Spain turns telegram into a 24-hour crime scene while durov cries surveillance
Spain’s security services are crawling through Telegram like electricians in a crawlspace, and every wire they touch hisses back. The platform that 22 % of last year’s scams call home is now erasing 500 000 channels a day—yet one in five of the vanished rooms still reek of stolen cards, hacked data and zero-day mercenaries. The government calls the cleanup HODIO, an AI nose that sniffs out “hate” in real time; Pavel Durov calls it a gag order wrapped in a dashboard.
Durov’s mass mail arrived in january
A single push notification to every Spanish handset: “You are entering a surveillance state.” The encryption evangelist timed the alert to beat the EU’s Digital Services Act, but Madrid answered by cranking the microscope tighter. Sources inside Moncloa tell TechBloom the new protocol is simple: flag once, crawl forever. If a channel mentions IBANs, CVVs or the word “fullz”, the crawler keeps a ghost copy even after the room disappears.
Check Point’s latest crawl is brutal. Three million invite links still float in the gutters of Russian-language forums, each URL a trapdoor back into Telegram. Discord barely reaches 6 % of that traffic; Signal, SimpleX and Matrix total less than 1 %. The cockroaches aren’t migrating—they’re renovating. A banned carding channel reopens 30 minutes later with a pineapple emoji instead of a handshake, and the same 40 000 users reappear under new burner SIMs.
The math is ugly. Telegram now nukes 50 times more rooms than it did last spring, yet the fraud share keeps climbing. SOC analysts say the platform’s new moderation API returns “actioned” within 200 ms, but the criminal bots repost faster than the JSON response hits their screen. Meanwhile, Revolut’s 2025 fraud ledger shows Telegram-linked scams up 38 % quarter-on-quarter, even as the company’s own anti-fraud engine tags the domain as “high-risk ephemeral.”

Inside hodio’s black box
The government won’t reveal the training corpus, but leaked slides show the model weighs 3 400 lexical markers mined from 60 000 takedown requests. A single message scored above 0.7 triggers a human review within 15 minutes; above 0.9 and the channel is throttled before the admin can blink. Critics warn the threshold is drifting: cryptocurrency channels discussing “mixers” have vanished, and last week a Catalan indie game dev lost his 12 000-member beta group because the AI misread “kill the boss” as incitement.
Durov’s answer is coded, not spoken. Engineers in Dubai push nightly builds that rotate channel IDs every 45 minutes and splice invite links into base64 haiku. The cat-and-mouse server costs have doubled Telegram’s AWS bill, yet venture funds still pour cash in—crime creates stickiness, and stickiness keeps the ad platform alive.
Spanish prosecutors are preparing a second sanction file, this time targeting personal liability of Telegram’s Dublin-based entity. The fine framework tops out at 4 % of global revenue, but the real weapon is criminal exposure: if judges accept that Telegram “consciously facilitated” scams, EU board members could face prison. The company has hired former Europol officers as lobbyists; their pitch is simple: “Arrest us and you lose the largest honeypot you’ve ever had.”
The scent of flux is unmistakable. In server rooms stacked outside Madrid, Guardia Civil analysts run mirrored Telegram nodes on air-gapped racks, logging every hash before it disappears. They know the platform will never be clean; the goal is to keep the criminals audible long enough to handcuff them in the real world. Telegram keeps burning the furniture to heat the house, but Spain just brought a flamethrower—and a warrant.
