Telegram wants .gram: what happens when criminal infrastructure leaves onions for platform-controlled DNS
On August 18, 2026, Pavel Durov announced that Telegram had formally applied to ICANN for its own top-level domain: .gram. Under the proposal, every Telegram username becomes a resolvable web address - @paypal would point to paypal.gram - with an AI-generated landing page rendered automatically at each one. Durov framed it as democratizing web publishing. Security researchers immediately framed it differently: as the largest single expansion of brand-impersonation surface in years, built on infrastructure Telegram itself controls.
What .gram actually changes
The mechanics are straightforward. ICANN's latest gTLD round lets large organizations operate their own registries, and Telegram is applying to become the registry operator for .gram. Because Telegram already owns every username on its platform, it can mint domains at platform speed and revoke them the same way. As coverage by SOCRadar explains, the AI-generated site layer means a scammer who registers @legit-wallet-support gets not just a messaging handle but a plausible-looking website impersonating that brand, with no hosting arrangement, no registrar, and no separate identity trail. Brand-protection teams have spent two decades fighting typosquats across hundreds of TLDs. A registry where the namespace is allocated from an existing username pool collapses that fight into a single chokepoint - feature or bug, depending on how much you trust the operator.The t.me suspension was the preview
The application did not land in a vacuum. In July 2026, the .me registry placed t.me itself on serverHold after OFAC sanctions listed a channel operating as VPN-service infrastructure. For roughly 19 hours, every t.me short link on the internet stopped resolving - support pages, news outlets, bot handoffs, everything built on the platform's addressing layer. TechCrunch documented the restoration after the day-long suspension of the domain, noting that a single administrative action by one registry had silenced links used by close to a billion people. That episode is worth sitting with. The stated target was one channel. The blast radius was the entire short-link namespace, because DNS delegation works in whole branches. When the same organization operates both the messaging layer and the naming layer, a sanctions designation aimed at one account can take down the addressing for all of them.The numbers behind the concern
Skeptics of the impersonation argument point out that new gTLDs remain a minority of the domain market. That is true - they hold roughly 12% of registered domains - but abuse does not scale with market share. The Interisle study of the cybercrime supply chain found that newer TLDs account for nearly half of reported cybercrime domains, a disproportionate concentration the authors tie to cheap bulk registration and lax registry oversight rather than anything inherent to the name strings themselves. A registry operated as a feature of a chat app adds a novel variable to that equation. Allocation is tied to platform identity policies rather than domain-industry contracts, revocation is instant and opaque, and there is no historical precedent for how a messaging company arbitrates between legitimate users and impersonators at registry scale.Why this matters to Tor users specifically
Here is the part relevant to anyone tracking onion services. For years, the underground has been migrating in one direction: away from standalone onion sites toward platforms. Markets keep vestigial onions but do their real business in channels, bots, and invite-gated groups reachable through clearnet gateways. The onion address survives mostly as a trust anchor - a way to verify which platform link is real. .gram accelerates that drift. If a market's @handle resolves to a live, HTTPS-fronted site with AI-generated content, the operational incentive to maintain onion infrastructure drops further. Criminal presence consolidates onto naming infrastructure that is simultaneously more convenient and more fragile: subject to registry holds, sanctions designations, and unilateral platform enforcement in ways onion services structurally cannot be. The irony is sharp. Onion addresses were despised precisely because nothing above them could intervene - no registry, no hold, no takedown. The platforms users fled to for convenience have rebuilt every one of those intervention points, and now they are extending them into DNS proper.What trackers should watch
For onion status trackers like ours, the practical consequences arrive in stages. First, expect more "official link" churn as services announce gram-style addresses; our guidance on onion lookalike domains applies with even greater force when a lookalike comes with a working website attached. Second, expect status signals to get noisier - when a service's availability depends on a t.me or .gram resolution path, an outage may be a registry hold rather than a hidden-service failure, and reporting it as downtime misleads everyone.- Track the onion address as the canonical liveness signal; treat gateway and short-link outages as separate events.
- Log the distinction explicitly so users can tell censorship from collapse.
- Expect impersonation campaigns to exploit transition periods, when communities argue about which address is current.
- Watch ICANN's evaluation of the .gram application - objections from brand owners will shape whether it proceeds at all.