Preparation
Account Protection
A bought account still shares its login with the seller. Follow this sequence over three days to get a login of your own, log the seller out, keep a backup and set a password.
01Why protect a bought account
A bought account arrives already logged in, on the seller's login key. Importing it gives you that key, but the seller still has it too. With it they can log every other session out, including yours, and sell the account again.
The sequence below gives the account a login of your own, logs the seller's copy out, makes a backup login and sets a cloud password.
02The sequence
Import the account with its own proxy. Wait 24 hours and change nothing.
Terminate other sessions. Logs out every other device, including extra sessions the seller opened. The imported session itself stays.
Reauthenticate. Creates a brand-new session of your own and switches ATREOX to it. The key you bought is no longer used.
Wait 24 hours. Telegram does not let a session younger than 24 hours log others out.
Terminate other sessions again. Now it runs from your own session, so it also logs out the imported key — including every copy the seller kept. This is the step that makes the account yours.
Download new tdata. Creates a separate backup login and downloads it as a zip. It comes after the second Terminate because that step would have logged the backup out too.
Set 2FA. Adds a cloud password, so a code sent to the phone number is no longer enough to log in. It goes last: a password set while the seller still shares the session does not remove them.
If you run Terminate other sessions too early, the dialog says Retry after with a time. Nothing is lost; run the same step again then.
03Running it in the dashboard
Select accounts in Account Manager and open the Protection folder. Its four actions are listed in order; Terminate other sessions is used twice. Each opens a dialog that goes through the accounts one by one and shows a result for each. The same four buttons are on the Protection tab of each account.

IllustrationNot the live panel — nothing here is connected: no state, no saving, no requests. Click a control to read what it does.
Terminate other sessionsBulk actions · Protection
- What it does
- Ends every Telegram session on the account except the one ATREOX is using.
- Used twice
- Once from the imported session, once from your new one after Reauthenticate.
- Too soon
- Refused while the current session is under 24 hours old. The row shows when to retry.
ReauthenticateBulk actions · Protection
- What it does
- Creates a new session, checks it belongs to the same account, and switches ATREOX to it.
- Existing password
- If the account already has a 2FA password, enter it in the row.
Download new tdataBulk actions · Protection
- What it does
- Creates a separate backup session and downloads it as a zip with tdata and a session file. ATREOX keeps using the working session.
- One hour
- The download link works for an hour. Download tdata in the row fetches the same backup again.
Set 2FABulk actions · Protection
- What it does
- Sets the cloud password: the new password twice and an optional hint, plus the current password if one exists.
- One password per run
- The same new password goes on every account in the run. Save it before you press the button.

- The shield
- Counts the five actions (not the waits). Grey until all five succeed in order, blue at 5/5.
- Out of order
- An action run out of order starts the count again from Terminate other sessions. A failed step does not; press Retry this account.
- Account in use
- An account a module is using right now is refused with Account is in use. Stop the module or wait, then retry.
- Recover from tdata
- Replaces the working session, so the shield goes back to 0/5.
04The backup
The zip from Download new tdata is a full login: whoever has the file has the account. Keep it offline and do not log in with it anywhere.
If Telegram ever ends the working session, load the backup with Recover from tdata in the Accounts folder. It only helps if the backup login itself is still alive.
05Session killed by a moving IP
Sometimes an account stops connecting and looks banned, but the account is fine — only its session is dead. Telegram answers with AUTH_KEY_DUPLICATED: the same login key was used from two IP addresses at once, so Telegram treats it as copied and revokes it. ATREOX counts such an account under Invalid.
Two things cause it:
- The proxy's exit IP changed while the account was connected — a rotating proxy, or a sticky one without a hold time.
- The same session was opened in a second place: another tool, your own computer, or a copy of the session file.
To prevent it: one sticky proxy per account, with a hold time, and never open the working session anywhere else while ATREOX runs it.
If it has happened: do not reconnect the same session or re-import the same tdata — that key is dead. Fix the proxy first, then load your backup with Recover from tdata.
06AI Protection
The sequence protects the login. AI Protection protects the behaviour: while an account works in Neurocommenting, NeuroDialogs or Mass Reactions, it also does what a person does — reads channels and groups, scrolls, views posts and stories, looks through its settings, likes a post, archives a chat.

Neurocommenting has it in the Settings section at the bottom of the page; NeuroDialogs and Mass Reactions have it right under Control. Each module has its own level. The default is Medium. The level only changes how often it happens:
| Level | Neurocommenting | NeuroDialogs | Mass Reactions |
|---|---|---|---|
| Off | Only the module’s own work | Only the module’s own work | Only the module’s own work |
| Low | About every 25 min per account | Every 3–7 min between replies | 1 in 4 reactions preceded by browsing |
| Medium | About every 10 min | Every 1–3 min | Every other reaction |
| High | About every 4 min | Every minute or two | Almost every reaction |
- It uses only the account's own channels and groups: no new usernames looked up, nothing joined.
- Private chats are never opened, read or archived.
- It runs on the connection the module already has — no second login, no second IP.