NordVPN Promotion

Home / Blogs

Two Years After His Arrest, Pavel Durov Wants to Run His Own Registry

Telegram has applied to ICANN for .gram: a namespace that, if approved, could give ordinary users addresses like yourname.gram — and would put a platform whose founder faces an open French indictment, a Russian terrorism charge, and a nationwide ban in Russia in charge of running and policing that zone. As mid-September arrives, ICANN is due to announce when the public will see whether the application is even on the list.

On August 18, 2026, Pavel Durov posted 44 words to X. “Telegram has applied for the .gram domain zone,” it read. “If the application is approved by ICANN, a billion Telegram users could get their own second-level domains—yourname.gram. Users would be able to set up their interactive websites hosted by Telegram—with one prompt.” As of mid-September 2026, the post had tens of thousands of likes and several thousand reposts. Durov has not followed it with a second public filing detail.

That gap between the scale of the claim and the thinness of the record is the story. Everything that follows—the geopolitics, the abuse economics, the trademark exposure, the question of whether this becomes a template other platforms copy—sits on top of a single, unconfirmed tweet from a man ICANN’s own background-screening process will have to weigh against an open French indictment, a Russian arrest warrant, and a network backbone that investigative journalists say still touches Russian intelligence-linked infrastructure.

None of it is verifiable yet in the way it eventually will be. ICANN does not disclose who applied for what until “Reveal Day”—the moment it publishes the public-facing portions of every application that clears its administrative check. Until then, one industry blog put it bluntly: everyone is “arguing over shadows.” ICANN has said only that it will announce the exact Reveal Day date this month, in mid-September, with publication itself required no later than nine weeks after the application window closed on August 12—an outer boundary around mid-October. So as this piece goes to press, the identification of Reveal Day is genuinely imminent: within days or weeks, the shadows this story has been built on should start acquiring names, strings, and contention sets. Worth tracking now, before that happens, precisely so the record is straight once it does.

Figure 1: Pavel Durov’s original announcement on X, August 18, 2026.

Two domains, both called .gram, only one of them real

Before getting to what Telegram actually filed, it’s worth clearing up what it didn’t. Two months before the ICANN announcement, in June 2026, a domain called durov.gram was listed for sale on GetGems, the NFT marketplace built on Telegram’s own TON blockchain, at an asking price of $1.7 million. That listing referenced a genuine pattern of TON-native “domain” speculation—wallet.ton and casino.ton have sold at auction for $200,000 to $260,000, and a premium Telegram username fetched $2.4 million on the Fragment platform. But that .gram is an NFT collectible inside TON’s on-chain naming system, unrelated to ICANN and the global DNS.

The confusion is live, not academic. When Durov’s tweet broke, the Telegram channel GRAM ZONE Community—a hub for exactly this pre-existing NFT-domain market—posted its own reaction to over 5,900 views: Telegram’s promise of durov.gram-style addresses collides with the fact that “such addresses have long existed in the Gram DNS, and durov.gram was purchased there long before this application—for a substantial sum,” adding a hope that Telegram would, “in a civilized manner, buy back the legendary names from those who believed in Gram early” rather than simply overwrite them. Whether Telegram owes anything to a blockchain marketplace it has no formal relationship with is an open question, but the anxiety is real and telling: a constituency of early speculators has money riding on the assumption that the two “.gram"s are more connected than they legally are. Anyone doing due diligence on this story needs to hold the two apart—one is speculative crypto collectibles, the other is an application to control a piece of the actual internet—while noting that the market itself hasn’t fully made that distinction yet.

Figure 2: A GRAM ZONE Community post reacting to the announcement, illustrating confusion between the pre-existing TON-blockchain “.gram” market and Telegram’s ICANN application.

No confirmation, one rival bidder now visible on the record

ICANN has not verified that Telegram’s application exists; everything about it currently traces back to self-reporting. But two of the story’s loosest threads have since tightened considerably.

First, the rival bidder is no longer just a rumor. Link Freedom Group—the Malta-based operator behind Nova Registry’s .link, which filed the single largest application package in ICANN’s history (316 strings, roughly $71.7 million in fees)—lists .gram directly on its own public namespace browser, categorized under “Lifestyle,” phonetically spelled /græm/, tagged “small details, big impact,” with photo.gram, dia.gram, and weight.gram offered as illustrative second-level names. That’s a materially stronger basis for reporting the contention as real than the trade-press citations alone provided a few weeks ago, and it matters because the 2026 rules ban all private settlement of contention sets—if both applications survive to Reveal Day, .gram can only be resolved by ICANN-run auction, with a losing bidder forfeiting roughly $147,550 of the $227,000 evaluation fee.

Second, the identity of Telegram’s registry service provider has firmed up in a revealing way. Unstoppable Domains—reported as Telegram’s RSP since the original announcement—spent late August publicly abandoning its own web3 gTLD ambitions. On August 26, founder Matthew Gould confirmed the company would not submit ICANN applications for its own .crypto, .wallet, .nft, and similar extensions, concluding “the cost of taking web3 domains through ICANN in both compliance and application and bidding is higher than what we believe we’d recover in sales”—a retreat that triggered refund disputes with longtime holders. In the same week, Gould separately confirmed Unstoppable is still working with Telegram on .gram, continuing as a service provider for outside partners even while walking away from its own namespace push. The company building .gram’s technical backend has just told the market it doesn’t believe the web3-domain business case justifies ICANN for its own products—yet is proceeding anyway on Telegram’s larger, consumer-facing bet.

There is still no technical whitepaper behind any of this—Telegram has published no eligibility rules, pricing, or architecture for the actual gTLD. The public specification remains, functionally, one tweet plus now-visible fragments of its contractors’ and competitors’ own disclosures.

Figure 3: Link Freedom Group’s own namespace browser, listing .gram under its “Lifestyle” category—the strongest evidence yet that the Telegram/LFG contention is real.

Who actually decides, and what they’ll be reading

ICANN’s Board issues the final approval, but the substantive judgment is distributed across bodies the Board mostly ratifies rather than overrides. Independent contracted evaluators run financial and technical checks against fixed criteria. WIPO’s Arbitration and Mediation Center—now the sole provider for both Legal Rights Objections and String Confusion Objections in the 2026 round—issues binding expert determinations the Board doesn’t relitigate. The Governmental Advisory Committee, representing roughly 180 member states, can issue Early Warnings or Consensus Advice that carries, under ICANN’s bylaws, a strong presumption of deference from the Board. And background screening—run against what the Applicant Guidebook explicitly calls a “crimes of trust” standard borrowed from banking regulation—covers the applying entity plus its directors, officers, and major shareholders, checking for criminal history, sanctions exposure, and prior deceptive conduct. That last mechanism is the one worth sitting with, because for a Telegram application it is not hypothetical.

The file background screening will open

Durov’s public reputation was built on refusal. In December 2013, as CEO of VKontakte, he says he rejected an FSB demand for the personal data of Euromaidan protest organizers; in April 2014, refusing a second demand to shut down Alexei Navalny’s anti-corruption community, he was forced out and left Russia. A 2018 refusal to hand Russia’s FSB encryption keys triggered a two-year national ban on Telegram, lifted in 2020 only after what the company has always characterized as informal accommodation rather than capitulation.

What changed is the character of what Telegram refused next. Brazil suspended the app twice—in 2022 over disinformation orders, and again in 2023 when Telegram gave only “partial” data on neo-Nazi channels tied to school-shooting plots, Durov calling full compliance “technologically impossible.” India’s investigators said in 2019 that Telegram simply didn’t respond on ISIS-linked chats. Germany’s federal police told Der Spiegel many requests were “more or less ignored”—while Telegram’s own FAQ still claimed “0 bytes” disclosed to any government. That claim held until August 2024, when French police arrested Durov at Le Bourget Airport and indicted him on twelve charges, including complicity in distributing child sexual abuse material and drug trafficking, tied directly to the non-cooperation pattern. Weeks later Telegram reversed course, agreeing to disclose IP addresses and phone numbers “in response to valid legal requests”—after which disclosures to U.S. authorities alone reportedly jumped to 900 in 2024.

The French case remains open; Durov’s own description of his status is “I’m not on trial,” not “cleared.” A second front opened in July 2026, when Russia’s FSB charged him under its anti-terrorism statute—alleging Telegram failed to remove channels Ukrainian intelligence allegedly used to coordinate attacks inside Russia—and sought his arrest via Interpol on a charge carrying up to 15 years. Telegram’s official X account responded with a photograph of Durov giving the camera the middle finger. Russia had already fully blocked Telegram nationwide from April 1, 2026.

None of this automatically disqualifies the application; ICANN’s screening language appears built around convictions rather than open indictments. But it allows ICANN to weigh information “from any source,” including public comments, and gives at least two governments—France over the CSAM case, Russia over the terrorism charge, for unrelated reasons—a live incentive to file a GAC Early Warning against the same bid. A coordinated objection from adversaries who agree on nothing except that Telegram shouldn’t get this is one plausible outcome, and it illustrates a credibility tax: once an actor carries an open legal liability, every subsequent claim gets filtered through it, and the effect compounds when liability and announcement sit in the same domain. Telegram’s liability is a moderation failure; .gram is a bid for more infrastructure to moderate.

The precedent shelf

.gram would not be the first platform bid for a piece of the root zone. Google’s .google, .goog, and .youtube are live but restricted to Alphabet’s own staff—a closed dot-brand, the opposite of Telegram’s billion-user ambition. Automattic’s .blog is the closer analog: an open registry since 2016, now past 363,000 registrations, proving the mass-registrant model can work at a fraction of the scale Durov is describing.

The sharper cautionary tale involves a direct Telegram competitor. Tencent, operator of QQ and WeChat, applied for .weibo in 2012—only for Sina Corporation, owner of the real Weibo platform, to win a WIPO Legal Rights Objection arguing Tencent’s use would “inevitably impair the distinctive character” of Sina’s mark. Since the two were the only applicants, Sina’s 2013 win eliminated the contention set outright; .weibo now sits with Sina, restricted to its own use—a major messaging company knocked out of a gTLD entirely by a rights-holder objection, though “gram,” a generic dictionary word, is a harder target than “weibo” ever was. .amazon shows a geographic/cultural objection freezing a bid for seven years; .islam and .halal show ICANN’s Board rejecting strings on public-interest discretion even after objections failed on the merits; .wine shows GAC pressure without consensus isn’t enough to block anything. None map cleanly onto .gram, which is neither geographic, religious, nor tied to one obvious mark holder.

One brand-protection tool deserves more attention than the “watch out for brand.gram squatting” commentary is giving it: it already exists. ICANN’s Trademark Clearinghouse gives any recorded mark-holder a Sunrise period to claim its matching name before .gram opens publicly, plus ongoing infringement alerts after. The mechanism that stops a stranger from claiming paypal.gram is cheap and available now; the gap is that most brand teams don’t yet treat a Telegram-adjacent name as worth pre-registering—the same posture that let 1990s cybersquatters run wild on .com before Sunrise periods existed.

What a billion open doors actually invites

The security case doesn’t need to speculate; the base rate is published. Interisle Consulting’s Cybercrime Supply Chain study found new gTLDs hold roughly 12 percent of the domain market but account for 47 percent of all reported cybercrime domains. A separate Interisle analysis of 2025 registrations put malicious actors’ share of new gTLD registrations at 10 to 20 percent, warning explicitly “particularly since new open gTLDs will be introduced in 2027 and beyond.” .gram is precisely one of those.

What distinguishes .gram’s risk from an ordinary new gTLD is the delivery mechanism on top: a one-prompt fake page costs nothing to produce and inherits Telegram’s brand trust before any reputation system has built a signature for it. Mapping Telegram’s eight documented risk categories—moderation failure, phishing, the TON/GRAM crypto-scam ecosystem, jurisdictional non-cooperation, sanctions exposure, country-level blocking, founder-tied continuity risk, and eroded anonymity for high-risk users—against .gram’s architecture puts phishing and crypto-scam infrastructure in a category of their own: the only two risks positioned to compound rather than merely scale.

Figure 4: Author’s risk-growth mapping of Telegram’s documented risk categories under a proposed .gram architecture.

Where the servers would actually sit

Telegram’s infrastructure runs across five data centers—Miami, Amsterdam, Singapore—and any .gram hosting would likely extend that stack. But physical location and network control are separate questions, and the gap between them has just been independently tested. Reporting by iStories, first published in 2025, alleged that a Russian network engineer, Vladimir Vedeneev, controls much of Telegram’s actual IP infrastructure while maintaining an FSB handler under Russia’s SORM surveillance framework—Vedeneev is on record telling iStories: “They say: ‘So, we need this IP address at this time. Who is it?’ ... We quickly answer them.” Vedeneev disputed the characterization and sued in Switzerland—but the suit does not contest the underlying facts, only demands the interview’s removal. More significantly, an independent technical firm, Symbolic Software, later reviewed the claims (an audit Vedeneev himself reportedly submitted hoping it would refute them) and instead confirmed them: Telegram transmits a persistent, unencrypted device identifier that “creates a technical capability for device tracking by any entity with passive network access,” reproducible without any active attack. Telegram’s own response, attributed to a spokesperson named Remi Vaughn, calls the FSB link a “conspiracy theory” and states that no Vedeneev-linked company has served Telegram’s European/Russian data center since 2021. Both positions are now on the public record; neither has been independently adjudicated. What’s not disputed is that political hostility between Moscow and Durov has not obviously severed whatever technical dependency exists—the plumbing and the diplomacy are running on different clocks.

Moscow’s contradiction

That gap is worth dwelling on, because it inverts the assumption most coverage defaults to. Russia is not positioned to control .gram—it banned Telegram outright and charged Durov with terrorism facilitation, seeking extradition on a charge carrying up to 15 years. Any residual Russian relevance runs through two narrower channels: Roskomnadzor’s demonstrated willingness to block a namespace at the Russian border regardless of what ICANN decides globally, and the unresolved question of whether Vedeneev-linked infrastructure—a private commercial entanglement, not state control—persists underneath whatever Telegram builds next, independent of how hostile the political relationship becomes.

Why everyone else is watching

Google’s dot-brands and Automattic’s open .blog already proved platforms can hold pieces of the root zone; none tested Durov’s actual bet—that a billion ordinary users will treat a platform-issued, revocable subdomain as a meaningful identity. If it works, it’s a template: infrastructure independence (the lesson of the July 2026 t.me serverHold incident, when a sanctions-driven registry action took Telegram’s short links offline for 19 hours), platform lock-in, and a new revenue line in one filing. But the copying window is narrower than the interest—the prior round was 2012, this one’s application window is already closed, and any competitor deciding today it wants this model has no ICANN door to walk through for years.

That’s the note this story sits on as it goes to publication. ICANN’s own promised timeline puts a Reveal Day announcement in the days immediately ahead—meaning that by the time this piece reaches its second reader, some of what’s written here as “reported but unconfirmed” may already be settled fact, for better or worse, for Telegram and everyone circling it.

Figure 5: ICANN’s official 2026 Round timeline. Reveal Day—the point at which the Telegram/LFG contention becomes officially confirmed—is due imminently.

Disclosure: The author has no client relationship with Telegram, Pavel Durov, Unstoppable Domains, Link Freedom Group, Nova Registry, or ICANN.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By Mihaela Vata, Security and Intelligence Expert

Mihaela Vata is a security and intelligence expert with nearly 20 years of experience spanning national security, counter-terrorism, forensic intelligence, corporate investigations, and financial-crime risk advisory.

Visit Page

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

DNS

Sponsored byDNIB.com

DNS Security

Sponsored byWhoisXML API

IPv4 Markets

Sponsored byIPv4.Global

New TLDs

Sponsored byRadix

Domain Names

Sponsored byVerisign

Brand Protection

Sponsored byCSC

Cybersecurity

Sponsored byVerisign

NordVPN Promotion