Durov prefers community based security audit https://telegram.org/blog/crowdsourcing-a-more-secure-future to third party expert security audit https://news.ycombinator.com/item?id=6950305. Even if I agree with him, I would be good to have both audits since this would increase telegram trust among users and reputation among cryptographic community.
Protocol: there is already a proof of formal correctness of MTProto v2.0 https://arxiv.org/pdf/2012.03141v1.pdf that requires further improvements (proof of IND-CCA and INT-CTXT properties).
Applications: ~
Edit: for instance other communication services have third party expert security audit protonMail/VPN https://protonmail.com/blog/android-client-security-model/, https://protonvpn.com/blog/open-source/ by SEC consult keybase https://keybase.io/docs-assets/blog/NCC_Group_Keybase_KB2018_Public_Report_2019-02-27_v1.3.pdf by NCC group Wire https://medium.com/@wireapp/wires-independent-security-review-61f37a1762a8 and https://medium.com/@wireapp/wire-application-level-security-audits-98324d1f211b by Kudelski Security and X41 D-Sec