Owners of anonymous +888 numbers are reporting thousands of Telegram login requests, and according to Telegram channels, some accounts have already been hijacked. The attack coincided with Pavel Durov's 42nd birthday on October 10. According to the source, attackers try to guess login codes and, when they succeed, reset the cloud password, delete the account and grab its username. Here's what we know, why +888 numbers are the target and what to do right now.
Quick summary
- What: a flood of Telegram login code requests for accounts tied to +888 numbers.
- Who's affected: owners of anonymous numbers bought on the Fragment platform.
- The risk: account takeover, deleted chats and a lost username, along with any channels and bots the account solely owns.
- What to do: turn on a cloud password, review active sessions and, as the source advises, disable login code delivery on Fragment.
Telegram and Fragment had not commented at the time of publication. The source claims a similar attack hit Durov himself last year and that the problem was never fixed. The scale of the attack hasn't been independently confirmed either; we'll update this story if Telegram shares details.
Why +888 numbers are the target
+888 numbers are Telegram virtual numbers with no SIM card. They're bought on Fragment with TON, and the number itself is held as an NFT in the owner's TON wallet. Login codes for these numbers don't arrive by SMS but on Fragment itself, as Telegram explains. If you're already signed in on another device, the code goes there.
Two things make these accounts an attractive target:
- Valuable usernames. +888 accounts often hold short, memorable usernames that sell for serious money on Fragment.
- Work accounts. Media buyers, channel admins and teams who don't want to expose a personal SIM like anonymous numbers. These accounts often control channels, bots and Telegram Ads accounts.
How the attack works
According to the source, the scheme goes like this:
- Attackers trigger mass logins for +888 numbers, so owners get flooded with code notifications.
- They use device farms to try to guess the login code.
- If the code is guessed and there's no cloud password, they sign in, strip the protection, delete the account and register the freed-up username for themselves.
The key point: a flood of codes on its own doesn't mean your account is compromised. As long as you haven't shared a code and you have a cloud password set, an attacker can't get in.
How to protect your +888 number and account: 6 steps

- Turn on a cloud password. Settings → Privacy and Security → Two-Step Verification. Be sure to add a recovery email that only you can access.
- Review active sessions. Settings → Devices: terminate every session you don't recognize.
- Disable login codes on Fragment. The source advises turning off code delivery in your number's settings on Fragment (My Assets) when you aren't signing in on a new device. You can turn it back on at any time.
- Secure your TON wallet. The number is an NFT: whoever controls the wallet controls the number. Keep your seed phrase offline and don't connect the wallet to dubious sites or "airdrops".
- Never share codes. Telegram never asks for a login code in a chat, by phone or through "support".
- Back up your channels and bots. Add a second full-rights admin on a different account to your important channels and keep your bot tokens safe. If the main account disappears, you won't lose everything at once.
What it means for media buyers and channel admins
For teams running traffic in Telegram, a +888 account often means access to channels, bots and the Telegram Ads account. Losing it isn't just an inconvenience: it stops your campaigns and may cost you an audience built over months. If you're growing a channel or monetizing one, check your security today: a cloud password, a second admin and a backup of key data take ten minutes.
This is the second serious Telegram security story in a week: we recently covered the Telegram Desktop vulnerability that steals files and sessions through a single link. Update to the latest version if you haven't yet.
Frequently asked questions
I'm getting login codes I didn't request. Is my account hacked?
No, it only means someone is trying to sign in with your number. Don't share the code, turn on a cloud password and check your list of active devices.
Will a cloud password help if the code gets guessed?
Yes. With a cloud password, signing in requires both the code and the password, so the code alone isn't enough for an attacker.
Can I get my username back after the account is deleted?
If someone else has already claimed it, getting it back is hard. That's why you should secure the account in advance and keep a second admin on your channels.



