Skip to content
Review

TENET: Telegram Mini App (in)security

Aug 2026 · 0 citations · 39 references
Computer Science

TL;DR

This work presents TENET, a purpose-built auditing tool whose design decisions are grounded in the structural properties of the secrets targeted and empirically validated against a ground-truth dataset, and proposes mitigation measures and best practices for both Telegram platform developers and third-party Mini App creators.

Abstract

Telegram, with over 450 million daily active users, has introduced Mini Apps---web-based applications running directly within its client. However, this integration introduces notable security risks. As we demonstrate, many Mini Apps store authentication materials---such as session tokens and wallet mnemonic phrases---in plaintext on client devices, exposing users to unauthorized access, impersonation, and financial exploitation. While insecure client-side storage is a known risk in web applications, the Telegram Mini App ecosystem presents a uniquely dangerous combination of factors absent from prior work: no platform-level security review, no storage access restrictions, a financially motivated user base handling live cryptocurrency assets, and a WebView environment that offers weaker protections than standalone browsers. To investigate this threat, we present TENET, a purpose-built auditing tool whose design decisions---pattern selection, entropy thresholds, and charset validation---are grounded in the structural properties of the secrets targeted and empirically validated against a ground-truth dataset. We screened 61 Mini Apps using a stratified, popularity-weighted sampling strategy based on popularity. Of the 37 applications that met our processing criteria and were analyzed, 30 exhibited security flaws, which we classify into three severity tiers: plaintext storage, recoverable encryption, and replayable tokens. Notably, even Telegram's official Wallet exhibits a severe vulnerability that may lead to full account compromise. Following our responsible disclosure, Telegram implemented two new secure-storage APIs, and our post-remediation verification confirmed that its official Wallet no longer exposes the recovery mnemonic in plaintext. Finally, we propose mitigation measures and best practices for both Telegram platform developers and third-party Mini App creators.

View source

Similar papers

Preprint Aug 2026

TeleGapper: On the (un)reliability of Privacy Policies in Telegram Mini apps

TeleGapper, a black-box dynamic analysis framework, is presented, a black-box dynamic analysis framework to assess the privacy posture of Mini Apps by capturing runtime network traffic, identifying third-party communications, and comparing observed data flows against disclosed privacy information.

Luca Ferrari, Mariano Ceccato, Luca Verderame · 0 citations
Open access Jul 2026

Transition to Password-Free and Phishing-Resistant Authentication in Enterprise Information Systems: A FIDO2/Passkey-Based Standards-Based Qualitative Assessment and Phased Implementation Framework

This passkey approach is distinctively architecturally more secure against phishing owing to its root binding, public-key cryptography and authenticator domain and proposes Enterprises five-phase migration.

Oğuzhan Kilim · 0 citations

This paper is

This paper presents PreAcher, a system architecture that incorporates third-party Content Delivery Networks (CDNs) into the password authentication process and offloads the authentication workload to CDNs without divulging the passwords to them.

Shihan Lin, Yunming Xiao, Aleksandar Kuzmanovic et al. · 0 citations
Open access 2026

Development of a Raspberry Pi-Based Secure USB Passthrough System to Mitigate Bad USB Keystroke-Injection Attacks

A low-cost USB passthrough system that operates independently of host-side security software, using a Raspberry Pi 4 as an intermediary security layer between a keyboard and a host computer is developed.

Muhammad Alif Nukman bin Nor Azman, N. M. Salleh, S. R. Selamat et al. · 0 citations
Open access Aug 2026

Implementation of a Security Risks Model in Mobile Money Transactions Using a PIN Attempt Monitoring Algorithm

Mobile money platforms have revolutionized financial inclusion across developing economies, yet they remain highly vulnerable to sophisticated, automated credential-stuffing and unauthorized access attacks. Traditional static PIN authentication mechanisms often fail to balance robust security with user experience, leav...

Kazeem O. N., Umar Yahaya, Abdul Kareem Jimoh Mayaki et al. · 0 citations
Review Open access Sep 2026

Ranljivosti pri implementaciji standarda WebAuthn

The WebAuthn standard enables passwordless authentication using asymmetric cryptography and addresses several well-known vulnerabilities of traditional password-based authentication. Despite the formally proven security of the standard itself, practical implementations often contain server-side flaws that allow authent...

Sven Ulčar, Matevž Pesek · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.