CertiK Discovers Telegram RCE Vulnerability Allowing Attacks on Users

Cybersecurity Telegram
Author
Author
Jimmy AkiVerified
Part of the Team Since
Sep 2022
About Author

Jimmy has nearly 10 years of experience as a journalist and writer in the blockchain industry. He has worked with well-known publications such as Bitcoin Magazine, CCN, and Blockonomi, covering news...

Last updated: 

Blockchain security platform CertiK uncovered a Telegram vulnerability on April 9 that allows hackers to deploy a remote code execution (RCE) attack through “specially crafted media files, such as images or videos.”

CertiK’s Discovery Reveals Telegram Vulnerability

CertiK raised the alarm in an X post, describing the RCE attack as a “high-risk vulnerability in the wild.” An RCE vulnerability allows an attacker to execute arbitrary code on a remote device, which can lead to various levels of damage.

The security firm told the media that the RCE attack was exclusive to Telegram’s desktop version, not its mobile applications, as it was not designed to run executable programs.

https://twitter.com/CertiKAlert/status/1777632812700713254

Following CertiK’s discovery, the official Telegram X account countered the claim and argued that there was no vulnerability in their system and that the issue was likely a fake. Some X users shared their opinion, stating that the issue was not new to the platform.

This is not the first time that Certik has reported attacks on Telegram. In October 2023, the blockchain security firm warned users about Telegram bot tokens, which it claimed could be exit scams.

In 2021, a Shielder security research report revealed that the messaging app suffered a similar remote media-related attack that enabled hackers to send modified animated stickers on Android, iOS, and MacOS application versions which would grant them access to media files that people share in all types of chats.

The issues were reported and addressed by the Telegram security team, however.

In May 2023, Google engineer Dan Revah discovered a bug that enabled attackers to activate the camera and microphone on laptops running on MacOS software.

Could the Latest Security Setback Derail Telegram’s Wall Street Listing?

CertiK’s discovery of the Telegram vulnerability coincides with the platform’s announcement of a possible debut on Wall Street.

In March, Telegram CEO Pavel Durov exclusively told the Financial Times that the messaging app was mulling an IPO in the US, following in the footsteps of Reddit, whose stock has captured investor’s interest. With over 900 million users, a preliminary valuation of $90B, and increasing revenues, the social media app is ripe for a public listing.

“Generally speaking, we see value in [an IPO] as a means to democratise access to Telegram’s value,” he explained.

While Telegram’s expansion is evident, one major hurdle it must overcome before venturing into Wall Street is its ‘dark web’ baggage. Cybersecurity experts have long labeled the app as the hotbed for organized criminals.

According to a US cybersecurity magazine report, bad actors use the messaging platform as a marketplace to facilitate illicit transactions and spread extremist content. The platform’s poor reputation and alleged ties to the Kremlin – Patel Durov has consistently denied this – could be a major talking point for investors.

Despite these drawbacks, Telegram has adopted crypto for in-app ad purchases as part of its user monetization strategy.

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,096,484,631,113
-0.76
Trending Crypto

More Articles

Price Analysis
China’s DeepSeek AI Predicts the Price of XRP, Solana, Cardano by the End of 2026
Ahmed Balaha
Ahmed Balaha
2025-12-25 22:03:21
Industry Talk
Best Crypto to Buy Now 25 December – XRP, Dogecoin, Shiba Inu
Ahmed Balaha
Ahmed Balaha
2025-12-25 21:34:50
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors