# Telegram is privacy nightmare (personal number leak and OTP hijack)

**URL:** https://discuss.privacyguides.net/t/telegram-is-privacy-nightmare-personal-number-leak-and-otp-hijack/17518
**Category:** General
**Created:** 2024-03-26T19:01:12Z
**Posts:** 25

## Post 1 by @Akita — 2024-03-26T19:01:12Z

Telegram can leak your phone number to a stranger without your consent and/or hijack OTP code.

> **[Telegram's new peer-to-peer SMS relay is an absolute privacy nightmare](https://www.androidpolice.com/telegram-use-your-phone-send-other-people-login-codes/)**
>
> Telegram aims to save some coin by sending login messages via some users' phones

---

## Post 2 by @jerm — 2024-05-07T20:40:39Z

Telegram sucks

No [backdoored](https://words.filippo.io/dispatches/telegram-ecdh/) Secret Chats on desktop and Web intentionally, full of bad takes too.

> **[End-to-End Encryption FAQ](https://tsf.telegram.org/manuals/e2ee-simple#2-why-are-there-no-secret-chats-on-desktop-apps)**
>
> While checking the results of a recent quiz on how End-to-End Encryption (E2EE) works on Telegram, I noticed that not everyone…

> **[Never will I ever recommend Telegram again.](https://tgrush.bearblog.dev/never-will-i-ever-recommend-telegram-again/)**
>
> I've been around the block in terms of messaging services, privacy, and what else belongs to that topic as a whole. Recently, I've been seeing a lot more peo...

They now infested with cryptocurrencies like their own for usernames and USDT [https://decrypt.co/124243/telegram-announces-usdt-stablecoin-payments-on-tron-network](https://decrypt.co/124243/telegram-announces-usdt-stablecoin-payments-on-tron-network)

---

## Post 3 by @axenup — 2024-05-08T01:33:43Z

“Not to mention Telegram is vulnerable to SIM-Swaps and SIM-Jacking because of the fact that it relies on a phone number and SMS for signup and signin.”

I am not at all defending Telegram but Signal has this same flaw sadly!

---

## Post 4 by @TinFoilHat — 2024-05-08T08:57:09Z

All I can say is there are real usecase for people using Telegram.

I agree Matrix based messengers came a very long way and provided “kind of” similar feature set as Telegram. BUT there are reasons why so many activists, protesters, rebels, certain ethnic communities etc, picked and keep using Telegram. Telegram was not, is not, and will not be the only tool they use for everything, though.

Not to say Matrix based messengers have no match with Telegram regarding to stability and bot ecosystem, which are both vital in many usecases.

More “private and secure” messengers like signal is not suitable for huge groups with high moderation needs.

SIM is definitely an issue, and the “feature” offered by Telegram mentioned in OP’s link is definitely a no-go zone. The same goes to Web3 and business side offerings from Telegram, which is known in partnership with Tencent. There are many malicious TG groups and channels containing malicious files and links, even malicious Telegram clients can he found quite easily.

When you use a software / service, you need to know the limitation and boundaries. Not even Signal can save you from poor opsec.

I don’t know your threat model, and I am really not defending Telegram, I wish we have a all-round better or on-par alternatives, but we don’t.

In short, Telegram can be useful, but use it wisely and carefully.

Edit: Both Telegram and signal can prevent sim swap account takeover with 2 step verification. If you use them, make sure you enabled and tested them.

---

## Post 5 by @aspirin6993 — 2024-05-10T12:55:00Z

But Signal has perfect forward secrecy and when someone else logs into your account, recipients get alerted of the verification number change (aka safety number) and the hacker cannot access your past messages.

---

## Post 6 by @axenup — 2024-06-07T23:42:37Z

Signal does not have a 2FA cloud password like Telegram. In this way Signal is less secure than Telegram in terms of account-jacking

---

## Post 7 by @pinkandwhite — 2024-06-08T01:48:40Z

> [@axenup](#):
>
> 2FA cloud password

I have no idea wtf this is meant to mean, but Signal _does_ literally have the ability to lock re-registering your phone number with a pin that you set, i.e., with a second factor. That’s the sim swap prevention with 2 step verification TinFoilHat mentioned

---

## Post 8 by @anon66791365 — 2024-06-08T02:30:22Z

Difference is with Signal you can’t see old messages but with Telegram you can. Had this happen when I signed up with a VOIP number, I got someone’s very personal chats.

---

## Post 9 by @anon43985288 — 2024-06-08T02:50:32Z

That’s a feature not a bug. Though Telegram has an option to auto-delete all messages after 90days or more (configurable) if you haven’t logged in.

---

## Post 10 by @anon66791365 — 2024-06-08T03:15:28Z

I understand but it’s worse for privacy than how signal handles it.

---

## Post 11 by @jerm — 2024-07-16T15:51:39Z

Telegram is [susceptible to SS7 attacks](https://www.theguardian.com/world/2023/feb/15/revealed-disinformation-team-jorge-claim-meddling-elections-tal-hanan) the most as it doesn’t have an mitigations like Signal does with [Signal PINs](https://signal.org/blog/signal-pins/).

---

## Post 12 by @anon49578468 — 2024-07-16T18:29:00Z

I think that there is a separation that needs to be made clear to the end user: Telegram is NOT a E2EE personal communication app (in addition to other concerns pointed out by others, [it leaks your location too](https://www.schneier.com/blog/archives/2021/01/finding-the-location-of-telegram-users.html)), but it is clearly a good enough tool for mass communication not may not necessarily be encrypted or private. I think I agree with @TinFoilHat that it is one of the only mass adopted medium for mass communication that is better than trying to organize a matrix room or a forum for (for example, Iranian and Russian political dissidents use it often, and [Telegram tries to help them too](https://www.schneier.com/blog/archives/2018/06/russian_censors.html)). But the problem lies in the fact that telegram is neither transparent about what specific [use cases/threat models](https://telegram.org/security) it fits, and nor is it open to reforming its often moronic [crusades](https://www.theregister.com/2024/05/14/telegram_ceo_calls_out_rival/) against signal.

---

## Post 13 by @hakavlad — 2024-07-17T10:55:10Z

> [@anon49578468](#):
>
> Telegram is NOT a E2EE personal communication app

Absolutely! First of all, Telegram is cloud-based media platform. The main value is provided by censorship-resistant channels (with the ability to comment) and public thematic chats. Public channels can be read even without registration. In Russia, Telegram (together with YouTube) remains one of the main platforms for receiving uncensored information. All small independent media and sites are blocked, but YouTube and Telegram remain accessible. Telegram allows you to publish information that cannot be published on YouTube or Facebook.  
It can also be used to store and share files up to 2GB.

---

## Post 14 by @jerm — 2024-07-17T11:48:43Z

> [@anon49578468](#):
>
> [it leaks your location too](https://www.schneier.com/blog/archives/2021/01/finding-the-location-of-telegram-users.html)

You have to opt-in to this feature. Not turned on by default.

---

## Post 15 by @anon49578468 — 2024-07-17T11:51:54Z

100%, my apologies if that was not clear from my writing. I still think it being easily exploitable is bad end-user experience for someone who thinks of telegram as secure & private.

---

## Post 16 by @privacycarrot — 2024-07-17T13:00:34Z

> [@jerm](#):
>
> doesn’t have an mitigations like Signal does with [Signal PINs](https://signal.org/blog/signal-pins/).

How’s it different from Telegram’s 2FA password?

---

## Post 17 by @jerm — 2024-07-17T13:05:06Z

It is the same, I wasn’t aware of it, thanks.

---

## Post 18 by @hakavlad — 2024-07-17T13:17:24Z

> [@jerm](#):
>
> Telegram is [susceptible to SS7 attacks](https://www.theguardian.com/world/2023/feb/15/revealed-disinformation-team-jorge-claim-meddling-elections-tal-hanan) the most as it doesn’t have an mitigations

When you try to log in from a new device, Telegram sends a request to previously logged in devices. SMS is sent only if there are no logged in devices.

---

## Post 19 by @jerm — 2024-08-18T23:20:01Z

> On the Cryptographic Fragility of  
> the Telegram Ecosystem

[https://www.research-collection.ethz.ch/bitstream/handle/20.500.11850/620789/telegram\_client\_analysis.pdf](https://www.research-collection.ethz.ch/bitstream/handle/20.500.11850/620789/telegram_client_analysis.pdf)

---

## Post 20 by @PurpleDime — 2025-11-14T19:55:09Z

Super late to this party. I only became aware of it a couple of months ago through a friend who ran into this issue and asked for my help.

**Telegram is charging for SMS verification in some regions, and that’s unacceptable. The fact that the way they do it is by using your phone number as a relay for SMS login codes makes it even worse.**

 ![17duvx4i57mf1](https://forum-uploads.privacyguidesusercontent.com/original/2X/8/830423439a8e0816073043fe5fbc97751f138869.jpeg)

[The Telegram subreddit is filled with posts complaining about this SMS Fee.](https://www.reddit.com/r/Telegram/search/?q=SMS+fee&cId=b845b182-3952-46c0-84af-7956d2a75709&iId=be83b1c4-6d84-4108-bc5c-7a6b4ed99f7e)

So far the regions I’ve seen affected by this include the US, some European countries, some Asian countries, and the Middle East.

**WORKAROUND:**

[The only working workaround I’ve seen reported is to install an older version of Telegram on Android, specifically v.11.7.3.](https://www.reddit.com/r/Telegram/comments/1md9q23/for_anyone_having_issues_where_telegram_wont_send/)However, I’ve read that for some people it’s no longer working. I don’t think there are any workarounds for iPhone since I don’t think you can download an older version of an app on a new device if a new one exists.

**THINGS I DON’T GET:**

1. _ **If Signal can afford SMS verification in “expensive” countries, why can’t Telegram?** _

The way I see it, Telegram is punishing people who live in poorer countries, which I am guessing is a huge chunk of their user base.

1. _ **Why is SMS verification required when you are logged to another device?** _

This issue doesn’t just affect people who are signing up to Telegram for the first time. It also affects all existing users who want to log in on a new device, specifically a new phone. Unlike Signal, Telegram allows you to use their app on multiple phones. Although logging in on other types of secondary or third device will not require SMS verification, doing it on a second phone will. Even though I have mixed feelings about this, one could argue this measure is sensible.

1. _ **Why is SMS verification required when you are logged on other devices and have 2FA enabled?** _

Telegram allows you to enable 2FA with a password and email address. When you enable it, you won’t be able to log into a new device without them. It doesn’t make sense to me to force users who have 2FA on to pay for verification via SMS when they have other means to verify themselves.

And those who don’t have 2FA on but are already logged into at least one device, should be able to enable it and avoid the SMS verification.

1. _ **Why does SMS verification require an email, and why are some email providers blocked?** _

From what I heard, some people, regardless of if they have 2FA enabled or not, are required to provide an email address to receive a code for SMS verification. However, for a lot of email domains, although the code is received, it is not accepted when it is entered. For others, it is. It makes zero sense. Even when the code is accepted, you are presented with the screen asking you to pay for SMS verification.

1. _ **Why is the only way to pay for SMS verification via P2P?** _

**TELEGRAM DOESN’T CARE ABOUT PRIVACY:**

This is terrible for privacy and terrible implementation on Telegram’s part. They are an awful company. There’s a part of me that hates them more than WhatsApp because at least WhatsApp users are more aware that their data is being exploited. Telegram and its founder, Pavel Durov, have a cult grip on their users. I don’t know what it will take to break the curse.

---

## Post 21 by @plus-subzero — 2025-11-14T20:17:25Z

> [@PurpleDime](#):
>
> From what I heard, some people, regardless of if they have 2FA enabled or not, are required to provide an email address to receive a code for SMS verification.

I’m one, even though I cost them nothing SMS wise because I’m always signed in elsewhere. I know for sure they won’t accept a SimpleLogin address (don’t know whether they do an MX lookup or just block shared SL domains). I understand why they do it, [it’s expensive](https://signal.org/blog/signal-is-expensive/), but their hostility toward users has become palpable lately.

---

## Post 22 by @PurpleDime — 2025-11-14T20:28:10Z

> [@plus-subzero](#):
>
> I understand why they do it, [it’s expensive](https://signal.org/blog/signal-is-expensive/), but their hostility toward users has become palpable lately.

I know someone who used SL. They received the code, but the code is not accepted when they enter it. It says “wrong email”. That makes zero sense. If Telegram is not going to accept an email address, why send the code to them? When a website blocks a domain, it will not let you receive any emails at that domain. That is not how Telegram’s SMS verification works, though.

I also know someone who used a mainstream email provider and still their code was rejected. Their system is really crap.

Lastly, I get that registration fees are expensive, but the fact remains, Signal doesn’t charge their uses for it. Moreover, Telegram has the option to verify your account via 2FA password for existing users. They could also not require phone numbers.

---

## Post 23 by @plus-subzero — 2025-11-14T20:41:13Z

> [@PurpleDime](#):
>
> Moreover, Telegram has the option to verify your account via 2FA password for existing users.

There are plenty of clever [ways](https://support.signal.org/hc/en-us/articles/5440120029082-Re-registering-using-your-Signal-PIN) around it. It’s mostly just a way to get more users to sign up for their Premium plan, I guess. They’ve had perpetually broken OTP code flows for as long as I can remember, so I don’t think it’s malicious. They’re just big and don’t care.

---

## Post 24 by @PurpleDime — 2025-11-14T20:49:26Z

> [@plus-subzero](#):
>
> There are plenty of clever [ways](https://support.signal.org/hc/en-us/articles/5440120029082-Re-registering-using-your-Signal-PIN) around it. It’s mostly just a way to get more users to sign up for their Premium plan, I guess. They’ve had perpetually broken OTP code flows for as long as I can remember, so I don’t think it’s malicious. They’re just big and don’t care.

Wow. If Signal found an innovative way to make it work, then yeah, this reaffirms that Telegram really doesn’t care.

---

## Post 25 by @PurpleDime — 2026-01-07T07:52:29Z

Curious to find out if [the new passkey integration](https://discuss.privacyguides.net/t/telegram-adds-passkey-support-still-requires-phone-number/34460) allows users to log into second devices without SMS verification. If not, then this makes then passkeys make little difference for privacy as far as I’m concerned, especially when you consider that Telegram now charges many countries for SMS verification, and that that verification system, whch is P2P, is a privacy and security nightmare.
