Telegram does not need to have its message encryption broken for users to be tracked at the network layer.
Telegram sends MTProto over unencrypted TCP, exposing auth_key_id - a long-lived identifier tied to the clientโs authorisation key. An ISP, hotel WiFi operator, mobile carrier, transit provider, or surveillance system on the network path can see that identifier if they can observe the traffic. It can remain stable across app restarts, IP changes, VPN use, network switches, and location changes.
Secret Chats protect message content, but this leak is below that layer. That makes the attack passive.
The risk is in retroactive correlation. Think a journalist using Telegram from different networks for months, then joining hotel or corporate WiFi under a real name.
That one identity anchor could make old logs searchable for the same auth_key_id.
The fix is simple - mandatory transport encryption for all MTProto connections, with no unencrypted fallback. Telegram chose not to do this.
Source: @kaepora symbolic.software/pdf/gnmx-01.pdf
P.s.: Long life, global passive observer
Telegram sends MTProto over unencrypted TCP, exposing auth_key_id - a long-lived identifier tied to the clientโs authorisation key. An ISP, hotel WiFi operator, mobile carrier, transit provider, or surveillance system on the network path can see that identifier if they can observe the traffic. It can remain stable across app restarts, IP changes, VPN use, network switches, and location changes.
Secret Chats protect message content, but this leak is below that layer. That makes the attack passive.
The risk is in retroactive correlation. Think a journalist using Telegram from different networks for months, then joining hotel or corporate WiFi under a real name.
That one identity anchor could make old logs searchable for the same auth_key_id.
The fix is simple - mandatory transport encryption for all MTProto connections, with no unencrypted fallback. Telegram chose not to do this.
Source: @kaepora symbolic.software/pdf/gnmx-01.pdf
P.s.: Long life, global passive observer
โค13๐11๐7๐ฅ4๐ญ4๐2๐2๐2๐ข1๐คฎ1
This media is not supported in your browser
VIEW IN TELEGRAM
Did you prepare yourself for it?
๐13 7๐6๐5๐พ5โค4๐4๐4๐ฅ3๐ข3๐ญ1
Following a NYT report that the US and Israel discussed a potential post-war role for Mahmoud Ahmadinejad, some Iranian hardliners began accusing the former president of being an Israeli asset, despite no public evidence supporting the claim.
(Source: https://www.nytimes.com/2026/05/19/us/politics/iran-israel-us-leader-ahmadinejad.html)
(Source: https://www.nytimes.com/2026/05/19/us/politics/iran-israel-us-leader-ahmadinejad.html)
Nytimes
Early War Goal Was to Install Hard-Line Former President as Iranโs Leader
An Israeli strike designed to free Mahmoud Ahmadinejad from house arrest in Tehran, U.S. officials said, was part of an effort to bring about regime change and put him in power.
โค12๐7๐6 5๐ข3๐ฅ2๐2๐2๐2๐ค1๐ญ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐8๐5๐ฅ4โค2โก1๐ค1๐คฉ1๐1๐ฏ1 1
New Scientist
Fully autonomous drones have killed human soldiers for the first time | New Scientist
A senior figure in the Ukrainian defence industry told New Scientist that a test took place two years ago involving fully autonomous drones set to destroy anything in a given area, with confirmed casualties
โค8๐7 4๐คฉ3๐3๐ฏ3๐3๐คฎ2๐ฅ1๐1๐ค1
MTONGA? Steps? Great again?
Someone airdropped undeletable NFTs to each TON wallet that made a transfer. The NFTs contain NSFW content; when you try to delete them, they burn and immediately recreate with a new NSFW picture.
The NFTs contain a link to @nft_burn as a removing solution.
Users who followed instructions from @nft_burn should pass a verification check through sign-in using their Telegram account. That account would then be drained.
I tried to report @nft_burn three times to different people. The last time, I got a reply that moderators already knew about the problem.
So, for three weeks, @nft_burn has still been available, and as I understand it, continues draining and stealing Telegram accounts.
MTONGA? They do not give a fuck about users' problems until you do not have tits.
Someone airdropped undeletable NFTs to each TON wallet that made a transfer. The NFTs contain NSFW content; when you try to delete them, they burn and immediately recreate with a new NSFW picture.
The NFTs contain a link to @nft_burn as a removing solution.
Users who followed instructions from @nft_burn should pass a verification check through sign-in using their Telegram account. That account would then be drained.
I tried to report @nft_burn three times to different people. The last time, I got a reply that moderators already knew about the problem.
So, for three weeks, @nft_burn has still been available, and as I understand it, continues draining and stealing Telegram accounts.
MTONGA? They do not give a fuck about users' problems until you do not have tits.
๐13๐ฅ5โค4๐ค4 4๐3๐2๐2๐1๐1๐ฏ1
Adventures in Dystopia
MTONGA? Steps? Great again? Someone airdropped undeletable NFTs to each TON wallet that made a transfer. The NFTs contain NSFW content; when you try to delete them, they burn and immediately recreate with a new NSFW picture. The NFTs contain a link to @nft_burnโฆ
MTONGA? What about spam on Telegram?
If you try to create a chat on Telegram with two or more participants and share a public link to it, bots will find it after a while and youโll end up having to delete dozens of spam messages every day.
This doesnโt happen on Instagram, Twitter, Facebook or VK.
Creating small groups on Telegram for local purposes isnโt practical or sensible.
P.S.: @nft_burn is still online
If you try to create a chat on Telegram with two or more participants and share a public link to it, bots will find it after a while and youโll end up having to delete dozens of spam messages every day.
This doesnโt happen on Instagram, Twitter, Facebook or VK.
Creating small groups on Telegram for local purposes isnโt practical or sensible.
P.S.: @nft_burn is still online
๐7โค5 5๐ฅ4๐4๐4๐2๐1๐1๐
1
Adventures in Dystopia
MTONGA? Steps? Great again? Someone airdropped undeletable NFTs to each TON wallet that made a transfer. The NFTs contain NSFW content; when you try to delete them, they burn and immediately recreate with a new NSFW picture. The NFTs contain a link to @nft_burnโฆ
When the owners of @solana lost it and it was snatched up by bots reserving free tags, it was blocked in less than a day, over the weekend. It could have been quicker, but it happened at night.
โค8๐ฅ4๐ข4 4๐3๐2๐ค2๐1๐1๐1
Adventures in Dystopia
MTONGA? What about spam on Telegram? If you try to create a chat on Telegram with two or more participants and share a public link to it, bots will find it after a while and youโll end up having to delete dozens of spam messages every day. This doesnโt happenโฆ
๐ฅ9๐7๐5๐4๐ข3๐ฏ3๐ค2 2โค1๐1
This media is not supported in your browser
VIEW IN TELEGRAM
Russian roofers face up to 20 years in prison in the U.S.
Angelina Nikolaou and Ivan Birskus have been charged with eight counts following their climb up the Empire State Building. They are accused of endangering lives, burglary, intentional property damage, unlawful entry, tampering with equipment, possession of burglary tools, disturbing the peace, and violating local law.
Combined, these charges could result in up to 20 years in prison. In addition, prosecutors claim that the roofers caused $1,500 in property damage. The couple denies the charges.
โโโโโ
Would it be possible to see the same news about Jewish roofers? I think they wouldn't have mentioned the nation in that case. Is it racism? Or do I not understand something?
Many windows to go to prison when you aren't a US politician. ๐ซ
Angelina Nikolaou and Ivan Birskus have been charged with eight counts following their climb up the Empire State Building. They are accused of endangering lives, burglary, intentional property damage, unlawful entry, tampering with equipment, possession of burglary tools, disturbing the peace, and violating local law.
Combined, these charges could result in up to 20 years in prison. In addition, prosecutors claim that the roofers caused $1,500 in property damage. The couple denies the charges.
โโโโโ
Would it be possible to see the same news about Jewish roofers? I think they wouldn't have mentioned the nation in that case. Is it racism? Or do I not understand something?
Many windows to go to prison when you aren't a US politician. ๐ซ
๐8 5๐4๐ฅ3๐2๐2โค1โ1๐ค1๐คก1๐ฏ1
Forwarded from Neon Market (venom - busy)
This media is not supported in your browser
VIEW IN TELEGRAM
โ ๏ธ Warning: Two Bugs Being Exploited to Steal Telegram Usernames
Recently, certain individuals have been exploiting two serious bugs to hijack usernames belonging to active, long-standing accounts and channels. Sharing this so people are aware:
1๏ธโฃ Exploiting Phone Numbers Tied to Old Accounts
Some people use illegitimate methods to obtain phone numbers linked to old Telegram accounts (a year or more old). When they register with that number, Telegram automatically deletes the old account โ allowing them to directly seize the old username, even though they were never the original owner.
2๏ธโฃ Bug in the Username Protection Mechanism
Normally, when someone changes or removes a username, Telegram applies a protection period before that username can be claimed by anyone else. However, this is a genuine bug: by repeatedly sending username update requests, an attacker can bypass the protection mechanism entirely rather than simply waiting for it to expire.
As a result, the username becomes obtainable long before it should be available, effectively skipping the intended protection period and allowing an attacker to seize the username immediately after it is released.
๐น Attached video shows a real example of this happening, so you can see exactly how the exploit plays out step by step.
Bottom line:
These aren't just clever tricks โ they're actual bugs in how the protection system behaves, and they're being used daily to steal valuable usernames from their rightful owners. If you have an old or valuable username, consider enabling two-step verification and make sure your phone number isn't exposed or reused elsewhere.
Recently, certain individuals have been exploiting two serious bugs to hijack usernames belonging to active, long-standing accounts and channels. Sharing this so people are aware:
1๏ธโฃ Exploiting Phone Numbers Tied to Old Accounts
Some people use illegitimate methods to obtain phone numbers linked to old Telegram accounts (a year or more old). When they register with that number, Telegram automatically deletes the old account โ allowing them to directly seize the old username, even though they were never the original owner.
2๏ธโฃ Bug in the Username Protection Mechanism
Normally, when someone changes or removes a username, Telegram applies a protection period before that username can be claimed by anyone else. However, this is a genuine bug: by repeatedly sending username update requests, an attacker can bypass the protection mechanism entirely rather than simply waiting for it to expire.
As a result, the username becomes obtainable long before it should be available, effectively skipping the intended protection period and allowing an attacker to seize the username immediately after it is released.
๐น Attached video shows a real example of this happening, so you can see exactly how the exploit plays out step by step.
Bottom line:
These aren't just clever tricks โ they're actual bugs in how the protection system behaves, and they're being used daily to steal valuable usernames from their rightful owners. If you have an old or valuable username, consider enabling two-step verification and make sure your phone number isn't exposed or reused elsewhere.