GangExposed RU
GangExposed RU
@GangExposed_RU
Jan 10 11 days ago 4 tweets Read on X

⚠️Telegram 1-click vulnerability

A single click can reveal your real IP address — even if you use a proxy.

Affects both Android and iOS Telegram clients. 👇

Tweet image 1

Important detail:

An internal proxy link can be disguised as a normal username, e.g. .

Example of such link:

⚠️ Telegram shows no warning — it looks like a regular internal click.

What happens next:

• Telegram auto-pings the proxy before adding it
• The request bypasses all configured proxies
• Your real IP is logged instantly

Silent and effective targeted attack.

(chekist42)

@0x6rss
ONE-CLICK TELEGRAM IP ADDRESS LEAK!

In this issue, the secret key is irrelevant. Just like NTLM hash leaks on Windows, Telegram automatically attempts to test the proxy. Here, the secret key does not matter and the IP address is exposed.
Example of a link hidden behind a https://t.co/NJLOD6aQiJ

Missing some Tweet in this thread? You can try to Update

More Threads by @GangExposed_RU

0
3 tweets • 5 months ago
Read Thread

Unroll Another Thread

Convert any Twitter threads to an easy-to-read article instantly

Have you tried our Twitter bot?

You can now unroll any thread without leaving Twitter/X. Here's how to use our Twitter bot to do it.

  • Give us a follow on Twitter. follow us
  • Drop a comment, mentioning us @unrollnow on the thread you want to Unroll.
  • Wait For Some Time, We will reply to your comment with Unroll Link.
UnrollNow Twitter Bot
Modal Image
0:00 / 0:00