs or external pages that ask you to “verify,” “scan to unban,” “claim an airdrop,” or “enter your cloud password” as phishing first. After a mistake, terminate unknown sessions before you panic-reinstall.

Common plays, red flags, and quick tells

PlayPitchReal risk
Fake supportAccount issue, security checkCodes, cloud password, session grant
Fake airdropTime-limited tokens / NFTsWallet approvals, seeds
Vote / boostHelp a friend, unlock rewardsFake Telegram login pages
QR “verification”Prove you are human / lift limitsLogging into the attacker’s device
Fake bot / fake appWallet KYC, “Chinese turbo” buildData theft or stolen sessions

Red flags: cold DMs claiming support; asks for SMS/cloud/recovery codes; scanning an external QR via Link Desktop Device; seed phrases or “approve all assets”; lookalike domains; countdown pressure. Official QR login only belongs on a Desktop/Web window you opened—see QR safety.

AskNormalDangerous
Enter a login codeYou are signing into your own new deviceSomeone else’s “security check” link
Scan a QRYour own Desktop/WebSupport / airdrop / review pages
Connect a walletYou opened a verified project siteA bot rushing a limited claim
Enter cloud passwordInside the official appAn external webpage

Five-minute damage control—and what two-step actually blocks

Stop typing; Settings → Devices → end unknown sessions; change the two-step password and check recovery email; review outbound spam; if limited, use the SpamBot appeal. Keep the current session long enough to finish cleanup—reinstalling yourself can hand the attacker more time.

Two-step does not stop every click, but it raises the cost of SMS-only takeovers. Setup: two-step guide. Already compromised: recovery SOP.

Crypto users and lasting habits

Bots or pages that want seeds, private keys, or exchange codes are not trustworthy. “Free airdrops” that require approving a strange DApp or sending a fee first deserve a hard pause against the official channel. Telegram does not vouch for wallet safety.

HabitBlocks
Official clients only (download page)Modded session theft
Two-step + recovery emailSMS-only takeover
Passkeys / regular Devices checksSilent stranger sessions
Hide phone numberSocial-engineering entry
No seeds/exchange codes in DMsFake support / wallet bots

One usable rule: do not complete “verification flows” other people send you; only follow logins you start yourself from the official app or site. Copy domains into a browser instead of tapping chat links blind.

How to react—and when to stop

RequestDoDo not
DM asks for codes / cloud passwordRefuse and reportSend them to “support”
Scan to unban / claimOnly scan your own official login QRScan their image
A friend urges a timed linkConfirm offline + check DevicesTap immediately
Already opened an external pageKick sessions + change two-stepAssume nothing happened

FAQ

What is the most common Telegram phishing scam?

The most common pattern is impersonation: fake support, project founders, exchange staff, wallet support or group admins claim that your account, wallet, group access or airdrop status needs verification. They then push a link, QR code, login code request, two-step password prompt or seed-phrase request. Real support will not ask for those secrets.

How can a Telegram phishing link steal my account?

Most attacks do not break Telegram encryption. They trick you into authorizing a real login session: entering your phone number and code, scanning a QR login code, or tapping a confirmation inside the Telegram app. Once approved, the attacker’s device becomes an active session that can read cloud chats, contacts and groups.

What should I do after clicking a suspicious Telegram link?

Stop entering information. Open Telegram → Settings → Devices and terminate every unknown session. Then change your two-step verification password, review phone-number privacy, check recent outgoing messages, and ask @SpamBot about restrictions if the account sent spam.

I only opened the link and never entered a code — am I still at risk?

Still check Devices. Some pages push you to tap “Yes, it’s me / Confirm login” inside the official app — that step authorizes the session. If you only viewed a page and never signed in, scanned, or confirmed, risk is lower, but verify there are no unknown sessions and stop opening chat links without checking the domain first.

How do I tell fake support from a real admin quickly?

Official Telegram support will not DM you for codes or cloud passwords. If a “group admin” suddenly DMs “scan to unban / verify identity”, check the username against the real group profile and look for pinned official notices. Treat countdown threats, ban warnings and limited-time airdrops as phishing until proven otherwise.

A friend DMs me to “vote / claim an airdrop” — how do I judge it?

Confirm identity on another channel (call / second account) and open Settings → Devices for unknown sessions. Hijacked friends are common: don’t open unknown links or scan login codes they send; tell them to check Devices if needed.

I opened a suspicious link but didn’t enter a code — still act?

Yes. Check Devices and terminate unknowns, change the two-step password, and never enter codes on external pages. Even if “nothing happened,” run the post-click containment steps once.

Fake support sent an “official ticket number / screenshot” — how to judge?

Telegram won’t unlock you via a private-chat ticket screenshot. Real appeals go through @SpamBot or official email — not forged ticket IDs. Any external “complete your ticket” link is phishing.

A group admin suddenly @mentions me to “verify identity” — is it always phishing?

High odds it’s suspicious. Confirm the admin over a trusted side channel first, and check whether the admin account is brand-new or unverified. Stop before entering a login code or cloud password on any external page.

Need the installer or platform notes?

The download page lists versions, requirements, and install entry points.

Open download page

← Back to blog