At 7:24:55 p.m. UTC on July 13, 2026, the WHOIS record for Telegram's t.me domain changed. Eight EPP status flags — including serverHold — appeared simultaneously, removing the domain from the global Domain Name System. For 19 hours, every t.me short link on earth stopped resolving: channel invit...
"Hey @domainME, t.me links stopped working. Can you look into it?" — Pavel Durov, Telegram CEO, via X (July 13, 2026)
At 7:24:55 p.m. UTC on July 13, 2026, the WHOIS record for Telegram's t.me domain changed. Eight EPP status flags — including serverHold — appeared simultaneously, removing the domain from the global Domain Name System. For 19 hours, every t.me short link on earth stopped resolving: channel invites, bot addresses, mini-app URLs, group joins, and TON wallet links all returned browser errors.
The cause was a U.S. Treasury OFAC sanctions filing against First VPN Service (1VPNS), a Dnipro, Ukraine-based VPN provider that had sold anonymizing infrastructure to ransomware operators. Buried in the SDN listing was one identifier: t.me/FirstVPNService, a Telegram channel address. Identity Digital, the U.S.-headquartered company operating the .me registry backend, applied a serverHold to the entire t.me domain — not to the specific URL — because, according to DomainME, no technical mechanism existed at the registry level to block a single path on a domain.
The result: a sanctions action targeting a VPN service that had received $715 from the Anubis ransomware group knocked 1 billion monthly active Telegram users offline from every t.me-routed service, and severed the primary consumer on-ramp into a $4.3 billion token ecosystem.
The timeline is precise. At 7:24:55 p.m. UTC on July 13, the .me registry updated t.me's WHOIS record with eight status flags: serverHold, clientDeleteProhibited, serverDeleteProhibited, clientTransferProhibited, serverTransferProhibited, clientRenewProhibited, clientUpdateProhibited, and serverUpdateProhibited. The serverHold flag is the operative one — it instructs DNS root servers to stop resolving the domain entirely.
The domain remained registered under GoDaddy.com, LLC as registrar, with a creation date of 2010-05-20 and an expiry date of 2035-05-20. Non-renewal was not the cause. The registration was intact; the domain was administratively killed.
Telegram's messaging application itself continued functioning through direct IP-based connections and its primary telegram.org domain. Users who manually replaced "t.me" with "telegram.me" in any URL also retained access, since telegram.me was not listed in the OFAC SDN filing and was never placed on hold. But the vast majority of Telegram's public-facing web infrastructure — channel links, username handles, invite codes, bot addresses, mini-app URLs — routes through t.me.
Pavel Durov, Telegram's CEO, appeared to learn about the outage in real time. He posted on X tagging the .me registry directly, suggesting Telegram received no advance notice. The domain was restored approximately 19 hours later, on the afternoon of July 14. DomainME confirmed the hold had been placed "due to OFAC compliance" and stated it was "back online now."
On July 13, 2026, OFAC designated two individuals and one entity under its ransomware-enabling infrastructure sanctions program. The targets: First VPN Service (1VPNS), a VPN provider operating since 2014 on criminal dark-web forums; its administrator Dmytro Rashevskyi (Dnipro, Ukraine); and Yevgeniy Vladimirovich Silayev, a Belarusian national selling "cryptors" — tools that disguise malware to evade detection.
According to TRM Labs, ransomware groups including Anubis had sent a total of $715 to FirstVPN across two payment windows: December 13, 2025, and March 15-16, 2026. The action followed a May 2026 takedown of 1VPNS infrastructure by European law enforcement, supported by the FBI's Boston Field Office.
Within the SDN filing, OFAC listed several identifiers for 1VPNS, including a Telegram channel: t.me/FirstVPNService. This is standard practice. OFAC routinely lists websites, email addresses, and social media handles as identifying information for sanctioned entities.
The problem: Identity Digital, the U.S.-headquartered registry backend operator for .me, interpreted the listing as creating a compliance obligation over the entire t.me domain. OFAC's civil enforcement operates under a strict-liability standard — U.S. persons and entities with a U.S. nexus face penalties for any facilitation of a transaction involving a Specially Designated National, regardless of intent or knowledge. The registry had no technical mechanism to block a single URL path (t.me/FirstVPNService) while leaving the rest of the domain functional.
The result was a domain-level kill switch applied to a domain serving over 1 billion users, because one sanctions listing mentioned a single channel URL.
The t.me outage did not break the TON blockchain itself. Validators continued producing blocks. Smart contracts continued executing. But it severed the primary distribution channel through which users access TON-based services.
Key TON ecosystem metrics at the time of the outage:
Telegram's Wallet, mini-apps, and collectible usernames all depend on t.me links as their primary distribution and onboarding mechanism. According to Cryptopolitan, the outage "cut off the main consumer on-ramp into a roughly $4.3 billion token ecosystem." TON mini-apps, which generated over $1 billion in transaction volume in 2025, rely on t.me sharing links for viral distribution.
The token price impact was muted. GRAM recovered to $1.62 by July 14, up 1.29% over 24 hours. The brevity of the outage (19 hours) and the fact that the core messaging app remained functional likely contained the damage. But the incident exposed a structural dependency: an ecosystem built on decentralized blockchain infrastructure is accessed almost entirely through a centralized domain name routed via a U.S.-regulated registry.
The t.me incident is a case study in what security researchers call the "Web2 basement" problem — the layer of traditional internet infrastructure that sits beneath purportedly decentralized Web3 applications.
The TON blockchain runs on a distributed validator set. Its smart contracts are permissionless. Its token transfers are censorship-resistant at the protocol level. But users reach all of it through Telegram, and Telegram's public link infrastructure runs through a domain name governed by ICANN policy, registered through a U.S.-based registrar (GoDaddy), operated by a U.S.-based registry backend (Identity Digital), and subject to U.S. Treasury enforcement actions.
This is not unique to TON. According to DomainSure research, most crypto and Web3 projects "focus their security on smart contracts, wallets, and protocol layers," while their domain name and DNS infrastructure "still relies on Web2 infrastructure." DApps largely run on centralized data hosting platforms — AWS, Google Cloud, Microsoft Azure — which are susceptible to single-point failures.
The difference with TON is scale. No other blockchain ecosystem routes its primary user access through a single messaging platform's shortlink domain. Ethereum users access dApps through diverse front-ends. Solana protocols operate independent websites. TON's distribution model — embedded within Telegram — concentrates access through a single DNS chokepoint.
The legal question at the center of this incident: does a URL in an OFAC SDN filing create an obligation to block the entire domain on which it resides, or only to prevent that specific URL from facilitating the sanctioned entity's activities?
OFAC has published no specific guidance on this scenario. The strict-liability framework creates a powerful incentive for over-compliance. Identity Digital, as a U.S. entity, faces potential civil penalties for any facilitation of sanctioned-party activity. Given the absence of a technical mechanism to block a single path on a domain at the registry level, the conservative choice — and the one Identity Digital made — was to block the entire domain.
This creates an asymmetry: a sanctions designation targeting an entity that listed a $715 ransomware customer's Telegram channel address as a contact point resulted in a 19-hour global outage affecting 1 billion users and a $4.3 billion token ecosystem.
The .me top-level domain is nominally Montenegro's country-code TLD, but it has long been commercially operated as a generic domain. Identity Digital handles the technical backend under a contract with the Montenegrin government. The commercial nature of the arrangement means it falls squarely under U.S. jurisdiction for sanctions purposes, regardless of Montenegro's sovereign status over the TLD.
For domain registries: The incident establishes that a single URL in an OFAC SDN filing can trigger a domain-level hold, even when the sanctioned entity is a minor user of a platform with over 1 billion accounts. Registries operating under U.S. jurisdiction now face a compliance precedent with no published OFAC guidance on proportionality.
For Telegram and TON: The 19-hour outage demonstrated that the entire TON ecosystem's consumer access layer depends on a single domain name. Telegram's fallback — telegram.me — functioned throughout, but lacked the link density and user awareness to serve as a meaningful alternative. Any future registry-level action against t.me would produce an identical outcome unless Telegram diversifies its link infrastructure.
For Web3 broadly: The incident underscores the gap between protocol-level decentralization and access-layer centralization. A blockchain can be permissionless, but if users reach it through a centralized domain governed by a single country's sanctions regime, the censorship resistance of the underlying protocol is functionally irrelevant for the majority of users.
For OFAC: The unintended collateral damage raises questions about whether sanctions compliance frameworks need updated guidance for shared infrastructure. A domain name is not analogous to a bank account — it is shared infrastructure used by billions of unrelated parties. The current framework provides no mechanism for proportional enforcement at the infrastructure level.
The t.me domain suspension is, measured by user impact, one of the largest unintended consequences of a U.S. sanctions action on internet infrastructure. A filing targeting a VPN service that received $715 from a ransomware group knocked over 1 billion users off a core web service for 19 hours and temporarily disconnected a $4.3 billion token ecosystem from its primary distribution channel.
The technical fix took 19 hours. The structural problem remains. TON's entire consumer access layer routes through a single domain governed by a U.S.-regulated registry. The blockchain itself is decentralized; the door to it is not. Until either OFAC publishes proportionality guidance for shared infrastructure, or platforms like Telegram diversify their link infrastructure beyond single-registry dependencies, the t.me incident is a template for future disruption — not an anomaly.
The economic value at stake is real: $770 million in on-chain stablecoins, $150 million in DeFi TVL, 100 million activated wallet accounts. The infrastructure protecting that value — a single DNS record — is not.