Telegram’s Persistent Identifier Sparks Privacy Concerns

by Daniel Flis

A newly uncovered security flaw in the Telegram messaging platform has raised alarms among cybersecurity researchers, as it could allow third parties to track users across different networks and locations. The issue centers on a device identifier transmitted through the app’s network traffic.

An independent analysis conducted by Symbolic Software, obtained by investigative journalists, revealed that Telegram’s clients send messages in a way that leaves an identifier, called ‘auth_key_id’, visible in plain text or easily decipherable form. This identifier remains unchanged even when users switch sessions, change their IP addresses, move between networks, or travel to different geographic regions.

Because the identifier is accessible without breaking encryption or actively tampering with connections, internet service providers, network administrators, or surveillance systems could collect it passively. This passive collection could enable the creation of a database linking specific devices to their network locations, timestamps, and traffic patterns. If a user’s identity is known through other channels, the data could then be used to monitor that person’s device over time.

The vulnerability first came to light in 2025 following an investigation by a coalition of media outlets. That probe linked Vladimir Vedeneev, a Russian network engineer, to Telegram’s operations as its chief financial officer. Vedeneev held power of attorney to sign documents on behalf of both the company and its founder, Pavel Durov, and ran businesses with ties to Russian state and security-related clients, including the Federal Security Service (FSB). Vedeneev acknowledged having an FSB handler and responding to requests involving Russian internet users, though he denied the existence of the vulnerability and said he does not share Telegram data with the security agency.

Telegram has rejected the latest findings. In a statement, the company asserted that the ‘auth_key_id’ parameter changes on a regular basis and does not reveal user information, message content, or private data. The company also emphasized that its infrastructure is operated solely by its internal engineering teams and denied any connection between Vedeneev or his firm, GNM, and the FSB.