← back to blog

How to hand over a Telegram channel without losing it

telegram channel-ownership handover account-safety

How to hand over a Telegram channel without losing it

Someone asked me to look at their channel recently because a scheduled post had stopped going out. Before I looked at the scheduler I asked them a different question: open the channel and tell me whether you can see the option to delete it.

They could not. They had been running that channel as their own for fourteen months, and it still belonged to the person who set it up for them.

That is the whole failure mode. Somebody promotes somebody else to administrator, ticks every switch on the rights screen, and both people walk away believing ownership changed hands. The rights screen and the transfer button sit in the same menu, and only one of them asks for a password.

There is exactly one owner and no switch for it

A Telegram channel or group has one owner. Telegram calls that account the creator, and the slot holds a single account with no way to make it hold two.

The owner is the only account that can delete the channel, hand ownership to somebody else, and demote an administrator they did not personally promote. Everyone else, no matter how many switches are green, is an administrator.

Go through the administrator rights screen and you will find switches for posting, for editing and deleting other people’s messages, for changing the name and description, and for adding further administrators. There is no switch for deleting the channel and no switch for becoming the owner. Telegram left both off the screen on purpose, and that omission is the entire security model.

Full rights are still a lot of rope

I do not want to make administrator rights sound harmless, because they can do real damage.

An administrator with delete permission can empty years of archive in an afternoon. One with change info permission can rename the channel and rewrite the description so it points wherever they want. One with posting permission speaks to every subscriber you have as the channel itself, and no subscriber can tell which human pressed send. The recent actions log will show you who did what afterwards. It will not put any of it back.

What an administrator cannot do is end the channel, move it to a third account, or remove you from it. Those three stay with the owner, which is exactly the difference people discover from the wrong side.

Four things Telegram checks before it lets go

Telegram will not run the transfer until all of these are true.

Your account has a two factor password, and that password is at least seven days old. Set one this morning and the transfer fails with a message telling you how much longer you have to wait.

The session you are transferring from is at least 24 hours old. A login that happened an hour ago cannot move a channel.

The receiving account is already a member of the channel or group, is not a bot, and is not a deleted account.

The receiving account has room. There is a ceiling on how many channels and groups one account can own, and somebody who has been accumulating them for years can be sitting at it without knowing.

Then you confirm with your two factor password. That password prompt is the only reliable signal that a real transfer is happening. If nobody typed a password, nothing moved.

The delays are the security, not bureaucracy

Those two waiting periods are the best part of the design, and they make more sense once you picture the attack they were built for.

Somebody gets hold of a login code, signs in on their own device, and starts moving anything valuable out before you notice. The 24 hour session rule stops that within the first day. The seven day rule means that even if the attacker sets their own password after taking over, they still have to wait a week before they can move a channel.

A week is a very long time to hold a stolen account quietly. You check your active sessions, spot a login you do not recognise, terminate it, and the channel never went anywhere.

So: turn on your two factor password at least a week before you hand anything over. I have watched a handover call get rescheduled across three time zones because someone enabled the password that same morning.

The channel that outlives its owner

Now the scenario that actually destroys communities, which has nothing to do with a handover.

The owner’s account stops existing. The phone number lapses and the carrier recycles it. The account goes untouched past its self destruct window, which defaults to six months. A phone gets lost with no second session logged in anywhere and no memory of the two factor password. Or the person deletes the account deliberately, having forgotten what was attached to it.

The channel survives. Administrators keep posting, subscribers see nothing unusual, and the thing looks completely healthy from the outside.

But the owner slot is empty and nothing can refill it. No transfer, no deletion, no promotion to owner, no appeal that I have ever seen work. I am not going to claim recovery is impossible, only that I have never seen it happen and would not plan around it.

This is why I keep pushing the same unglamorous point at people whose channel is worth real money: the channel is the durable part. The account underneath it is what breaks, and the phone number underneath that account usually breaks first.

Doing the handover in an order that survives

Treat a real handover like a deployment rather than a favour.

A week out, clear the prerequisites. Two factor password on and dated. Receiving account created, logged in, and joined to the channel. A quick check that they are nowhere near their channel limit. Agree in writing who stays on as an administrator afterwards, because handovers get emotional a few months later and a message written before anyone was annoyed settles the argument.

Pick a window where both people are awake, on a call, and doing nothing else. Not late on a Friday.

Run the transfer with the other person watching their own screen. Then verify from their side, which is the step everybody skips. The new owner opens the channel on their own device and looks for two things they could not see yesterday: the option to delete the channel, and the option to transfer ownership. Both visible means it is done. Ask for a screenshot.

Only then do you take your own rights down. A transfer leaves the previous owner in place as an administrator with everything still switched on, so nothing looks different until you change it yourself. Stay on as an administrator for a couple of weeks rather than leaving the same afternoon, because if something needs undoing you want to still be in the room.

The discussion group I forgot about

A channel with comments has a linked discussion group sitting behind it. That group is a separate chat with its own owner, its own admin list, and its own transfer flow. Moving the channel does nothing to it.

I got this wrong about two years ago. Transferred a channel cleanly, verified it from the other side, then stepped down as administrator the same hour because I like a clean exit. The group was still mine and I never thought about it, because in the client it looks like part of the channel.

Months later I was clearing out old chats, saw a group I had no business being in, and left it. The last owner leaving a group with nobody behind them is not a quiet event. Comments broke, and the new owner of the channel had no rights in that group at all, so there was nothing they could do. We rebuilt it with a new group, relinked, and every comment thread on every old post was gone permanently. That one was mine.

Bot tokens do not travel

A bot does not belong to the channel it posts in. It belongs to whichever account created it in BotFather, and its token is a string of characters sitting wherever the automation runs.

After a handover the new owner can remove the bot from the channel and that is the extent of their control. The old owner still holds the token and can still point that bot at anything. Either transfer the bot through BotFather, which requires the receiving account to have its own two factor password enabled, or revoke the token and issue a fresh one. Revoking is clean and it is also an outage, because every script and scheduler running on that token stops in the same second. Find out what is using it first.

The last hour of housekeeping

The public username travels with the channel, so old bookmarks and old links keep landing in the right place. Invite links behave differently. They are generated per administrator, and the ones the departing team created keep working until somebody revokes them, so the new owner should clear out the old links and generate their own. A link printed on packaging is a door nobody remembers leaving open.

Two factor password on the new owner’s account, straight away, if it was not already on. Then pick a backup administrator. A full rights administrator cannot inherit ownership when the owner’s account dies. What they give you is continuity while you deal with the account problem underneath.

Which leaves the part that actually matters over a five year horizon. Keep the owning account alive. Keep the number paid and active. Keep a session connected somewhere so the inactivity timer never runs down.

Where hosting fits

That last paragraph is the whole of our job. Telegramvault is managed Telegram hosting on dedicated hardware in Singapore, real handsets on real carrier SIMs, so the account that owns your channel stays online and its number stays on a paid, active line. It will not undo a transfer you did wrong. It removes the one failure that leaves a channel ownerless. If that is worth outsourcing, start here and use code TGYT.

This advice is for handing over a channel you built to a person you actually know: a founder stepping away, an agency returning a client’s own property, a partner buyout. Account trading is a different world and we do not go near it.

Get new guides and videos first — join the Telegram channel.

need infra for this today?