Nekogram Dev Admits Collecting Phone Number Links
This morning things got spicy in the Telegram mod scene.
The developer of Nekogram basically admitted that the app collects info about which account is linked to which phone number. Someone (Sota) dropped the Extra.java code fragment, and a few hours later the dev himself said in his chat: “If your question is ‘Is it true?’, the answer is yes, numbers were sent to the bot.”
He followed up with something like “what kind of explanation do you need? It is exactly what it looks like; it is what it is.”
The dev claims no numbers were actually stored or shared with anyone, and that people might find that hard to believe. Honestly, yeah… it is kinda hard to believe without seeing the full picture.
There's also mention of the data going to some “breakthrough” bots, but he didn't really address that part. One of those bots even admitted Nekogram is using their TgDB search bot automatically (without their knowledge or partnership), probably to look up usernames.
If you're using Nekogram or any unofficial client, this is a good reminder to be careful what you connect. Privacy in mods is always a gamble.
Sources:GitHub - nekogram-proof-of-logging
TheBadInteger - Nekogram Phone Exfiltration