A critical vulnerability in Telegram Desktop allowed attackers to silently steal files, including private keys for cryptocurrency wallets. Discovered by cybersecurity researcher BeakSec and patched in version 7.2.9, the flaw highlights the growing risk of crypto exposure through messaging applications.
🔑 Key takeaways
- A critical flaw affected Telegram Desktop up to version 7.2.8, fixed in 7.2.9 released on September 17
- The attack vector used tg:// links to exfiltrate files without user confirmation
- Crypto wallet private keys and Telegram session files were directly targeted
- A macOS malware targets 16 desktop crypto wallets by stealing authenticated Telegram sessions
- Telegram is also being abused as command-and-control infrastructure for Monero-mining botnets
Critical Telegram Desktop Vulnerability Exposed
The vulnerability affected Telegram Desktop up to version 7.2.8. It was discovered by cybersecurity researcher BeakSec, who reported it to Telegram through the Zero Day Initiative (ZDI) program on June 25, 2024. The Officer’s Notes account on X (formerly Twitter) confirmed the flaw’s existence on October 9, warning the community about the concrete risks to messaging app users.

Officer’s Notes shared a warning message aimed at all Telegram Desktop users:
“A critical vulnerability has been discovered that allows attackers to gain access to your account and secretly steal files from your computer. The attack uses links in the format tg://. If a special command is constructed, clicking the link…”
Officer’s Notes, X account, October 9, 2024
Multi-Stage Attack Mechanism
The attack followed an orchestrated multi-step scenario. The attacker first adds the victim to a Telegram group, then deposits specially crafted files that the application downloads automatically. The attacker then only needs to convince the victim to click a malicious link from their browser, formatted as tg://.
This link opens Telegram and triggers hidden commands, enabling the application to send personal files to the attacker without any further confirmation. The exfiltrable files include passwords, login credentials, and data related to cryptocurrency wallets. If stolen files contained private keys or other information granting access to a wallet, an attacker could have used them to drain funds.
The attacker could also obtain Telegram session files, which allow the application to recognize a user without re-requesting credentials. By copying these files onto their own machine, the hacker could access the victim’s account even without a local passcode. As of now, no real-world exploitation of this flaw has been confirmed.
Telegram fixed the vulnerability in version 7.2.9, released on September 17, without publicly communicating about the flaw. BeakSec recommends several measures: updating Telegram Desktop to version 7.2.9 or later, disabling automatic downloads, restricting group invitations to contacts only, and enabling a robust local passcode. To protect crypto holdings, the researcher advises keeping private keys away from applications installed on the computer, ideally using a hardware wallet.
macOS Malware Targets 16 Crypto Wallets
Separately, researchers at blockchain security firm SlowMist analyzed a macOS malware capable of hijacking Telegram accounts without cracking passwords. The malicious software steals authenticated Telegram Desktop sessions, browser data, macOS keychain credentials, and Apple Notes content.
The malware targets at least sixteen desktop crypto wallets, including Ledger Live, Trezor Suite, Exodus, Atomic Wallet, Electrum, and Sparrow. SlowMist researchers reproduced the attack against Atomic Wallet by matching a stolen wallet database with a collected password. For Ledger and Trezor users, the malware replaces legitimate applications with fake versions that use embedded web pages, tricking users when they enter their recovery phrase.
SlowMist advises immediately revoking Telegram sessions, rotating passwords, and migrating funds to wallets generated from fresh seed phrases.
Telegram as Command-and-Control Infrastructure
Splunk’s research team separately documented the use of Telegram Desktop as command-and-control (C2) infrastructure by botnets targeting cryptocurrencies. In these campaigns, attackers first compromise Windows servers through brute-force RDP (Remote Desktop Protocol) attacks using weak passwords, then install Telegram Desktop to deploy crypto-mining tools such as MinerGate and XMRig.
A Monero wallet linked to these campaigns has been identified, with similar activity dating back to 2018, suggesting the persistence of the same malicious actors over several years. This approach leverages Telegram as an encrypted communication channel between compromised machines and botnet operators, making detection harder for traditional security solutions.
| Threat | Target | Vector | Status |
|---|---|---|---|
| Telegram Desktop vulnerability | Local files, private keys | tg:// links exfiltrating files | Patched (v7.2.9) |
| SlowMist macOS malware | 16 crypto wallets | Stolen Telegram sessions | Active, under watch |
| Splunk botnet | Windows RDP servers | Telegram as C2 channel | Active since 2018 |
Escalating Crypto Theft Landscape
The cryptocurrency market has experienced a significant rise in theft over recent years. According to data cited by CoinCover, in the first half of 2024 alone, stolen cryptocurrencies reached $1.38 billion, double the figure from the same period the previous year. Between 2022 and 2024, approximately $10.5 million was spent on illicit services providing fake social media accounts, indicating the scale of scam techniques targeting crypto users.
In response to these threats, researchers’ recommendations converge: keep software up to date, isolate private keys from messaging apps, use hardware wallets, and maintain rigorous digital hygiene. The Telegram Desktop vulnerability, though patched, is a reminder that the attack surface for crypto assets extends far beyond the blockchains themselves. Users must consider their entire digital ecosystem — messaging apps, browsers, password managers — as vulnerable links in the security chain protecting their funds.
Sources
- Cryptoast – Telegram Desktop vulnerability
- Surfshark – Cryptocurrency theft
- CoinCover – Fake Telegram accounts
- Splunk – Telegram crypto botnet advisory
- Bitcoin Foundation – Mac malware crypto wallets
- Kaspersky – Crypto exchange hacks
This article is published for informational and educational purposes only. It does not constitute investment advice in any form. Always do your own research (DYOR) before making any decisions.

