Proposal: introduce an additional account security layer that applies temporary restrictions to newly connected devices for a period of 24–48 hours after login.
When a new device is added to a Telegram account, the system would automatically enforce a limited-access mode during the initial 24–48 hour window. In this period, the new device would be restricted from performing high-risk actions, including but not limited to:
deleting chats or message history;
transferring NFTs or digital assets to other accounts;
listing or selling digital assets;
modifying critical security settings (e.g., password, 2FA, recovery options, active sessions management).
All previously trusted devices would retain full functionality and remain unaffected by these restrictions.
Rationale: this mechanism would significantly reduce the impact of account compromise. Even if an unauthorized party gains access via a new device, they would be unable to immediately perform irreversible or high-value actions. This delay provides the account owner with a protective window to detect suspicious activity, revoke unauthorized sessions, and strengthen account security.
Overall objective: add a time-based risk control layer for new device trust establishment to improve resilience against account takeover scenarios.