The Hidden Layer Behind Telegram's Mini App Explosion
Telegram Mini Apps have transformed the messenger from a communication tool into a full commercial platform. The numbers tell a story of explosive growth: Mini Apps grew from 2,388 to 8,923 between January and October 2025, while the number of bots surged from 9,297 to 58,482 . Rewarded ads now generate eCPMs of $12-35 in hypercasual games, with completion rates reaching 70-90% .
But beneath this growth lies a structural problem that ad networks and advertisers are only beginning to understand: the infrastructure layer of Telegram Mini Apps is largely invisible.
What Ad Networks Currently See
PropellerAds, RichAds, AdsGram, and Monetag have all built sophisticated anti-fraud systems. They detect bots, filter invalid traffic, score publishers, and monitor behavioral anomalies. PropellerAds explicitly states that Mini App advertising may be less exposed to traditional fraud because "ads are shown during real in-app activity rather than through channel inventory that can be artificially padded" .
RichAds has developed TMA-specific targeting, including options for "Telegram Premium subscribers only" and "users with positive TON wallet balance" . AdsGram advertises multi-layer anti-fraud against bots and dishonest impressions.
These systems work inside the advertising transaction. They answer: Is this impression valid? Is this click real? Is this user human?
What they do not answer is a different question: What is this Mini App? What infrastructure stands behind it? How has it changed over time? Is it related to previously observed risky publishers?
The Infrastructure Intelligence Gap
This is where MiniAppShield operates. Not as a competitor to ad network anti-fraud, but as an adjacent layer that observes the Mini App ecosystem at a structural level.
Consider what our Observatory has already discovered:
A complete K6 cluster: Six Telegram Mini Apps, each connected to every other through shared application-specific JavaScript hashes and API endpoints. Fifteen out of fifteen possible pairs. Sixteen shared JS artifacts and fourteen shared API endpoints per pair.
A GPT-focused K4 cluster: Four AI-related Mini Apps with thirty-nine shared JS artifacts per pair.
Two separate VPN triangles: Six VPN-related Mini Apps forming two independent infrastructure clusters.
These are not coincidences. They are technical fingerprints that reveal shared infrastructure behind different Telegram identities.
Why This Matters for Ad Networks
PropellerAds' own reporting acknowledges that fraud in Telegram has historically involved "fake channel metrics, cloned administrators selling ad placements, and bot-inflated audiences" . The company argues Mini Apps are less vulnerable because ads are served during real activity.
This is partially true. But it misses a critical scenario:
A banned Mini App can return under a new Telegram identity while maintaining the same backend infrastructure.
For an ad network, a new bot ID looks like a new publisher. For MiniAppShield, it looks like a reincarnation—the same domain family, same JS hashes, same API endpoints, same CDN buckets, same analytics IDs.
The network sees a new source. We see continuity with a previously observed risk.
The Time-Based Moat
Scanning Mini Apps can be replicated. Anyone can build a crawler and capture runtime data.
What cannot be replicated retroactively is historical infrastructure intelligence.
MiniAppShield currently tracks:
650+ Telegram Mini Apps
1,100+ historical snapshots
55+ exact technical relationships
Every relationship has an observation_count. Currently, most are at 1—a single observation. But as monitoring continues, these counts grow. A relationship observed across 6 snapshots over 3 weeks becomes something fundamentally different from a one-time detection.
This enables signal types that do not exist elsewhere:
Publisher Reincarnation Detection: Identifying when a previously banned Mini App returns under a new Telegram identity through shared infrastructure artifacts.
Monetization Drift: Detecting when a Mini App that previously served no ads suddenly integrates an ad SDK, adds rewarded video endpoints, or introduces external redirectors—signaling a pivot toward aggressive monetization.
Infrastructure Relationship Graph: Mapping hidden connections between seemingly unrelated Mini Apps, revealing clusters that operate as coordinated entities.
Top comments (0)