Telegram Lecture at TechnoSecurity & Digital Forensics on June 4, 2025
April 3, 2025
No AI. Just a dinobaby sharing an observation about younger managers and their innocence.
The organizers of the June 2025 TechnoSecurity & Digital Forensics Conference posted a 60 second overview of our Telegram Overview lecture on LinkedIn. You can view the conference’s 60 second video at https://lnkd.in/eTSvpYFb. Erik and I have been doing presentations on specific Telegram subjects for law enforcement groups. Two weeks ago, we provided to the Massachusetts Association of Crime Analysts a 60-minute run down about the technical architecture of Telegram and identified three US companies providing services to Telegram. To discuss a presentation for your unit, please, message me via LinkedIn. (Plus, my son and I are working to complete our 100 page PDF notes of our examination of Telegram’s more interesting features. These range from bots which automate cross blockchain crypto movement to the automatic throttling function in the Telegram TON Virtual Machine to prevent transaction bottlenecks in complex crypto wallet obfuscations.) See you there. — Thank you, Stephen E Arnold, April 3, 2025, 223 pm U S Eastern
FOGINT: Dubai Makes a Crypto Move
March 26, 2025
Cryptocurrencies are on deck to replace fiat currencies. The Dubai Financial Services Authority (DFSA) recently recognized a cryptocurrencies says Gadgets 360: “USDC, EURC Stablecoins Secure ‘Token Recognition’ In Dubai.” The two new tokens recognized in Dubai are the stablecoins USDC and EURC from Circle.
The DFSA approved the use of these stablecoins within the Dubai International Financial Centre’s (DIFC) economic activities. EURC and USDC are the first crypto stablecoins to receive official recognition from the DFSA. Stablecoins are cryptocurrencies backed by traditional assets such as gold and regular hard currencies.
The DFSA issued a crypto token framework in 2022 so businesses working with cryptocurrencies would have safe guidelines. Only DFSA-recognized cryptocurrencies are allowed to be used within the DIFC. This is to ensure companies are protected from scams.
This is an important move for stablecoins:
Dante Disparte, Chief Strategy Officer and Head of Global Policy and Operations at Circle called the development a ‘milestone’ moment for the stablecoin sector. ‘This milestone aligns with our mission to make digital dollars and euros more accessible, interoperable, and useful for businesses, developers, and financial institutions worldwide,’ Dante said. ‘As the first stablecoins to receive this designation, USDC and EURC continue to set the global standard for transparency, compliance, and utility.’”
Circle is the second largest provider of stablecoins in the world after Tether. The company reported the USDC profit reached $18 trillion since launching in 2018. Dubai, Telegram, and crypto: Interesting ingredients.
Whitney Grace, March 18, 2025
FOGINT: Pavel Durov Offers a Fix for Lagging US Innovation
February 10, 2025
Yep, another dinobaby emission. No smart software required.
Pavel Durov, familiar to the US Securities & Exchange Commission and the French judiciary, has offered some advice to Americans. Mr. Durov founded Telegram, and he shared some ideas via is Du Rove Channel on Telegram. You can find the message at https://t.me/durov/394. (You do not need to have the Telegram mini app installed to read his post.) Mr. Durov’s message addresses the success of DeepSeek, and the lack of innovation in the United States. He believes that China will dominate the West without positioning his home country as a winner or a loser in AI innovation.
He points out:
Following the success of the Chinese startup Deepseek, many are surprised at how quickly China has caught up with the US in AI. However, China’s progress in algorithmic efficiency hasn’t come out of nothing. Chinese students have long outperformed others in math and programming at international Olympiads.
He then draws a parallel to inform Americans about the reason for the Chinese Deepseek achievement:
When it comes to producing outstanding performers in math and science, China’s secondary education system is superior to that of the West. It fosters fierce competition among students, a principle borrowed from the highly efficient Soviet model.
As you may know, Mr. Durov encountered some friction with Russian authorities when he operated VKontakte, the so-called Russian Facebook. Mr. Durov exited that company, bounced around looking for a suitable location for Telegram. He settled on Dubai and operated a service in order to make free speech a possibility for many people in the world.
Mr. Durov explains the difference between the outstanding Chinese and Russian educational systems and the American approach:
… most Western schools discourage competition, prohibiting public announcements of students’ grades and rankings. The rationale is understandable — to protect students from pressure or ridicule. However, such measures also predictably demotivate the best students. Victory and defeat are two sides of the same coin. Eliminate the losers — and you eliminate the winners.
Mr. Durov’s logic is that educational systems must allow the super achievers to fulfill their destiny. I want to point out that Mr. Durov is rumored to have fathered more than 100 children. Allegedly he will pay a suitable female breeder for the costs of artificial insemination. The idea is that supermen need to produce super children in order for the superior people to improve society.
He then makes clear why China will dominate the West:
Reality, unlike well-meaning school policies, does have public grades and rankings — whether in sports, business, science, or technology. AI benchmarks that demonstrate Deepseek’s superiority are one of such public rankings. And more are coming. Unless the US secondary education system undergoes radical reform, China’s growing dominance in technology seems inevitable.
Several observations are warranted:
-
- The clever recasting of his name from Durov to Paul Du Rove is a brilliant play on words. Wordsmiths require time to find the precise way of delivering a bon mot. Mr. Durov has had some time to contemplate his means of expression. He has been confined to France since August 2024.
- His principles of freedom have been modified since his lengthy interview with the American (presumably one who has not fulfilled his intellectual capabilities due to a lack of competition) Tucker Carlson. In that interview, Mr. Durov expressed his commitment to freedom and resisting governmental pressure to compromise the security of Telegram users. However, shortly after the interview, Mr. Durov blocked Ukrainian government messages to Russian users of Telegram.
- Mr. Durov is now responsible for steering Telegram through a number of business challenges while incrementally increasing his cooperation with legal authorities interested in money laundering, human trafficking, and CSAM activities on Telegram.
To sum up, the message from Mr. Durov illustrates his staunch belief in the Chinese and Russian systems. He makes a case that better education generates more innovation. Words from a person under the control of the French judicial system speak volumes.
Stephen E Arnold, February 10, 2025
Telegram Speed Dates a Bad Actor: Pavel Durov and Judgment or Lack Thereof
February 5, 2025
Another non smart software write up from a real, authentic dinobaby.
Pavel Durov has had a rocky start to 2025. He may have about 100 loving children. He has his brother Nikolai’s support. He has pals from his days at VKontakte. And he has new friends from the French judiciary urging him to embrace some opportunities for freedom. That private jet is waiting. The sunny skies of Dubai beckon.
But another decision may come to haunt him. Telegram and the TON Foundation’s BFF has been busted. According to the US Attorney for the Southern District of New York, one of the outfits shepherding the Ku Group and its KuCoin operations said, “Yep, we are guilty of unlicensed money transmitting business.”
As a dinobaby, I think the statement in “KuCoin Pleads Guilty to Unlicensed Money Transmission Charge and Agres to Pay Penalties Totaling Nearly $300 Million” means in rural Kentucky speak something like “money laundering.” The official news release explains:
U.S. Attorney Danielle R. Sassoon said: “For years, KuCoin avoided implementing required anti-money laundering policies designed to identify criminal actors and prevent illicit transactions. As a result, KuCoin was used to facilitate billions of dollars’ worth of suspicious transactions and to transmit potentially criminal proceeds, including proceeds from darknet markets and malware, ransomware, and fraud schemes. Today’s guilty plea and penalties show the cost of refusing to follow these laws and allowing unlawful activity to continue.”
Pavel Durov’s proxy outfit the Open Network Foundation showcased Ku Group at the November 2024 Gateway Conference in Dubai. Ku Group’s then-CEO (apparently not called out in the official statement issued on January 27, 2025, by the southern district) sparkled with optimism about the tie up between the owner of the Messenger mini app and the Peken Global Limited / Ku Group operation.
The news release points out:
KuCoin was founded in or about September 2017. Since its founding in 2017, KuCoin has become one of the largest global cryptocurrency exchange platforms, with more than 30 million customers and billions of dollars’ worth of cryptocurrency in daily trading volume. Between in or about September 2017 and in or about March 2024, the date of the Indictment, KuCoin served approximately 1.5 million registered users who were located in the U.S., and earned at least approximately $184.5 million in fees from those U.S. registered users.
Some of Ku Group’s services included, according to the official AG statement placing:
orders for spot trades in cryptocurrencies, including Bitcoin, Ethereum, and others, and orders for derivative products, including futures contracts, tied to the value of Bitcoin and other cryptocurrencies. As a result of its operation of this business, KuCoin has, at all relevant times, been a money transmitting business required to register with FinCEN and reported suspicious transactions.
The November BFF moments between Ku Group and Telegram’s proxy organization make clear that the Messenger app is a clever and versatile technology system. It is also now clear that the intent of some of Telegram’s announcements is possibly going against the established financial systems methods of serving their customers.
For now, Chun (Michael) Gan and Ke (Eric) Tang have suffered a set back. Will the Peken Global and Ku Group disappear? Possibly. However, the Ku Group’s and Telegram’s vision of a Web3 financial services entity is likely to thrive. Will the French judiciary amp up their discussions with Pavel Durov? Will the United Arab Emirates take a closer look at the Telegram operation which has a nominal headquarters in Dubai? Will the Swiss authorities pay a visit to the TON Foundation’s office in Zug, Switzerland? Will bad actors change their ways of hiding money in digital form?
Good questions. I think the French are on the job. The other entities may be reluctant to rock the good ship Telegram too much more. Could those folks have a vision for a financial system cut loose from traditional ways to do money business?
My thought is that BRICS, Russia, China, and some influential people have a goal. Telegram and the Ku Group were players, not leaders.
Stephen E Arnold, January 5, 2025
Who Knew? A Perfect Bribery Vehicle, According to Ethereum Creator
January 30, 2025
A blog post from an authentic dinobaby. He’s old; he’s in the sticks; and he is deeply skeptical.
I read “Ethereum Creator Vitalik Buterin: Politician Issued Coins Perfect Bribery Vehicle.” Isn’t Mr. Buterin a Russian Canadian? People with these cultural influences can spot a plastic moose quickly in experience.
The write up reports:
Ethereum founder Vitalik Buterin has criticized cryptocurrencies issued by politicians as “a perfect bribery vehicle.” “If a politician issues a coin, you do not even need to send them any coins to give them money,” Buterin explained in a tweet. “Instead, you just buy and hold the coin, and this increases the value of their holdings passively.” He added that one of the reasons these “politician coins” are potentially excellent tools for bribery is the element of “deniability.”
Mr. Buterin is quoted in the write up as saying:
“I recommend politicians do not go down this path.”
Who knew that a plastic moose would become animated and frighten the insightful Russian Canadian? What sound does a plastic moose make? Hee haw hee haw.
Nope, that’s a jackass. Easy mistake.
Stephen E Arnold, January 30, 2025
FOGINT: Telegram Sends Message: We Are Coming to America!
January 15, 2025
A short blog post from the FOGINT team.
In 1988, Eddie Murphy starred in the film Coming to America. The film features this bit of dialogue:
- Lisa McDowell: So why did you come here?
- Prince Akeem: To find something special.
- Lisa McDowell: It’s a long way to travel.
- Prince Akeem: No journey is too great when one finds what he seeks.
What Telegram and its wing man, the Open Network Foundation, seek is a new market. Telegram, since the detainment of Pavel Durov (Telegram’s founder) has been pushing crypto. Pushing hard. Now the organization with more than 900 million users is coming to America. “No journey is too great when one finds what he seeks.” And what Pavel Durov seeks is a market for online gambling linked to crypto currency. Online gambling, link ups with organizations mostly unknown in the US, and a messaging system with a mind-boggling range of features.
Pavel Durov is coming to the New World, a land of opportunity for crypto and certain interests unlikely to be aligned with those of the United States and its allies. Thanks, creative You.com. Good enough.
Bloomberg published “Telegram Linked TON Blockchain to Expand in US As Trump Courts Crypto.” Similar stores have appeared in Cryptobriefing, Cryptotimes, and Cryptonews, among others. For example, “Telegram-Linked TON Eyeing U.S. Expansion” reports:
The TON Foundation, associated with Telegram Messenger, is planning to expand into the U.S. market, anticipating more favorable regulatory conditions under President-elect Donald Trump. As part of its U.S. expansion strategy, the foundation has appointed Manuel Stotz, founder of Kingsway Capital Partners, as its new president.
The film was a comedy. Telegram’s return to the United States is an important step. Telegram is not just a messenger service used by warfighters, purveyors of contraband, and goofy pitches for get rich schemes originating in Myanmar. Telegram is different from Signal, Threema, and WhatsApp. The decentralized organized organization has a social media component, a recruitment program, a venture fund, some smart software, and a conceptual commitment to ideas somewhat different from those in the US and some countries in Western Europe, including France where Pavel Durov is confined to the country as a legal proceeding involving him moves forward through the French judicial system.
As Prince Akeem said, “No journey is too great when one finds what he seeks.” Mr. Durov has found what he seeks. Telegram in America.
Stephen E Arnold, January 15, 2025
FOGINT: Divergent Trajectories for Facebook and Telegram
January 7, 2025
The Techmeme splash page featured several Meta (Facebook, WhatsApp, etc.) stories. Here’s a mini-version of the home page with the Zuck-related stories identified:
The separate “stories” presented one theme: Free speech. Here’s a representative item from today’s Techmeme page at 9 20 am US Eastern: “Meta Is Ending Its Fact-Checking Program in Favor of a Community Notes System Similar to X.” The news item from NBC reports:
Meta CEO Mark Zuckerberg announced a series of major changes to the company’s moderation policies and practices Tuesday, citing a shifting political and social landscape and a desire to embrace free speech. Zuckerberg said that Meta will end its fact-checking program with trusted partners and replace it with a community-driven system similar to X’s Community Notes. The company is also making changes to its content moderation policies around political topics and undoing changes that reduced the amount of political content in user feeds, Zuckerberg said.
For me, this says, “Cut some costs and respond to “a shifting political and social landscape.” The direction in which Meta is moving seems to be “freer speech,” albeit within whatever Silly Putty guardrails Mr. Zuckerberg decrees.
In contrast, Telegram — which has out-innovated Meta for many years — is taking a different path through environmental changes in the datasphere. Since France required that Mr. Durov, founder and “owner” of Telegram remain in France until his company’s behavior has been dissected, Telegram is moving on a different trajectory. A few details of this charge have been reported in “Telegram Hands U.S. Authorities Data on Thousands of Users.” This exposé declares:
Telegram, the popular social network and messaging application which has also become a hotbed for all sorts of serious criminal activity, provided U.S. authorities with data on more than 2,200 users last year, according to newly released data from Telegram. The news shows a massive spike in the number of data requests fulfilled by Telegram after French authorities arrested Telegram CEO Pavel Durov in August, in part because of the company’s unwillingness to provide user data in a child abuse investigation. Between January 1 and September 30, 2024, Telegram fulfilled 14 requests “for IP addresses and/or phone numbers” from the United States, which affected a total of 108 users, according to Telegram’s Transparency Reports bot. But for the entire year of 2024, it fulfilled 900 requests from the U.S. affecting a total of 2,253 users, meaning that the number of fulfilled requests skyrocketed between October and December, according to the newly released data. “Fulfilled requests from the United States of America for IP address and/or phone number: 900,” Telegram’s Transparency Reports bot said when prompted for the latest report by 404 Media. “Affected users: 2253,” it added.
Since France’s direct action, Telegram has apparently become even more cooperative with law enforcement. Plus, Telegram agreed to participate in activities designed to identify human traffickers. On the surface, it appears that Telegram is becoming more agreeable to legitimate requests from law enforcement. Telegram has become associated with a number of interesting and possibly illegal activities in some countries. Examples range from groups (private and public) discussing terrorism and child pornography.
But that “shift” to cooperation distracts from what is a major change at Telegram and its affiliated entities like The Open Network Foundation, Ton.social, and assorted investment vehicles. Specifically, Telegram is doubling down on crypto currency. The Telegram infrastructure is being shaped and in some cases repurposed to host services, features, and distributed applications related to crypto. The idea, as the FOGINT team understands it, is to provide a hub or nexus for traditional financial services built on crypto, not the US dollar, euros, or “traditional” and regulated currencies.
A second effect of this shift at Telegram is its push to provide a home for a wide range of seemingly harmless online games. On the surface, a parent or a person as old as the producer of this blog, would glance at the display and think, “Oh, another child’s game.” Those individuals would be incorrect. Telegram “click to earn” games include addictive hooks and the upside of playing are points which can be converted to crypto currency. Gambling and the downstream financial services required by big winners or “whales” are the customers. The addictive element is just part of Telegram’s marketing activities.
Net net: Meta wants free speech or at least to appear to be lining up with the “shifting political and social landscape.” Telegram is using social as a way to speed use of crypto as an alternative to the US dollar. Social media giants are similar in some ways, but at this point in time, the two companies are on divergent trajectories.
Stephen E Arnold, January 7, 2025
Dubai: The 21st Century Crypto “Silicon Valley”
January 7, 2025
Information from the FOGINT research team.
How prescient was Telegram when it selected Dubai as headquarters of a decentralized, distributed company? After Pavel Durov bounced from Moscow to Berlin, to Singapore to San Francisco, and ended up in Dubai, United Arab Emirates, his judgment seems good. FOGINT’s view is that he listened to UAE government officials and determined that that country wanted to become the financial hub for crypto currency. The goal of both UEA and Telegram aligned: Both wanted to exploit a desire of many countries and financial entrepreneurs from the US-centric financial system to one based on crypto currency, largely unregulated crypto currency cut loose from the shackles of the US financial system. A standard other than and competitive with the US dollar promised a shift of finance from Wall Street to Sheikh Zayed Road.
The plan is not a secret. “UAE to Attract Crypto Ventures Amid EU’s Stringent MiCA Regulation: Experts” reports that regulations in Western Europe are adding a kick in the pants for some crypto-centric innovators. The regulation is Markets in Crypto-Assets Regulation (MiCA). Its purpose is to establish a legal framework — that is, uniform rules for crypto assets — across the EU. MiCA might be the booster that the United Arab Emirates and other Middle Eastern states want. A more supportive regulatory environment and a thriving crypto community exist in the United Arab Emirates.
According to the Crypto News’ report:
The MiCA regulation introduces a pan-European licensing and supervisory regime for crypto-assets, exchanges, and service providers… Among its stringent requirements, small stablecoin issuers must hold 30% of their reserves in low-risk EU-based commercial banks, while major players like Tether face a mandate to maintain 60% or more in similar institutions. While aimed at ensuring market stability, these rules are seen as increasing operational costs, potentially undermining the financial viability of many firms.
The FOGINT team wants to point out that the UAE provides a “crucible” for crypto innovation; specifically:
- A regulatory environment different from that in the US and Western Europe; for example, a Virtual Assets Regulatory Authority (VARA) in Dubai oversees the regulation, licensing, and governance of virtual assets
- Tax benefits because there is currently no direct taxation on cryptocurrencies in the UAE
- Infrastructure provides a “Silicon Valley”-type of magnetic pull situated almost equidistant from Asian financial hubs and Western European money centers
- The UAE supports the crypto industry via the Dubai Multi Commodities Centre and the Dubai International Financial Centre
The UAE has cultivated a robust ecosystem for crypto and blockchain innovation with more than 500 crypto startups are now based in Dubai’s free zones. One poster child for Dubai’s flexibility is Telegram’s choice of the city as the location for its “headquarters.” (Keep in mind that Telegram is a distributed and decentralized organization, so the “staff” in Dubai is modest in size for the company’s size.) Plus, the UAE has implemented measures to ensure investor protection and market stability with Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements. Also, the Central Bank of the UAE approved a custodial insurance product to protect financial institutions and their clients from potential losses due to hacks or internal fraud.
One key question: Are there technical professionals with crypto experience in Dubai? The answer, in part, can be approached via the attendance at the November 2024 TON Foundation Gateway Conference. The conference attracted about 400 people in 2023. In November 2024, more than 2000 crypto savvy professionals participated in two day program held in Dubai. The UAE may be on the path to becoming the hot spot for crypto innovation.
Stephen E Arnold, January 7, 2025
FOGINT: What Do the Most Recent Telegram Function Enhancements Portend for 2025?
January 2, 2025
This is a report from the FOGINT research team.
For a company without a permanent office with staff who show up everyday, Telegram has been busy in December 2024. One good example is Telegram’s chopping up the video stream from its Gateway Conference held in early November 2024. The individual talks with their unique Telegram / TON Foundation quirkiness are available on YouTube at this link. One can mostly parse some speakers’ content using the Google caption function.
Also, a “real” news service has collected several other Telegram and its ecosystem announcement in “Telegram Rolls Out Third-Party Account Verification, Filters.” For those unfamiliar with Telegram, the service offered a verification process. That service remains, and “has now launched a new project to let already-verified third-party authorities, such as food quality regulators or educational consortiums, verify an account.” The article also points out that Telegram has added “filters” to the baked in search and retrieval service. FOGINT wants to point out that the search service is not very good. Retrieval remains spotty. The only way to find certain content is to monitor specific public and private groups. The content from these groups can then be downloaded or sucked from the service with a well-crafted script tuned to observe Telegram’s quite specific blocks on bulk downloading. According to the cited article, Telegram has added:
- Emoji reactions
- Sending gifts (this is a money generating angle)
- Search filters for private chats, group chats, and channels.
The write up does not ask the question, “What is the direction these features suggest Telegram and its associated entities are heading in 2025?”
Here’s FOGINT’s take on the path Telegram is likely to follow:
- Freeing Pavel will be a top priority
- Amping up Telegram and the TON Foundation’s crypto activities. (Telegram is the platform for TON Foundation; the Foundation is the marketing and developer magnet for the TONcoin.)
- Provide functions and services like third party verification to show the French judiciary and others that Telegram does have “real” users and can provide investigators with some useful information maybe.
But the big priority after the “Free Pavel” action is crypto; specifically, making the Telegram platform the hub for crypto gaming and possibly some allied services like automating the movement of crypto from one coin and wallet to other wallets and coins. Tie ups with the Ku Group and other organizations providing crypto alternatives to traditional and regulated financial systems are on board and rolling out integrated services at this time.
Stephen E Arnold, January 2, 2025
FOGINT: TOMA Abandoning Telegram in Sharp U Turn
December 24, 2024
Observations from the FOGINT research team.
Pressure is building on Telegram’s vision for Messenger to become the hub for game crypto currency. Bitnewsbot published allegedly accurate information in “Popular Telegram Game Tomarket Ditches TON, Picks Aptos for Token Launch.” The article asserts:
Telegram-based gaming platform Tomarket announced it will launch its TOMA token on the Aptos blockchain network, abandoning initial plans to deploy on The Open Network (TON). The decision affects millions of users ahead of the December 20 token launch, marking a significant shift in the Telegram mini-app ecosystem.
One of the reasons given for the switch, according to Bitnewsbot, is the “speed and infrastructure capabilities” of Aptos’s blockchain network. The article continues:
The decision stands out as most Telegram-based cryptocurrency applications, including prominent names like Hamster Kombat and Notcoin, typically deploy on TON. The TON blockchain has seen substantial growth, currently ranking as the 16th largest cryptocurrency by market capitalization, according to CoinGecko with, a price increase of approximately 190% over the past year.
The online information service Decrypt.io adds some additional information which suggests that the Telegram infrastructure is not as supple as the Aptos offering; specifically:
Tomarket has handed out allocations of tokens across multiple airdrop waves, but players have been unable to withdraw or trade the token. The app’s developers previously said that the TOMA token was generated, but clarified afterwards that the term was used to describe token allocations within the app. And now, Tomarket won’t ultimately deploy to TON.
Decrypt.io reports:
Tomarket isn’t the first game to choose an alternative path, however: tap-to-earn combat game MemeFi recently launched its token on Sui, after pivoting from its original chain of Ethereum layer-2 network Linea.
The FOGINT team thinks that this Tonmarket abrupt change of direction may increase the pressure on Telegram at a time the organization is trying to wriggle free from the French red tape ensnaring Pavel Durov. Mr. Durov is on a legal tightrope. Defections like Tonmarket may spark some unpredictable actions by the Telegram collections of “organizations.”
Stephen E Arnold, December 24, 2024