Disguised proxy links on Telegram can reveal your real IP address

Last update: 13 January 2026
  • Proxy links disguised as profiles or t.me links on Telegram can activate a proxy without prior notice.
  • By connecting to that malicious proxy, the actor controlling it can see the user's real IP address.
  • The flaw particularly affects Telegram's mobile apps for Android and iOS, which are very widespread in Spain and Europe.
  • Telegram has announced that it will incorporate specific warnings when using a proxy link.

Telegram security and proxy links

The rise of Telegram as a messaging platform in Spain and the rest of Europe has gone hand in hand with privacy features highly valued by users, such as use Telegram without a numberSuch as secret chats, encryption in transit, or the ability to use proxies to bypass blocks. However, a recently detected abusive practice is putting one of these protection mechanisms in the spotlight.

Cybersecurity researchers have warned that Some links shared on Telegram hide a malicious proxy Tapping this button can expose the user's real IP address to the proxy owner. The problem primarily affects users of the app on Android and iOS devices, which are the most common in Europe, and has led the company to announce the addition of new warnings.

What are proxy links in Telegram and what are they used for?

In Telegram it is possible to configure a proxy using Special links that, with a single click, automatically add the intermediate connection between the user's device and the service's servers. It is a very popular tool among those who need to bypass geographical restrictions. Avoid Telegram blocking in Spain or corporate filters.

A proxy acts, in simple terms, as an intermediary that forwards the traffic between the user's mobile device and the destination server. This way, the website or service being visited doesn't see the user's real IP address, but rather that of the proxy server, which can help preserve anonymity and prevent direct tracking.

These links are commonly shared within channels and groups, both public and private. usually with an explicit indication that it is a proxyThus, the user knows that, if they click on them, it will temporarily modify the way they connect to Telegram and, in some cases, the rest of their traffic.

In environments where Telegram has become a key communication tool, such as several European countries, Proxies are also used to access the service when there are blocks or selective outages.This legitimate use is being tarnished by the abuse detected in recent weeks.

How links are being disguised to reveal IP addresses

The problem arises when malicious actors begin to hide these proxy links under the appearance of normal Telegram links and usernameswith the typical t.me domain format. That is, the user believes they are opening a simple profile, channel, or content link, but in reality, they are activating a proxy controlled by a third party.

According to information released by the specialized media outlet Bleeping Computer, The Telegram client attempts to automatically connect to the proxy included in the disguised link.without providing the user with clear prior confirmation. This behavior has been observed primarily in the mobile versions for iOS and Android.

Once this connection is established, the proxy owner can View the actual IP address the user is connecting fromFrom that data, it is possible to infer the approximate location, the Internet access provider, and even combine it with other digital fingerprints to better profile the affected person.

Researchers indicate that these types of disguised links are primarily circulating in channels and chats linked to potentially illicit or low-profile activitieswhere the feeling of anonymity causes many users to let their guard down. The technique, however, can be easily replicated in any community.

What are the risks involved in having your IP address revealed?

An IP address is a technical identifier, but Their exposure is not a minor detail from a privacy point of viewAlthough it does not by itself identify a person's name and surname, it can place them in a specific geographical area and even relate them to a particular organization or company.

With this information, an attacker can attempt targeted attacks against the user's connection or device, such as port scans, intrusion attempts, or more personalized phishing campaigns, based on your location or the type of network you use.

Furthermore, when this data is cross-referenced with other elements, such as connection times, the channels frequented, or the information shared, it is possible build a fairly detailed profile of their online behaviorThis opens the door to more persistent monitoring, something especially sensitive in political, activist, or professional contexts.

In Europe, where Telegram is commonly used by tech communities, buying and selling groups, social movements, and journalists, The disclosure of IP could have additional implicationsfrom exposing sources to identifying protest organizers or participants in sensitive conversations.

Who uncovered the abuse and how has Telegram responded?

The situation was made public through the Telegram channel known as chekist42, where cases of disguised proxy links began to be documented that activated a proxy without any additional user interaction. These findings caught the attention of the cybersecurity community.

Subsequently, researchers such as GangExposed R and 0x6rss confirmed the viability of this abuseAnalyzing the behavior of Telegram users when clicking on the affected links, their findings point to a design flaw in how the app handles certain types of proxy URLs.

Following the publication of these reports, a Telegram spokesperson, in statements reported by Bleeping Computer, asserted that the company It plans to introduce additional warnings when the user connects to a proxy through one of these links.The goal is for the person to be aware of what is happening before the connection is established.

Although not all the technical changes have been detailed yet, the measure suggests that in future versions of the app, both on Android and iOS, A clear warning will be displayed when a link is detected that attempts to add or modify a proxy.thus reducing the impact of the disguised links.

Impact on users in Spain and Europe

In markets like Spain, where Telegram has established itself as an alternative to other messaging appsThis type of abuse is not a minor issue. The platform is used to coordinate communities, disseminate news, manage sales channels, and share sensitive information, making IP protection a key element.

In certain European countries, Telegram has also become an essential tool for accessing information when there are media or social network blocks. Reliance on proxies as a mechanism to circumvent censorship and restrictions It is high, so the existence of malicious proxies can have a direct impact on the security of vulnerable groups.

Data protection authorities and agencies in Europe often remind us that IP address is considered personal data in most contextsand its handling is subject to strict regulations. Although in this case the malicious use originates from third parties unrelated to Telegram, the focus is also on how the app manages connections to external proxies.

For many users, this incident will serve as a reminder that, however secure a platform may seem, Ultimate security depends largely on the links you click and the sources they come from.The combination of advanced privacy tools with prudent usage practices becomes essential.

Practical recommendations to avoid falling for disguised proxy links

Until Telegram's new warnings are fully rolled out, experts recommend Exercise extreme caution with any t.me link that comes from unknown sources. or that seems out of context, especially if shared in very large groups or groups with sensitive topics.

It is advisable, as far as possible, Always check who is sending the link and in which channel or chat it is being shared.Links that promise access to exclusive content, overly attractive offers, or supposed "secret" channels can be a lure to sneak in malicious proxies.

If, after clicking a link, the app displays any unusual message related to network settings or connection, it is advisable Cancel the process and review the proxy settings in Telegram settings.to ensure that no unknown server has been left active.

As an additional measure, those who use Telegram for particularly sensitive communications in Spain or other European countries may consider complement its use with privacy alternatives such as Using Tor on Android at the system level. This way, even if a proxy is activated, the visible IP address would still be that of the VPN provider and not the user's.

The incident involving disguised proxy links serves as a reminder that, even in applications with a reputation for security, such as Telegram, Attackers are constantly looking for vulnerabilities in user behavior and feature designs.Staying informed and taking certain basic precautions can make the difference between browsing with relative peace of mind or exposing more data than you'd like.

android malware
Related articles:
Beware of malicious VPN apps on Android: Discover the threats and how to protect yourself