On Monday night, an app with over a billion monthly users stopped existing.
Not blocked by a government. Not taken down by a court. A company's review team found something they didn't like, pressed a button, and for about forty minutes Telegram was simply not available to download on any iPhone on earth.
Forty minutes. Then it came back, and almost nobody noticed.
I want to spend some time on it anyway, because the interesting thing here isn't what happened. It's what the forty minutes demonstrated — and it's a part of your threat model that I'd bet money you haven't thought about.
What actually happened
Let's do the facts fairly first, because there's a lot of very excited coverage on this one.
On the evening of Monday, August 3rd, at around 9:30 p.m. Eastern, Telegram disappeared from Apple's App Store. Apple's statement afterwards was brief: "We briefly removed Telegram from the App Store after our review found content that violates our strict guidelines prohibiting child sexual abuse material."
Telegram's account is narrower. They say Apple reported a single user sharing that material, and that user was immediately banned. Around 10:10 p.m. Eastern — roughly forty minutes later — the app was back.
Existing users were never affected. If you already had Telegram installed, nothing happened to you. It remained available on the Mac App Store and on Google Play throughout. This was new downloads only, and it was brief. (Coverage disagrees on scope: several outlets described it as worldwide, while Cybernews specified the US, Australia, India and Singapore.)
Credit where it's due on both sides. Apple acted on child abuse material, which is the correct thing to act on, and restored the app once it was dealt with. Telegram says it has removed more than 337,900 CSAM-related groups and channels in 2026 alone, on top of roughly 29,640 in 2025 acting on reports from bodies including the National Center for Missing & Exploited Children. Those are not the numbers of a company doing nothing.
On the narrow facts: a moderation failure, caught, fixed, over inside an hour. If that were the whole story I wouldn't be writing about it.
Durov's counter-story
The following day, Pavel Durov gave a very different account.
His claim is that the takedown was engineered. In his words: "Extortionists have found a way to manipulate Apple into overreacting." He describes a specific mechanism — that these groups use automated accounts to plant illegal content into public channels, then report that content directly to Apple, in order to trigger the removal of legitimate communities. And the reason, he says, is that the owners of those communities refused to pay them.
He also says Apple never contacted Telegram before pulling the app.
I want to be careful here, and I'd encourage you to be too.
That is an unverified claim from a man with every motive in the world to make it. Apple has not responded to it. No independent evidence has been produced. Durov is currently under legal pressure from three jurisdictions at once, and "we were set up" is a convenient story.
But the mechanism he describes is real and well documented. Report-bombing, false-flag uploads, weaponising a platform's abuse pipeline against a rival or a target — that isn't exotic. It happens on YouTube, on Twitch, across every large platform with an automated complaints system. Anyone who has run a community of any size has seen a version of it.
So the honest position is: unproven as a description of this incident, entirely plausible as a description of a real attack pattern.
And that's why it's worth raising. Because if the mechanism works, the takedown button isn't only reachable by Apple. It's reachable by anyone willing to plant content and file a report. That's a considerably wider door than the one everybody is looking at.
The part that actually matters
Here's the thesis.
For most of the world, two companies decide which software you are permitted to run on the computer in your pocket. Two. And one of them, on Monday, removed a billion-user communications platform from global distribution in the time it takes to watch a sitcom.
It was only forty minutes. Fine. But the length of the outage isn't the finding. The finding is that the button exists, that pressing it takes one decision inside one company, and that nobody outside that company gets a vote.
Consider what "removed from the App Store" actually does. It doesn't delete the app from phones that already have it. It stops new people from getting it. It stops updates, so the app can't even be repaired while it's delisted. And it stops all of that precisely at the moment a person is most likely to need it — because the moment people rush to install an encrypted messenger is usually the moment something has gone wrong in their country.
An outage that is harmless on a Monday night in August is a very different object on the night of an election, or a coup, or a wave of arrests.
This isn't hypothetical. We have the pattern already:
- 2018 — Apple removed Telegram over "inappropriate content."
- 2023 — Telegram removed in Brazil under a court-ordered ban.
- 2024 — Telegram removed in China at government request.
- 2024 — Apple removed at least 60 VPN apps from the Russian App Store, including NordVPN, ExpressVPN and Proton VPN.
- March 2026 — Russia began blocking Telegram around the 16th–17th; about ten days later Apple removed four more circumvention tools from the Russian store: Streisand, V2Box, v2RayTun and Happ Proxy Utility. These were the manual-configuration proxy clients people were using to route around deep packet inspection.
Durov's own reaction to that last one, back in the spring, was "that's not cool, Apple." Which is a gentler version of what I'd put more directly.
Apple is not the villain of this story. Apple is the chokepoint. Those are different things, and the difference is the whole point. A villain can be shamed into behaving better. A chokepoint is a structural fact — it will be leaned on by whoever has leverage over it, in whichever jurisdiction, for whatever reason is locally legal. Roskomnadzor asks and gets sixty VPNs. Beijing asks and gets Telegram. An anonymous extortion crew files a report and, if Durov is right, gets forty minutes.
The politics change. The chokepoint doesn't.

The practical shape of a takedown — and the five times the button has already been pressed.
The nuance most coverage is skipping
A correction to something you'll see repeated all week, because precision matters.
A lot of coverage is framing this as "Apple removed an encrypted messenger." Telegram is not, by default, an encrypted messenger — not in the sense that Signal is.
Telegram's ordinary cloud chats — the ones essentially everybody uses, the groups, the channels, everything that syncs across devices — are encrypted to Telegram's servers, and Telegram can read them. End-to-end encryption does exist on Telegram, but only in an opt-in feature called Secret Chats: one-to-one only, no groups, and rarely used.
I'm not raising that to score points. I'm raising it because it makes the story sharper, not weaker.
Everybody's threat model for a messaging app is about content — can someone read my messages. That's the question we all learned to ask. But this incident didn't touch content at all. Nothing was decrypted. Nothing was broken.
Somebody just made the app harder to get.
Distribution is a separate attack surface from encryption, and almost nobody has it in their threat model. You can have flawless cryptography and still be one policy decision away from your users being unable to install you. Signal has exactly the same exposure. So does every VPN, every Tor browser, every privacy tool on iOS — and the tools most likely to be removed are precisely the ones built to be uncensorable everywhere else in the stack.
That's the irony worth sitting with. We spent fifteen years hardening the transport layer. The distribution layer — the actual door people walk through to get the software — is still owned by two companies.
The week it landed in
This arrived in a very particular week for Telegram, and the context is worth stating factually.
On Wednesday July 29th, Russia's FSB charged Durov with aiding terrorism — carrying up to fifteen years — and placed him on the international wanted list, alleging Telegram failed to remove channels, chats and bots used by Ukrainian intelligence and by extremist organisations to coordinate sabotage, cyber fraud and armed attacks. Worth being precise: Durov is a Russian citizen, which is what makes this a Russian prosecution of a Russian national. He also holds Emirati, French and St Kitts & Nevis citizenship, and lives in Dubai. Telegram's official account responded by posting a photograph of him making a rather direct gesture. Earlier this year he said Russia was fabricating pretexts to restrict Telegram and "suppress the right to privacy and free speech."
On Thursday the 30th, Australia's eSafety Commissioner filed civil penalty proceedings in Federal Court, alleging Telegram left ten of twelve reported terror posts up between July and October 2025 and did not suspend the accounts that posted them. Three were already-known terrorist content. Maximum exposure is around A$54.6 million. Telegram says it rejects the allegations and will contest them in court, pointing to more than 153,000 terrorist-related communities blocked this year.
Durov also remains under indictment in France, and that case is routinely under-described as a dispute about cooperating with police. It's considerably heavier. He was charged in Paris on August 28, 2024 on twelve counts — including complicity in distributing child sexual abuse material, complicity in drug trafficking, organised fraud, money laundering, and providing cryptology services without declaration. Refusal to hand information to authorities is one count out of twelve. He faces up to twenty years. His travel ban was fully revoked in November 2025, no trial has begun, and he denies all of it.
Then, on Monday, Apple.
I'm not going to draw a line between those four things, because I have no evidence of one and neither does anyone else. And they are genuinely not equivalent: an authoritarian state that wants a messenger it cannot read is a different animal from a democratic regulator with a specific, documented complaint about twelve specific posts. I won't pretend otherwise.
But note the shape. Whatever the legitimacy of each pressure, they converge on the same target — and the fastest-acting lever in the entire set, the one that worked in forty minutes with no hearing, no filing and no appeal, was a private company's content review queue.
Courts are slow on purpose. App stores are fast by design. Guess which one gets used.

Three jurisdictions in five days. Only one of them moved in forty minutes.
So what do you actually do
Less than you'd like, and more than nothing.
On Android, you have a real answer. You can install apps from outside the Play Store. Telegram distributes its own APK directly, as do many privacy tools, and F-Droid exists for open source software. If Google delists something, there's a path. Verify what you download and check signatures — sideloading is a real capability with real risk attached, and "I grabbed the APK off a random site" is how people get compromised. But the capability is genuinely there.
On iOS, be honest with yourself: mostly you don't. In the EU, the Digital Markets Act forced Apple to permit alternative marketplaces, and several now exist — AltStore PAL, Aptoide, the Epic Games Store, Skich, Onside, and Mobivention for enterprise distribution. Japan opened up in February 2026 under its Mobile Software Competition Act, where Onside and AltStore PAL also operate. That's real progress and I don't want to be dismissive of it. But it is regionally limited, the catalogues are thin, and it isn't stable — Setapp Mobile, one of the more promising entrants, shut down in February because the business terms didn't work. If you're outside the EU or Japan on iOS, the App Store is the only door.
What helps wherever you are:
Install before you need it. Removals stop new downloads, not existing installs. The tool already on your phone survives a takedown. The one you were planning to get does not. If there's a messenger, VPN or browser you'd want in a bad week, put it on the device now, while it's boring.
Keep a second channel your people are actually on. Not a theoretical backup — a real one, with your real contacts in it, that you've used. A backup messenger nobody you know has installed is not a backup.
Know the web client. Most of these services have one, and browsers are far harder to remove from a device than apps are.
Keep at least one device in your life that isn't gatekept. A laptop, a spare Android, something where you choose what gets installed. Not because you'll need it tomorrow, but because the entire point of this story is that the button gets pressed without warning, and no appeal runs on the timescale you'd need.
What I'd take from this
Nothing terrible really happened on Monday. That's not me being glib — the app was gone for forty minutes, the trigger was genuinely serious content, and it was fixed. On its own terms, you could argue the system worked.
But every so often you get a demonstration. A moment where the machinery is briefly visible and you can see how much force sits behind a decision nobody voted on. Monday was one of those. One review queue, one guideline, one company, one billion users, forty minutes.
The lesson is not "distrust Apple." Apple removing child abuse material is Apple doing its job, and doing it quickly. The lesson is the one this site keeps arriving at from different directions: capability is what matters, not intent. A power that exists gets used — by whoever holds it today, and by whoever holds it, or can manipulate it, tomorrow.
We have spent a very long time arguing about whether our messages are readable. We've spent almost no time on whether we're allowed to install the thing that sends them.
Install the tools you'd want before you want them. And keep one door that isn't somebody else's to close.
— Simon
Sources & further reading
- Telegram briefly pulled from the App Store over child sexual abuse material availability — 9to5Mac
- Telegram Briefly Removed From App Store — MacRumors (Apple's statement, 40-minute timeline)
- Telegram Briefly Removed From App Store Over Alleged Child Sexual Abuse Content — Forbes
- Telegram's Durov says 'extortionists' pushed Apple to remove messaging platform from App Store — The National
- Why did Apple remove Telegram from the App Store? — Cybernews
- Apple Briefly Takes Telegram Off App Store Over Abusive Content — Bloomberg
- Why Was Telegram Removed From the App Store? — SOCRadar
- Russia charges Telegram founder Pavel Durov with 'aiding terrorism' — Al Jazeera
- eSafety commences civil penalty proceedings against Telegram — eSafety Commissioner
- Apple removes custom VPN clients from Russian App Store amid Telegram crackdown — TechRadar
- Move over, Apple: Meet the alternative app stores available in the EU and elsewhere — TechCrunch
- Pavel Durov's post — X