Apple removed Telegram on Monday after a planted piece of child sexual abuse material was hidden from a public group's members. CEO Pavel Durov says any user content app shares the exposure.
Telegram's CEO says the technique was almost invisible to the people it was used against. According to Pavel Durov, an attacker edited an old message inside an active public Telegram group, swapped in AI-modified child sexual abuse material, the kind of imagery platforms are legally required to remove, and the edit did not surface in the chat for ordinary members. The group's members could not see the new content, which meant they could not flag it themselves. The attacker then filed a takedown report to Apple. By Monday night, Telegram, an app used by more than a billion people, was off the App Store. It was restored within hours. (The Verge)
The trick leans on how public Telegram groups work. They are searchable, linkable, and lightly moderated. An edit of an old message keeps the message in place, keeps its timestamp, and does not bump the chat for the people inside it. The bad content sits there as a stale message in a long thread, easy to miss, easy to forget, and a single tap away from a screenshot for an attacker who wants to file a clean report with Apple's App Review. The imbalance is structural: a single bad-faith report, filed with a planted piece of content, can remove a billion-user app before the platform that built it is told what is happening.
He said the takedown amounted to "potential systemic risk" for any app that hosts user-generated content, and accused Apple of acting "before contacting us." Apple did not respond to The Verge's request for comment, so the order of events, whether Apple tried to reach Telegram, what category of report triggered the removal, and whether Apple's standard review process flagged the edit, are all unverified. (The Verge)
Durov also claims there is a recurring extortion pattern behind incidents like this one. In his telling, attackers use automated accounts to seed illegal content inside large public groups, file a takedown report directly with Apple rather than with Telegram, and then demand a ransom from the group owner to make the report go away. The details of any specific case, including the names of the group or the ransom demand in this incident, are not in the public record. The pattern he describes, however, is not new. App Review moves fast on credible child sexual abuse material reports, because the legal exposure for a platform that delays is severe, and that speed is exactly what makes the channel exploitable for a planted report.
Telegram's own track record complicates the framing. The company has spent years defending its decision to keep public groups lightly moderated, and has been criticized for hosting illegal content in channels that range from piracy hubs to extremism forums. Durov is personally exposed. French authorities arrested him in 2024 on charges that included enabling illegal transactions, and Russia has issued an arrest warrant against him alleging Telegram facilitates terrorism. He has a self-interested reason to recast a moderation incident as an external attack on his platform. None of that negates his specific technical claim about the invisible edit. It just keeps the question of motive honest.
If the edit-and-report trick Durov describes works as he says it does, the next target is not Telegram. It is any app that hosts public, editable chat, which today includes Discord servers, X Communities, Roblox comment threads, and the comment fields of nearly every consumer social product. The unresolved question is what the App Store review pipeline owes those platforms when a single report, filed in good faith by the platform or in bad faith by an attacker, can drop a billion-user app out of distribution without a heads-up. Apple has not answered. The group that triggered this incident remains private, and Durov says the attackers are still at it.