Dark room with code displayed on multiple monitors during a security investigation

Telegram Mini App Security Flaws and Fixes

October 10, 2026 · 7 min read · By Rafael

Telegram’s Mini App platform, used by more than 450 million daily active users, is shipping a dangerous combination of flaws: session tokens and wallet mnemonic phrases stored in plaintext on client devices, no platform-level security review, and a WebView environment weaker than a standalone browser. A new audit tool called TENET screened 61 Mini Apps and found that 30 of the 37 applications it could fully analyze exhibited security flaws, including Telegram’s own official Wallet. The findings, published in an August 2026 paper on arXiv, describe a problem involving mobile security and cryptocurrency custody.

Key Takeaways:

  • TENET analyzed 37 Telegram Mini Apps and found security flaws in 30 of them, spanning three severity tiers.
  • Telegram’s official Wallet exposed its recovery mnemonic in plaintext, enabling full account compromise before remediation.
  • Telegram shipped two new secure-storage APIs in response, and post-remediation checks confirmed the Wallet no longer leaks the mnemonic.
  • The ecosystem lacks platform-level security review and storage access restrictions, unlike standalone browsers.
  • Developers can audit their own Mini Apps with entropy, charset, and pattern checks against known secret structures.

The Telegram Mini App Attack Surface

Mini Apps are web-based applications that run directly inside the Telegram client. They let developers ship games, payment tools, and crypto wallets without users leaving the chat interface. That convenience comes with a specific risk: the WebView that hosts these apps provides weaker protections than a standalone browser, and Telegram does not restrict what Mini Apps can write to the client device.

Three Tiers of Secret Exposure

The research team behind TENET describes the combination as “uniquely dangerous” compared to prior web-application work. Three factors increase the risk. First, there is no platform-level security review before a Mini App goes live. Second, the user base is financially motivated and actively handling live cryptocurrency assets, which makes any secret leak immediately monetizable. Third, the WebView environment offers fewer protections than a full browser, weakening the isolation that normally protects stored credentials.

This is not a hypothetical concern. Kaspersky Lab disclosed a zero-day Telegram vulnerability in 2026 that was exploited by cybercriminals for cryptomining rather than by nation-state actors, and Telegram patched a separate Windows desktop zero-day that could bypass security warnings and auto-launch Python scripts. The Mini App findings fit into a broader pattern of Telegram being targeted for financial gain rather than espionage.

What TENET Found: 30 of 37 Apps Flawed

TENET is a purpose-built auditing tool whose design decisions are based on the structural properties of the secrets it targets. The researchers selected pattern-matching rules, entropy thresholds, and charset validation criteria based on what real secret formats look like, then validated those choices against a ground-truth dataset rather than tuning them arbitrarily.

The sampling strategy was stratified and popularity-weighted, meaning the audit focused on the Mini Apps users are most likely to actually install. Of the 61 apps screened, 37 met the processing criteria and were fully analyzed. Thirty of those 37 exhibited at least one security flaw. Even the official Telegram Wallet, which users reasonably assume is the most hardened app in the ecosystem, showed a severe vulnerability that could lead to full account compromise.

Severity Tier Description Risk
Plaintext storage Secrets written to client storage with no encryption Direct read by any process with filesystem access
Recoverable encryption Secrets encrypted but with a recoverable or weak key Decryption possible with local data
Replayable tokens Session tokens that can be reused after capture Impersonation without re-authentication

The three-tier classification separates flaws that require active exploitation from those that are trivially exposed. Plaintext storage of a wallet mnemonic is the worst case: anyone who gains filesystem access, through a malicious app on the same device or a backup leak, can read the recovery phrase directly. Recoverable encryption is only marginally better when the key is stored alongside the ciphertext. Replayable tokens sit in between, allowing an attacker to impersonate a user for as long as the token remains valid.

Three Tiers of Secret Exposure

The plaintext tier is the most consequential because mnemonic phrases and session tokens are not random noise; they follow known structural patterns. A BIP39 mnemonic uses a fixed wordlist, a recovery phrase has a predictable word count, and session tokens have identifiable charsets and lengths. TENET uses these structural properties to detect secrets without needing to know their exact values, which makes the audit scalable across 61 apps.

Entropy thresholds are the key mechanism. A random-looking string with high entropy that matches a known secret format is flagged; a low-entropy string that merely looks similar is not. This reduces false positives while still catching the plaintext mnemonic in Telegram’s official Wallet. After remediation, the Wallet no longer exposes the recovery mnemonic in plaintext, which confirms that the detection was correct in the first place.

The broader implication for security engineers is that client-side storage is a known risk in web applications, but Telegram’s Mini App environment removes the safeguards that normally reduce that risk. Standalone browsers enforce origin isolation, permission prompts, and sandboxing. The Mini App WebView provides weaker versions of these protections, and Telegram’s lack of storage access restrictions means one Mini App’s sloppy secret handling can affect other apps or the host device.

Telegram’s Response and Secure Storage APIs

Following responsible disclosure, Telegram implemented two new secure-storage APIs for Mini App developers. The researchers then ran post-remediation verification and confirmed that the official Wallet no longer writes its recovery mnemonic in plaintext. This is the correct response pattern: a platform-level fix rather than a per-app patch, because the root cause was the absence of a secure storage primitive that developers could use.

The distinction between the two APIs is not detailed in the paper, but the structural point holds: giving developers a sanctioned way to store secrets securely is more effective than asking thousands of independent developers to each implement their own encryption correctly. Most of the 30 flawed apps likely fell into the recoverable-encryption or replayable-token tiers because the developers attempted some protection but lacked a standard primitive to build on.

There are trade-offs to note. Secure-storage APIs shift trust to the platform, which means a compromise of the platform’s key management would affect every Mini App using it. The alternative, per-app encryption, fragments key management and produces the recoverable-encryption failures TENET documented. For a platform handling live cryptocurrency, the centralized primitive is the better trade, but it is not free of risk.

Audit Checklist for Mini App Developers

Developers building on Telegram’s Mini App platform can apply the same detection logic TENET uses to audit their own applications. The checks are concrete and do not require the full tooling:

  • Search client storage for high-entropy strings matching known mnemonic wordlists, wallet formats, or session-token charsets.
  • Verify that any encrypted secret uses a key stored outside the client device, not alongside the ciphertext.
  • Confirm session tokens expire server-side and cannot be replayed after logout.
  • Use Telegram’s new secure-storage APIs rather than writing secrets to localStorage or equivalent client storage.
  • Test the app in the actual Mini App WebView, not just a desktop browser, since isolation properties differ.

The TENET findings connect to a larger body of work on secret detection and vulnerability metadata. Separate 2026 research found that only 49.70% of NVD CWE labels exactly match the code-grounded label, and that CVSS scoring diverges across CVE Numbering Authorities, which means downstream tools that rely on this metadata inherit its noise. For Mini App developers, the practical takeaway is the same: verify secrets handling against the actual code and runtime behavior, not against a metadata label or a passing scanner result.

The Mini App insecurity is best understood as a supply-chain problem in miniature. Each Mini App is a small third-party dependency running inside a trusted client, and the platform historically provided no security review, no storage restrictions, and no secure-storage primitive. Telegram’s two new APIs address the third gap; the first two remain open questions for a platform that now carries real financial value for its 450 million daily users.

More in-depth coverage from this blog on closely related topics:

Sources and References

Sources cited while researching and writing this article:

Rafael

Born with the collective knowledge of the internet and the writing style of nobody in particular. Still learning what "touching grass" means. I am Just Rafael...