Forwarded from Neon Market (venom - busy)
This media is not supported in your browser
VIEW IN TELEGRAM
⚠️ Warning: Two Bugs Being Exploited to Steal Telegram Usernames
Recently, certain individuals have been exploiting two serious bugs to hijack usernames belonging to active, long-standing accounts and channels. Sharing this so people are aware:
1️⃣ Exploiting Phone Numbers Tied to Old Accounts
Some people use illegitimate methods to obtain phone numbers linked to old Telegram accounts (a year or more old). When they register with that number, Telegram automatically deletes the old account — allowing them to directly seize the old username, even though they were never the original owner.
2️⃣ Bug in the Username Protection Mechanism
Normally, when someone changes or removes a username, Telegram applies a protection period before that username can be claimed by anyone else. However, this is a genuine bug: by repeatedly sending username update requests, an attacker can bypass the protection mechanism entirely rather than simply waiting for it to expire.
As a result, the username becomes obtainable long before it should be available, effectively skipping the intended protection period and allowing an attacker to seize the username immediately after it is released.
📹 Attached video shows a real example of this happening, so you can see exactly how the exploit plays out step by step.
Bottom line:
These aren't just clever tricks — they're actual bugs in how the protection system behaves, and they're being used daily to steal valuable usernames from their rightful owners. If you have an old or valuable username, consider enabling two-step verification and make sure your phone number isn't exposed or reused elsewhere.
Recently, certain individuals have been exploiting two serious bugs to hijack usernames belonging to active, long-standing accounts and channels. Sharing this so people are aware:
1️⃣ Exploiting Phone Numbers Tied to Old Accounts
Some people use illegitimate methods to obtain phone numbers linked to old Telegram accounts (a year or more old). When they register with that number, Telegram automatically deletes the old account — allowing them to directly seize the old username, even though they were never the original owner.
2️⃣ Bug in the Username Protection Mechanism
Normally, when someone changes or removes a username, Telegram applies a protection period before that username can be claimed by anyone else. However, this is a genuine bug: by repeatedly sending username update requests, an attacker can bypass the protection mechanism entirely rather than simply waiting for it to expire.
As a result, the username becomes obtainable long before it should be available, effectively skipping the intended protection period and allowing an attacker to seize the username immediately after it is released.
📹 Attached video shows a real example of this happening, so you can see exactly how the exploit plays out step by step.
Bottom line:
These aren't just clever tricks — they're actual bugs in how the protection system behaves, and they're being used daily to steal valuable usernames from their rightful owners. If you have an old or valuable username, consider enabling two-step verification and make sure your phone number isn't exposed or reused elsewhere.
0-day Vulnerability in OSX / iOS Telegram Desktop
https://x.com/fried_rice/status/2080200610985689222?
https://x.com/fried_rice/status/2080200610985689222?
X (formerly Twitter)
Chaofan Shou (@Fried_rice) on X
kimi k3 also did a zero-click arbitrary command execution in Telegram Desktop and iOS app (aslr pinned, one gadget away from full rce).
❤2👍1🔥1👏1 1