DEV Community

Yuhe He
Yuhe He

Posted on

Six Attribution Signals Hiding in Telegram's Public Preview HTML

Public Telegram channels leak more about their owners than the owners realize, and every leak is in the HTML you can fetch without an account. Here are the fields I mine on every channel I ingest, and what each one is good for.

1. The t.me/s/ page footer. Each preview page carries the channel's subscriber count at fetch time. Fetch daily, store the series. Growth spikes correlate with virality events; the decay slope after a spike tells you whether the audience was real. A 40k jump overnight with a flat view curve = purchased.

2. The data-post ID series. Post IDs are sequential per channel. The gap between the oldest post ID you can reach and the newest tells you how deep the public history goes; channels that delete aggressively show visible gaps. Deleting history right after a controversy is itself an observable event.

3. The preview's media thumbnails. Post previews expose CDN thumbnail URLs. Media-heavy channels with near-zero text are content farms; the ratio is a one-line feature. Thumbnails also expose the original filename when reposted from WhatsApp-adjacent pipelines - a fingerprint of cross-platform laundering.

4. The pinned-message block. The preview page separates pinned posts from the feed. What a channel pins is its self-image: a disclaimer pins a disclaimer, a sales channel pins a rate card, an aggregator pins a submission form. Pinned content is the cheapest profile of channel intent you can get at scale.

5. The bio block, mined for handles. Channel descriptions routinely contain contact handles (@username), external domains, and cross-promotion links. One crawl of the descriptions gives you a graph: channel → domain, channel → operator handle. The domain edges are gold for attribution work - operators reuse landing pages across channels they run, and the reuse is the link you need.

6. The anti-bot tell. Fetch the same channel 20 times in a minute and watch the response. Rate-limit degradation on the public preview is a live signal of how much scraping pressure a topic area is under - which, transitively, tells you which narratives are being farmed.

None of this requires the MTProto API. The public preview layer is a degraded view of Telegram, but it is public, stable, and criminally under-collected: most tooling jumps straight to API-key pipelines and never mines the free surface.

I package the full field list, the ingestion cadence, and the scoring sheet in the Telegram & Web OSINT Bundle ($5). Free sample: here.

Runs free on GitHub Actions - no server, no paid APIs.

Top comments (0)