HushTelegram is a Morphe patch bundle for Android that takes the sponsored messages out of Telegram and keeps a few things on your phone that Telegram would otherwise send home.
The latest release is v0.0.8, with 22 patches. They're built for Telegram 12.10.6 and the official beta 12.10.7, and on a signed-in phone Hide ads took a live search ad off the screen. See the before and after.
v0.0.8 adds official beta support, a Firebase certificate-header repair and a switch that stops a pull at the bottom of a channel from opening the next unread one. Two optional patches take your own registered Telegram API credentials and Google Maps key when you patch. With its own registered API ID, a Samsung phone that Telegram had turned away signed in normally.
Add to Morphe | Download a release | Browse the patches
- Channels and search without sponsored posts. Telegram never asks for them, so none are drawn, counted as seen or reported as clicked. That covers the sponsored accounts pinned above search results and the ads in its video player too.
- Usage reports stay on your phone. When Telegram's server requests its storage-type statistic, the patch stops that report. It also stops channel read-time reports and Premium interaction telemetry. Billing callbacks and operational reports keep their usual behavior.
- No update offers that can't work. telegram.org's build offers its own updates, and those can't install over a patched app. That offer is switched off, so you update through Morphe Manager instead.
- Controls that recover. Every feature has a switch, and there's a pause, settings backups and privacy-filtered diagnostics for when Telegram changes.
HushTelegram is the Telegram member of a small family of patch bundles. Its settings screen, diagnostics and release checks come from its Threads sibling, HushThreads. The Telegram patches are written here. See Where the patches come from.
This project has no connection to Telegram or to the Morphe project. Neither endorses it, and neither wrote it.
HushTelegram patches the Telegram you download from telegram.org, package org.telegram.messenger.web, version 12.10.6 (version code 71129). That APK carries every phone architecture, and it's the build each patch is checked against. Morphe Manager warns about other builds.
Since v0.0.8 it also targets the official beta, package org.telegram.messenger.beta, version 12.10.7 (version code 71159). Its vendor signer and native patch targets are checked on their own.
The other Telegram, org.telegram.messenger, shares nearly all its code with this one. Support for it is planned once it has its own checked build.
The patched app requires Android 9 or newer. A build that loses one ad or usage-report hook names the missing coverage in its settings and diagnostic report.
Changed Premium report builders are refused before the patch changes any code.
- Install Morphe Manager 1.33.0 or newer.
- Add HushTelegram as a patch source: https://morphe.software/add-source?github=SysAdminDoc%2FHushTelegram
- Get Telegram 12.10.6 from telegram.org/android by tapping Download Telegram. Skip the Google Play link, which installs a different package. The download saves as plain
Telegram.apk, with no version in its name. - In Morphe Manager, pick that file, keep the default patch selection or change it, and patch.
Android accepts an update only when it carries the installed app's signing key. Use your retained Morphe key to update an existing patched Telegram in place. Its data and permission choices stay intact.
Moving from stock Telegram needs a deliberate migration because the signing keys differ. Keep a signed-in fallback on another device and save any important local files before removing stock Telegram yourself. Removing it permanently deletes this phone's local secret chats. Cloud chats return after a successful sign-in, but secret chats can't be recovered that way. Verify that you can sign in before giving up your only working installation.
Morphe Manager signs the patched Telegram with a key it makes on your phone. Android installs an update over your patched Telegram only when the update carries that same key.
- Back it up right after your first patch. In Morphe Manager, open Settings, then System, then Import & export, then Signing key, and tap Export. Keep the
Morphe.keystorefile somewhere private, because anyone who has it can sign an APK your phone will accept as an update. - On a new phone, import it before you patch anything. Without your exported copy, nothing you patched earlier can be updated in place.
The developer installation script requires the exact device serial, expected model (and AVD profile for an emulator), shared lease directory, owned lease token and chat identity. Supply -LeaseDirectory, -LeaseToken and -ChatIdentity, or their HUSHTELEGRAM_DEVICE_LEASE_DIR, HUSHTELEGRAM_DEVICE_LEASE_TOKEN and HUSHTELEGRAM_DEVICE_CHAT environment variables. It checks ownership before every device command and verifies the installed signer and version before updating. It never uninstalls the app, grants permissions or permits a downgrade. The old -Replace option is refused. A first install also verifies an unambiguous package absence before changing the device.
The source catalog has 25 patches, with 23 selected by default. The three new local controls below are unreleased. A few of their switches stay off until you turn them on in settings, like tracking cleaning and draft link previews. The two credential patches need your own values and aren't selected by default.
| Patch | What it does |
|---|---|
Disable analytics |
Stops Telegram sending its storage-type statistic and how long you spent on each channel post to its server. Also stops reports about Premium screen views, feature taps, accepts and purchase failures. Messages and calls work as before. |
Disable update checks |
Stops telegram.org's Telegram offering its own updates, which can't install over a patched build. Patch the new version in Morphe Manager instead. |
Disable call debug upload |
Stops automatic call debug reports and log-file uploads requested by Telegram's server. |
Disable draft link previews |
Adds a switch, off by default, that stops Telegram fetching link previews for messages you haven't sent yet, in chats, the share sheet, polls, story links and bot shares. Sent messages still get their preview. |
Gallery camera on tap |
Adds a switch, off by default, that keeps the attachment gallery from starting the camera or asking for camera access when it opens. Tapping the camera tile starts it. |
Hide ads |
Hides the sponsored messages in channels, the sponsored accounts in search and the ads in Telegram's video player. Telegram never asks for them, so none are counted as seen. |
HushTelegram settings |
Adds a HushTelegram row to Telegram's Settings. You can also long-press Telegram's launcher icon, or open Additional settings in the app on Telegram's App info page, to turn features on or off, pause HushTelegram, save your switches to a file or load them, and export diagnostics. The licenses are there too. |
Hide Stories |
Hides the chat-list story bar, avatar story rings and Post Story button, and stops fetching the story list. Profile stories and archives remain available. |
Hide recommendations |
Hides similar channels and bots, including cached recommendations. Telegram doesn't ask for new recommendations while the switch is on. |
Hide Premium, gifts and Stars |
Hides Premium, Stars, My Grams, Business and Send a Gift in Settings, profile Gifts tabs and the channel Gift button. Purchases and account controls keep their usual behavior. |
Hide promotional banners |
Hides Premium, birthday and low Stars balance banners in the chat list. Account security notices and other suggestions remain. Nothing is dismissed for you. |
Hide sponsored proxy channel |
Hides a proxy's sponsored channel from the chat list and folders. Leaves proxy settings and shared promo-data updates alone. |
Hide popular apps |
Hides the Popular apps list in search's Apps tab and stops Telegram from asking its server for it. Apps you've opened and other search results stay. |
Disable chat swipe actions |
Adds a switch, off by default, that stops a sideways swipe on a chat in the chat list from archiving, muting, pinning, deleting or marking it read. A swipe set to change folders still does. Long-press keeps every action. |
Disable pull to next channel |
Adds a switch, on by default, that stops pulling past the bottom of a channel from opening the next channel. Scrolling, opening channels directly and pulling between forum topics still work. |
Use normal paste |
Adds a switch, off by default, that pastes text with Android's plain-text action. Whitespace and URLs stay intact without Telegram's HTML, table or monospace conversion. Other clipboard actions stay available. |
Show user and chat IDs |
Adds a switch, off by default, that shows a copyable local user or chat ID in the inspected profile's menu. It doesn't expose access hashes or ask Telegram's server for anything. |
Disable double-tap reactions |
Adds a switch, off by default, that stops reactions from a double tap in chats and the reaction-settings preview. Scrolling, taps, selection and explicit reaction menus keep their usual behavior. |
Repair Firebase push registration |
Restores Telegram's official certificate header in Firebase Installations requests on re-signed builds. Other signature checks keep their usual behavior. |
Use registered Telegram API credentials |
Uses the API ID and hash registered for your application at my.telegram.org. Supply both patch options. Leaving both unset keeps the original credentials. |
Use registered Maps API key |
Uses your Google Maps Android SDK key, authorized for Telegram's package and the installed signer. Leaving the option unset keeps the original key. |
Quiet contacts nag |
Keeps the Contacts tab from asking for contacts access again, and clears its warning badge, once you've said no. The first request, the tab's own buttons and contact sync stay as they are. |
Holiday look all year |
Adds a switch, off by default, that puts a Santa hat over the chat list logo and keeps Telegram's New Year snow falling all year over the chat list's top bar and chat backgrounds. Telegram's own holiday dates apply while it's off. |
Open links externally |
Opens ordinary HTTP(S) links in your browser. Telegram links, login, payment and authenticated routes keep their existing behavior. |
Strip link tracking |
Optional local cleaning at link-open and Share Link chooser sites. Removes only utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid and fbclid. Any unknown query key preserves the entire URL. Off by default in settings. |
The same search on the same phone, first with Hide ads off, then on. Telegram pins a sponsored account above the results for a lot of searches. With the switch on it never asks for one, so there's nothing to show and nothing to count as seen.
Open Telegram's Settings and tap HushTelegram settings. You can also long-press the Telegram icon and tap HushTelegram, or open Telegram's App info page and tap Additional settings in the app, which Samsung phones call Configure in Telegram. The launcher and App-info entries remain available if the native settings surface is absent.
More settings has separate pages for Pause, Settings backup and Diagnostics. Search finds each control by its name or page. Your saved switches and backup files work as before.
v0.0.8 adds a Notifications page and the channel-pull switch. Both are shown below.
Telegram's push notifications go through Google's Firebase. Its Android API key checks the package and certificate header, so a re-signed build can get API_KEY_ANDROID_APP_BLOCKED before it receives a push token. Repair Firebase push registration fixes only that header on Firebase Installations requests from the declared web and beta packages. It preserves Android's package signatures and TLS checks.
The Notifications page also shows what this phone knows about push. It says whether notifications are allowed and whether Telegram has saved a push token, then counts your signed-in accounts and how many of them Telegram has confirmed for push. It only reads what's already on the phone. It doesn't send anything, and it can't tell you whether a notification will actually arrive. The diagnostic report carries the same facts, without the token itself.
Push delivery also depends on Telegram's server holding push credentials for the app's Firebase project, which Telegram documents separately. A new API ID and hash don't set that up on their own. Telegram has its own fallback for this. Under Settings, Notifications and Sounds, turn on Keep-Alive Service and Background Connection to keep its connection open. That costs some battery.
The location picker uses a separate Google Maps credential, restricted to the installed package and signer. Select Use registered Maps API key and supply apiKey from a Google Cloud project with the Maps SDK for Android enabled. Its Android restriction must allow the selected web or beta package and your retained signing key's SHA-1. Follow Google's setup instructions.
Sign-in can fail with API_ID_PUBLISHED_FLOOD, which means Telegram rejected the API ID bundled with the app. Register your own app at Telegram's developer portal, then select Use registered Telegram API credentials and supply both apiId and apiHash when patching. This changes the shared app credentials used by native initialization, phone and passkey login. You can install the result as an update over your current HushTelegram build. On its first start it introduces itself to Telegram with your ID, so login codes are requested under your app instead of the bundled one. Changing from one registered API ID to another also refreshes that connection identity, while keeping saved account keys and the app version intact. Telegram still decides which login methods are available. Keep any existing signed-in installation.
Credential options are compiled into the APK and recorded in the patching result report. Keep both private. These two patches have no runtime switch, and Pause doesn't change their credentials. Updating with the retained signing key preserves the installed app's data.
For a patching bug, attach the separate public summary. patch-for-device.ps1 writes public-summary.json; verify-all-patches.ps1 writes verify-all-public-summary-*.json. They contain only supported package and bundle versions, catalog patch names and counts, and fixed failure codes. They omit credentials, options and private error text, including when patching fails. Keep the original result report and configured APK private. -ShowPatchLog prints the private CLI log locally, so don't copy that output into a report without reviewing it.
Fixture verification and new release receipts check native-library names, bytes and compression against the original APK. They also check relevant 64-bit ELF LOAD alignment and run zipalign -c -P 16 -v 4. Compressed native libraries remain valid. Receipt schema 4 records this evidence and the checker/tool hashes; older receipts use the schema pinned by their own commit. These packaging checks don't establish that Telegram has booted on a device with 16 KB memory pages. Native regression fixtures check their ZIP headers and bytes independently on PowerShell 7 and Windows PowerShell 5.1.
Can Telegram tell? Assume it can. A patched Telegram is signed with your key rather than Telegram's, and Telegram's app reports a fingerprint of that key to its servers when it connects.
What stays the same? Your chats, contacts and calls use Telegram's servers and native account flow. HushTelegram doesn't send, read, forward or delete messages on your behalf.
More than one account? HushTelegram's switches belong to the app, not to an account. Every one of them applies to all the accounts you've added, and a settings file you export or import covers them all.
Could my account be limited? Nobody can promise it won't be, and this project is young. If you'd rather not risk the account you care about, try HushTelegram with a second account first.
Some patches other people publish for Telegram unlock Premium features, get past a channel's forward and save protection, or open content Telegram hides for age or legal reasons. HushTelegram won't ship any of those. They take away something someone else controls, and the first two take something people pay for.
HushTelegram doesn't collect anything and has no server. The patched app goes online on HushTelegram's behalf for one thing only: the release check, and it's off until you turn it on. Once it's on, HushTelegram asks api.github.com for its latest release at most once a day, when Telegram starts, and again whenever you tap Check now. That's a plain HTTPS request with HushTelegram/<version> as its User-Agent, and it carries no cookies and nothing about you or your phone. GitHub sees your IP address, as any site you visit does.
The About and Licenses screens link to github.com, gitlab.com and www.gnu.org. Those open in your browser, and only when you tap one.
Diagnostics omit named Telegram API IDs and hashes from buffered events, crash sections and exported reports. Versions, counters and unrelated hashes stay readable. Review a report before sharing it.
| Source | What came from it |
|---|---|
SysAdminDoc/HushThreads at b141524 |
The Gradle build, the shared extension library with its settings screen, diagnostics and pause, the bytecode helpers and the checks that apply every patch to real builds before a release. Most of that came to HushThreads from Hushfacebook, and some of it from Hushfeed, Andrew Liang's patches and FroggoMorphePatches. |
| Morphe and ReVanced | The patcher and the patch template. Everything above grew from their code. |
The Telegram patches were written for this project by reading Telegram 12.10.6 itself. Every source file says where it came from in its header, and provenance.json maps each file to the project and commit it came from, with its license. The source ledger records the other Telegram references, their reviewed commits and adoption decisions. A listed feature is a research candidate, not an approved addition or a dependency. The ledger also records four confirmed directory listings. The published bundle is v0.0.8. Changes under Unreleased in the changelog are newer source work.
You need JDK 21 and the Android SDK. The Morphe patcher comes from GitHub Packages, so you also need a GitHub token with read:packages.
export GITHUB_ACTOR=<your GitHub user>
export GITHUB_TOKEN=<a token with read:packages>
./gradlew :patches:generatePatchesList
./gradlew :patches:buildAndroidThe bundle lands in patches/build/release/patches-<version>.mpp, beside its SHA-256 and a CycloneDX SBOM of every library that goes into it. Run generatePatchesList before buildAndroid, or the bundle loses its Android payload. Independent push checks use separate snapshots of the commits being pushed and separate outputs, with every required check retained. Fixture tests retain bounded content-keyed query facts and isolate mutable copies.
Tests: ./gradlew :patches:test :extensions:telegram:test. Set HUSHTELEGRAM_FIXTURE_DIR to the directory containing every APK named in AppCompatibilities.kt before pushing a patch change. The push check rejects missing fixtures.
Text input fingerprints ignore LF/CRLF differences, so validated tests can be reused in a temporary checkout. Source changes still invalidate the results, and APK fixture bytes remain exact. pwsh -NoProfile -File scripts/test-gradle-test-cache.ps1 exercises both test tasks in isolated copies, checks cache reuse and changes source and binary inputs to verify invalidation.
pwsh -NoProfile -File scripts/verify-patch-selections.ps1 -Apk <declared APK> -WorkDir <private folder> patches one declared Telegram build 41 ways. That covers the defaults, the full catalog, settings alone, each runtime patch by itself, the link and preview/camera pairs, and the two credential patches unset, configured and fed bad values. Every build is checked for its dependency closure, minimum Android version, preserved resources and native libraries, and the switches its settings screen offers. Configured credentials must change exactly their two literals and the native version marker that refreshes the connection identity. The Maps option changes only its metadata value.
Malformed options and rejected credential values must stop the build without echoing them. Ignored optional values must preserve stock behavior. The console prints only case names and fixed result codes. Keep the work folder private, since it holds the raw patcher reports. Combine both runs' matrix-private.json arrays into one file and set HUSHTELEGRAM_SELECTION_FACTS to it when running CompiledSelectionUiTest. The test task tracks that file's contents, so source-only results can't satisfy the compiled UI check.
Build dependencies have a separate advisory check. Run ./gradlew :patches:buildDependencyReport, then pwsh -NoProfile -File scripts/build-advisories.ps1. The report is in patches/build/dependency-reports/; the shipped SBOM continues to describe only libraries carried by the bundle. High, critical or unrated findings and failed queries stop a push. Lower-severity findings are reported.
pwsh -NoProfile -File scripts/test-bouncycastle-test-graph.ps1 checks the real dependency review in both task orders and verifies that unreviewed unit-test requests still fail. pwsh -NoProfile -File scripts/test-host-advisory-alignment.ps1 checks the settings and Android result-listener graphs while proving unrelated runtime requests keep their original versions.
GPL-3.0, with the Morphe section 7 notices carried in NOTICE. Telegram is a trademark of Telegram FZ-LLC.






