cryptofoundry

Contact cryptofoundry

Tell us what you want to build or automate.

Article

Telegram’s Anonymity Hole: How to get any user’s phone number

ADAMANT MessengerFrom the foundry ↗
Telegram’s Anonymity Hole: How to get any user’s phone number

Telegram requires a phone number to begin messaging, binding all messages to a user’s identity. This mechanism is not only obsolete but introduces significant privacy risks. One such vulnerability allows anyone to obtain the phone number of a user in a Telegram group by exploiting the app’s contact synchronization feature.

To demonstrate, consider an open group chat where a target user, “Sergey Lebedev,” is visible.

Telegram’s Anonymity Hole: How to get any user’s phone number

By leaving the application and adding a new contact to the device’s native contact book with a guessed phone number, we can test if that number belongs to a Telegram user.

Telegram’s Anonymity Hole: How to get any user’s phone number

Next, ensure that contact synchronization is enabled in Telegram’s privacy settings (Settings — Privacy and Security). This feature automatically adds device contacts to the application if they are registered on Telegram.

Telegram’s Anonymity Hole: How to get any user’s phone number

If the guessed phone number is registered in Telegram, the application will add the user to its contact list. In this example, the guessed number was correct.

Telegram’s Anonymity Hole: How to get any user’s phone number

Telegram will then override the user’s display name with the name assigned in the device’s contact book. Returning to the original group chat, “Sergey Lebedev” is now displayed as “Testing Phone ID,” confirming the guessed phone number belongs to him.

Telegram’s Anonymity Hole: How to get any user’s phone number

While guessing a phone number out of millions seems impractical, attackers can significantly narrow the range using social engineering to determine the target’s country and carrier. Furthermore, a simple mobile application could automate adding large ranges of phone numbers to a device’s address book, making brute-force discovery feasible. This vulnerability poses a severe threat to user privacy, particularly for public figures, investors, and activists. Applications that mandate phone number registration often carry hidden privacy trade-offs.