Three facts decide what you should do first, and they are not equally urgent. A stolen mailbox on its own is not a way into a Blomo account, because Blomo has no “forgot password” email to abuse. A stolen Telegram account is a way in, unless two-factor authentication is switched on. And a stolen wallet recovery phrase is not a way in at all — it is the money itself, already gone if someone else has it. Work down the list below in order, because the steps that come first are the ones that stop being possible once someone else acts.
Do these in this order
- If your wallet recovery phrase was reachable from the account that was stolen, move the crypto out of that wallet first. Reachable means: typed into an email, sent to yourself in a messenger, saved in a note that syncs to a cloud account tied to that mailbox, or photographed into a photo library. Create a new Blomo Wallet and send the balance to it, then keep the new phrase on paper and out of every account that was compromised. What this step buys you is narrow and worth naming: the phrase the thief can reach stops controlling your money. Nothing else on this list is worth doing before it, because a blockchain transfer cannot be reversed by Blomo or by anyone else.
- Take back the account that was actually stolen. Change the password on the mailbox or Telegram account, and turn on that provider’s own two-factor. If you skip this and go straight to Blomo, whoever is sitting in your mailbox watches you do it.
- Change your Blomo password in the app. Settings → Security → Email and password. The change asks for your current password, and the moment it succeeds every other session is signed out. This is the step that removes someone who is already signed in as you.
- Turn on two-factor authentication if it is off. Settings → Security → Two-factor authentication. Blomo uses TOTP by RFC 6238, so any authenticator app works. Confirming it also signs out every other session, and from that point a sign-in through Telegram no longer skips the second factor.
- Store the recovery codes somewhere offline. They are shown once, when you confirm two-factor, and Blomo does not keep a copy to show you again. Each code works once.
- Read your notifications, your cards and your wallet history, then write to support. The support entrance is the Telegram bot @blomo_bot, and it is the only one — the same chat the app opens from Settings → Help → Support → Write to support.
What a stolen mailbox gets someone
Less than people fear. Blomo has no password reset by email today: there is no link that a mailbox can receive and turn into a new password. Someone reading your mail cannot sign in to Blomo with what they find there, and cannot lock you out of your own account.
That cuts the other way too, and it is fair to say so. If you forget your Blomo password and have no Telegram account linked, there is no self-service reset waiting for you either. Keeping a second way in — a linked Telegram account, or a confirmed email address if you signed up through Telegram — is what keeps a forgotten password from becoming a locked account.
What a stolen Telegram account gets someone
More. Signing in through Telegram is a full sign-in to the Blomo account linked to it. If two-factor authentication is off, whoever controls the Telegram account controls the Blomo account.
If two-factor is on, that door is closed at the same point as the password door: Blomo asks for the authenticator code after a Telegram sign-in as well. This is deliberate — a second factor that one of the two sign-in methods walks past is not a second factor.
What two-factor authentication covers, and what it does not
Two-factor is checked when you sign in. It is not asked again for each action inside a session that is already open. So the code protects the door, and ending other sessions is what removes somebody who is already through it. That is why step 3 sits above step 4 on the list.
A Blomo session lasts up to thirty days unless it is ended. There is no list of active devices in the app today, and no separate “sign out everywhere” button. Changing your password is how you end them all at once; confirming two-factor does the same thing at the moment you confirm it.
One more thing worth knowing before you need it: Blomo does not send you an alert when someone signs in to your account. The notifications in the app cover top-ups, card events and support replies. Silence is not evidence that nothing happened — check the account yourself.
The wallet is a separate question, and the honest part is short
Two things hold here regardless of anything else. Whoever has the recovery phrase can move the money in that wallet — that is what the phrase is for, and it is why a phrase that reached a stolen mailbox is an emergency rather than an inconvenience. And a transfer on a blockchain is final: Blomo cannot reverse it, cannot freeze the receiving address and cannot refund it out of its own pocket. This is the part of “no documents, no verification” that has a price attached: there is no institution standing in the middle with the power to undo a move. Write to support anyway if it happens — support will tell you plainly what can and cannot be done — but expect an honest no rather than a recovery.
Which is why the phrase belongs on paper and nowhere a stolen account can reach. Not a screenshot: a screenshot lives in a photo library that syncs to a cloud account, and that is where phrases are stolen from.
Short answers
Can someone reset my Blomo password using my email? No. Blomo has no password-reset-by-email flow, so a mailbox on its own is not a way into a Blomo account.
Does two-factor stop someone who has my Telegram account? At sign-in, yes. A Telegram sign-in does not skip the second factor — if it is on, the authenticator code is still required.
How do I sign out a device I cannot see? Change your password in the app. It requires your current password and signs out every other session. Turning on two-factor does the same at the moment you confirm it.
Will Blomo return crypto that left my wallet? No. Blomo cannot reverse a blockchain transfer, and does not promise to.
Someone is messaging me claiming to be Blomo support — is that related? Often, yes: a leaked mailbox is how the target list is built. Blomo support lives in one place, the bot @blomo_bot, and the signs of a fake support message are worth reading before you answer anyone.
Where to read next
- Account and card security — what protects an account and the money on it.
- Blomo Wallet — what the wallet is, and how it differs from the Blomo balance that cards spend from.
- How to spot a fake Blomo support message — the things Blomo never asks for.