Telegram's Durov Blames App Store Delisting on Extortionist Who Weaponized Group Chat Editing

Telegram founder Pavel Durov says the messaging app's brief removal from Apple's App Store was triggered by a "takedown extortionist" who planted AI-modified illegal content inside an active Telegram group chat and then flooded Apple with automated reports demanding payment. Durov laid out the allegations in a post on his X account Engadget.
The mechanism Durov described is narrow and specific. A malicious actor edited an old message already present in an active Telegram group chat so that it displayed what Durov called "AI-modified illegal content." Because the edit targeted an existing message rather than posting a new one, group members would not see the modified content surface in their feed and therefore had no opportunity to report it through Telegram's in-app moderation tools. The content sat undetected by the community it had been planted in.
The extortion scheme, as Durov characterized it, depended on scale. He alleged the actor planned to deploy a fleet of automated accounts to report the planted post to Apple, generating a volume of flags designed to trigger App Store review processes. The threat: pay up, or the reporting campaign continues. Whether Telegram received a specific ransom demand, and for how much, was not detailed in Durov's post.
Durov's account includes a pointed criticism of Apple's process. He said Apple removed Telegram from the App Store before contacting Telegram about the flagged content. The delisting, in other words, preceded any opportunity for Telegram to investigate, remove the material, or respond. Apple's App Review guidelines give the company broad discretion to remove apps that host illegal content, and the standard workflow typically involves reactive takedowns following user reports or automated detection.
The attack vector Durov described exploits a structural tension in how UGC platforms interact with app store gatekeepers. Telegram's group chats can host thousands of members, and message editing is a core product feature. An attacker who can quietly modify an old message in a large, semi-public group can create the appearance of a moderation failure that the platform's own community flagging system was never designed to catch in this form. When paired with coordinated mass-reporting to an external gatekeeper, the result is a takedown request that looks legitimate to Apple's reviewers but originates from the same actor who planted the content.
Durov himself framed the stakes in systemic terms. He said the incident creates "a potential systemic risk for every mobile app that hosts user-generated content." That claim, coming from the CEO of a platform with over 900 million monthly active users, extends well beyond Telegram's own situation. Any app that allows users to post, edit, or share content, and that distributes through Apple's App Store or Google Play, faces a version of the same exposure: a bad actor who understands both the platform's content mechanisms and the app store's reporting pipeline can weaponize the gap between them.
The attack does not require sophisticated exploitation of Telegram's codebase. It requires understanding two separate systems, the in-app moderation model and the App Store reporting workflow, and finding the seam between them. That is a lower bar than a zero-day or a infrastructure breach, and it is replicable across any UGC platform whose community reporting depends on users visually encountering content.
For platform security teams, the specific lesson is that message-edit functionality creates a moderation blind spot when the edit surface is not itself subject to the same visibility, indexing, or flagging pipeline as original posts. If an edited message does not re-surface in recipients' feeds, it will not generate community reports, and externally submitted reports referencing that content will appear to describe unmoderated violations. Telegram has not publicly detailed what technical changes, if any, it has made to its edit-visibility pipeline in response.
Worth flagging is the broader question this raises for app store governance. Apple's decision to delist before contacting Telegram suggests that the App Review process prioritizes rapid removal of flagged illegal content over coordination with the hosting platform. That posture is defensible from a child-safety or illegal-content standpoint. It also means that any actor who can manufacture a plausible violation, and generate sufficient report volume, can weaponize Apple's own enforcement pipeline as leverage. For developers of UGC apps, the implication is that app store distribution itself becomes an attack surface, mediated not by code vulnerabilities but by the trust relationship between platform, gatekeeper, and bad actor.
Durov's allegations remain just that, allegations from a single party with an obvious interest in framing the delisting as externally imposed rather than reflective of a moderation failure. Apple has not publicly confirmed or denied Durov's account of the sequence of events. What is verifiable is that Telegram was briefly delisted, restored, and that Durov has now described a coherent, technically plausible extortion mechanism that ties together in-app content manipulation and app store reporting abuse.


