Telegram Desktop Local Session Reuse: a Reproduction That Should Not Have Happened
A macOS stealer can copy Telegram Desktop's tdata directory and Telegram for macOS's local session files to another machine, restoring the logged-in state without triggering phone verification, SMS codes, or 2FA. An honest account of the discovery and the cognitive shift from 'this shouldn't happen' to 'but it does.'