Gridware Logo

While t.me Was Down, Anyone Could Claim to Be Telegram

By Ahmed Khanji Updated 24 July 2026 2 min read

in 𝕏
While t.me Was Down, Anyone Could Claim to Be Telegram

I usually recommend encrypted messaging apps like Signal and Telegram to clients whose work or public profile makes them more likely to be targeted.

Then yesterday, I received a few messages from people saying they couldn’t open t.me links.

What happened to t.me?

Telegram uses t.me as a short address for profiles and public content. Instead of telling someone to search for an account inside the app, you can send them a link with t.me/username.

Yesterday, those links stopped opening in web browsers. The registration record for t.me showed a status called serverHold. A domain with this status is usually not active anymore in DNS.

The app was still working for most users because Telegram doesn’t rely on t.me to send and receive messages. The domain is mainly used for links opened outside the app.

Was Telegram hacked?

At this time we don’t know, but Telegram did not suspend the domain itself. Only the .ME registry can place t.me on serverHold. Telegram could have requested the suspension, although there is no evidence that it did.

It’s possible a hack could have played a part indirectly. The registry could have applied the hold after detecting a possible compromise. However it could also have been an internal decision or an error. Neither Telegram nor the registry has explained what happened.

How threat actors could exploit the outage

t.me stopped working rather than sending users to an attacker’s website. That means there was no obvious sign of a domain takeover. It doesn’t completely rule out a hack, since the registry may have suspended the domain after detecting a security problem.

Attackers could still potentially take advantage of the outage without controlling t.me. They could share fake replacement links and claim that Telegram had moved to a temporary address. Those links could then be used to steal phone numbers or login codes. But there is currently no evidence that this happened during the outage.

t.me is back online

In a post on X responding to Durov, DomainME said Telegram’s t.me domain had been placed “on hold due to OFAC compliance” but was now back online.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.