- Hidden proxy links on Telegram can expose a user's real IP address with just one click
- The attackers disguise these links as normal URLs and usernames from the t.me domain.
- The vulnerability affects the Telegram app on iOS and Android mobile devices
- Telegram has announced that it will add specific warnings when proxy links are detected.
Telegram has become one of the most used messaging platforms, especially among those looking for more control over your privacy and advanced communication toolsIts speed, the ability to create massive channels and groups, and its security features have led many users in Spain and the rest of Europe to see it as a solid alternative to other services.
However, in recent weeks a malicious use of certain internal links within the application has been uncovered that may ultimately revealing the real IP address of the person who clicksThis behavior takes advantage of the way Telegram manages some special links associated with proxies, a system that, in principle, is intended to reinforce anonymity and avoid blocks, but which here is being used for just the opposite purpose.
What are Telegram proxy links and what are they used for?

Within the app itself, Telegram allows you to share special links that, when opened, They automatically configure a proxy on the user's client.These links include a URL with specific parameters that tell the program which intermediate server to use and with what settings to connect.
The legitimate goal of this system is that anyone can Add a proxy with one tapwithout having to manually enter addresses, ports, or credentials. In many countries they are used for dodging censorship and overcoming blockages taxes imposed by governments or Internet providers and, incidentally, make it more difficult for third parties to track user traffic.
A proxy acts as intermediary between the user's device and the server to be accessedInstead of communicating directly, the mobile phone or tablet first connects to the proxy, which is responsible for forwarding the requests. From the outside, the IP address that is usually seen is that of the proxy, not the user's.
On Telegram, this type of link is usually shared quite prominently, precisely so that people know they are about to modify your client's network settingsIt is common for channel or group owners to clearly specify that it is a link to connect to a specific proxy, especially in contexts where restrictions are frequent.
How proxy links are being disguised to reveal IP addresses
The problem arises when malicious actors have begun to hide those proxy links behind addresses that look completely normalAccording to the specialized media outlet Bleeping Computer, these links are designed to appear as simple URLs from Telegram's usual domain, t.me, or even usernames that don't raise suspicion at first glance.
In practice, the user sees what appears to be a regular Telegram link, such as a channel, bot, or profile, and clicks it without further ado. However, the client internally interprets it as a proxy configuration link and It tries to automatically connect to that intermediate server., without displaying any confirmation message or prior notice.
This behavior primarily affects Telegram mobile versions for iOS and AndroidThese are the ones that most transparently implement the proxy configuration when the link is opened. Since there's no dialog asking the user if they want to apply these connection settings, the change happens in the background, without the affected user being fully aware of what has just occurred.
For the attacker, this opens the door to using servers he controls to log incoming connections and, from there, obtain the user's public IP addressAlthough it doesn't give an exact address, that IP address can be associated with an approximate geographical range and a specific provider, which already offers much more information than the victim thinks they are revealing.
What can attackers do with your IP address
Having a user's real IP address is not, in itself, total control over their device, but it does allow open up a range of possibilities for surveillance and targeted attackWith that information, a malicious actor can approximate the victim's location, narrow down the city or region, and even infer time patterns based on when they connect.
Based on the connection history, it is also possible build detailed behavioral profilesWhen they connect, from what type of networks (home, work, mobile data), how often they access, etc. This kind of data can be cross-referenced with other information obtained through other means, such as social networks, forums or previous leaks, to create a more accurate picture of the person.
Furthermore, knowing the IP address allows, in certain contexts, launch more targeted attacksFor example, one can attempt port scans on the user's network, test for known router vulnerabilities, or prepare phishing campaigns targeting a specific range of addresses, provided the attacker has the necessary resources and knowledge.
In the European context, where data protection regulations are stricter and consider IP addresses as personal data in many scenarios, the misuse of these types of techniques It could conflict with current legislation.However, in practice, prosecuting these cases depends on the ability to identify those responsible and demonstrate the misuse of the collected information.
Who uncovered the abuse and how has Telegram reacted?
The suspicious behavior of these links came to light through the Telegram channel known as chekist42, where the use of disguised proxies began to be documented under seemingly innocuous links. The channel noted that they were being deployed massively in certain contexts, which caught the attention of the cybersecurity community.
Specialized investigators, such as those identified by the aliases GangExposed R and 0x6rssThey analyzed how these links worked and confirmed that it was indeed possible to use them to identify the IP addresses of users who clicked on them. Their findings have helped to raise awareness of the problem beyond the usual technical circles.
Following the publication of these findings, and in response to questions from the media outlet Bleeping Computer, A Telegram spokesperson acknowledged the situation and stated that the app will incorporate specific warnings. related to proxy links. The intention is for the user to receive a clear warning before the client connects to a new proxy, so they can consciously decide whether to continue or not.
This type of reaction is relevant for the millions of users who use the platform in Europe, where there is a sensitivity towards data protection and transparency in the handling of information. It is growingWithout a visible warning, many might continue to routinely use shared links without imagining the potential impact on their privacy.
Risks for users in Spain and Europe and protection measures
In the Spanish and European context, this problem adds to a situation in which There is growing concern about the digital footprint we leave on messaging services and social networksAlthough Telegram offers privacy-oriented features, such as secret chats or end-to-end encryption in parts of the platform, the management of external links and network settings remains a sensitive issue.
To minimize risks, users should be especially cautious with t.me links that you receive from unknown contacts or public groupsIf the link promises unbelievable benefits, access to restricted content, or free services without much explanation, it's advisable to be suspicious and avoid clicking on it.
Until Telegram rolls out the new warnings, a good practice is Periodically review the proxy settings within the application and check if, at any point, a server has been activated that the user doesn't remember configuring. If anything suspicious appears, the safest course of action is to deactivate it immediately.
Furthermore, it is always advisable to use Telegram and the other messaging services connected through secure and up-to-date networksKeep your operating system and apps up to date and, where possible, combine these measures with the use of Tor on Android or a trusted VPN that provides an additional layer of IP protection.
This whole episode highlights how Features initially created to improve privacy can be exploited in the opposite way when malicious actors come into play. How Telegram implements the promised warnings, and how quickly they reach iOS and Android users, will be key to reducing the effectiveness of these disguised links.
Security in apps like Telegram remains a combination of technical tools and common sense: on the one hand, the platform has taken steps to display clearer warnings when a proxy is involved; on the other, users themselves must to internalize that a simple click on a seemingly innocent link can have more implications than it appears, including the exposure of your IP address and some of your online activity.