Proposal: introduce an additional account security layer that applies temporary restrictions to newly connected devices for a period of 24–48 hours after login.
When a new device is added to a Telegram account, the system would automatically enforce a limited-access mode during the initial 24–48 hour window. In this period, the new device would be restricted from performing high-risk actions, including but not limited to:
deleting chats or message history;
transferring NFTs or digital assets to other accounts;
listing or selling digital assets;
modifying critical security settings (e.g., password, 2FA, recovery options, active sessions management).
All previously trusted devices would retain full functionality and remain unaffected by these restrictions.
Rationale: this mechanism would significantly reduce the impact of account compromise. Even if an unauthorized party gains access via a new device, they would be unable to immediately perform irreversible or high-value actions. This delay provides the account owner with a protective window to detect suspicious activity, revoke unauthorized sessions, and strengthen account security.
Overall objective: add a time-based risk control layer for new device trust establishment to improve resilience against account takeover scenarios.
This proposal is highly justified and crucial at the moment. Nowadays, scammers are increasingly deceiving people to access their accounts and steal their assets, or deleting accounts entirely using phishing bots. If this proposal is implemented, it would provide significant utility and enhanced technical security for a vast number of users.