h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

DeFi Rug Pulls in Court: The Chain Walks, Founders Don’t

A federal judge drew the clearest line yet under a DeFi rug pull. Solana walked free, the securities case collapsed, and two old-fashioned crimes did the work instead.

For most of the last two years, the standard answer to the question of who pays when a DeFi token dies was nobody. A founder renounced a contract, drained a liquidity pool, deleted a Telegram group, and walked. Prosecutors stared at a wallet address and a blockchain that did exactly what it was built to do. On 31 August 2026, a federal judge in Manhattan finally gave a different answer, and the shape of it surprised almost everyone who had spent two years predicting it.

In Aguilar v. Baton Corporation, the company behind the memecoin launchpad Pump.fun, Judge Colleen McMahon threw out the securities claims that most of the industry assumed would carry the case, cleared Solana Labs and the Solana Foundation completely, and then let the lawsuit live on two charges almost nobody was talking about: wire fraud and running an unlicensed money transmitting business. The blockchain walked. The marketing did not. This is an analysis of what that ruling actually says, why the securities theory collapsed, and what the new legal map means for anyone still trading tokens that can vanish overnight.

The ruling that redrew the map

The case began the way many of these do, with retail buyers who lost money on tokens that spiked and collapsed. Lead plaintiff Diego Aguilar and a consolidated class alleged losses on Pump.fun memecoins and built a sprawling complaint: unregistered securities, civil racketeering under RICO, illegal gambling, unjust enrichment, and a defendant list that eventually stretched from Pump.fun’s parent company all the way to Solana’s founders and 25 unnamed promoters. Estimated retail losses across the platform ran to between $4 billion and $5.5 billion, according to the court filings reported by The Crypto Times.

McMahon’s ruling, in the Southern District of New York (case number 1:25-cv-00880), was a near-total demolition of the parts of the complaint the crypto press had focused on, and a quiet green light for the parts it had mostly ignored. She dismissed the Securities Act counts with prejudice as to the two tokens the plaintiffs actually bought, FRED and GRIFFAIN. She rejected the gambling theory outright. She dismissed every Solana defendant: Solana Labs, the Solana Foundation, and executives including Anatoly Yakovenko, Raj Gokal, Dan Albert, Austin Federa, and Lily Liu. She even dismissed Aguilar’s own racketeering claim, because he had not adequately pleaded a domestic injury.

What survived was narrow and sharp. The RICO claims, both the conspiracy count and the substantive one, proceed against Baton Corporation and three named founders: chief executive Alon Cohen, chief technology officer Dylan Kerler, and chief product officer Noah Tweedale. They proceed on two predicate acts and two only: wire fraud and unlicensed money transmission under 18 U.S.C. 1960. Plaintiff counsel at Wolf Popper framed the surviving theory as an association-in-fact enterprise that pulled in the three founders and the unnamed promoters for the common purpose of profiting from an alleged fraudulent promotional scheme.

Claim or defendantOutcomeWhy
Securities Act (FRED, GRIFFAIN)Dismissed with prejudiceNo common enterprise under Howey
Illegal gambling predicateDismissedBuying a volatile asset is not a wager
Solana Labs, Foundation, executivesDismissedNo proven knowledge of fraud
Aguilar’s own RICO claimDismissedNo domestic RICO injury pleaded
RICO vs Baton Corp and 3 foundersSurvivesWire fraud plus money transmission
Predicate: wire fraudSurvivesPublic unruggable marketing claims
Predicate: 18 U.S.C. 1960SurvivesBonding curve moved value for a fee

The asymmetry is the whole story. The claim that would have reshaped the entire token economy, that memecoins are unregistered securities, is dead for these tokens and dead with prejudice. The infrastructure layer, the chain and the companies that build it, is untouchable. And the liability that remains attaches to specific humans for specific things they said and specific money they moved. That is a far narrower target than the industry spent two years bracing for, and a far more durable one.

First, what actually counts as a rug pull

A rug pull is not a single technique; it is an outcome reached several ways. The cleanest version is the hard rug: a team seeds a liquidity pool, lets buyers in, then pulls the pooled assets out through a privileged function, a hidden mint, or a honeypot contract that lets people buy but never sell. Liquidity goes to zero in a single block, and the token is worthless by the time anyone refreshes the chart.

The soft rug is slower and much harder to prosecute. Nobody drains a pool in one transaction; instead, insiders who control most of the supply sell steadily into retail demand until the price bleeds out, often while the team keeps posting roadmaps. A Solana study published in 2026 classified more than 76,000 of roughly 100,000 tokens launched on three major decentralized exchanges in early 2025 as rug-pull candidates, most of them soft rugs rather than dramatic one-transaction drains. The quiet exits vastly outnumber the spectacular ones.

Then there is the slow rug that hides in plain sight: a pre-announced insider token unlock. Nothing is hacked and nothing is hidden; a vesting schedule simply hands early holders a large tranche of supply on a known date, and they sell. It is disclosed, it is legal, and it can erase as much value as an outright theft. No scanner flags it, because technically it is not a rug at all.

It helps to separate three things the headlines constantly blur. A hack is when code does something its authors did not intend, usually because an attacker found a flaw. A collapse is when a project fails honestly, through bad design or market conditions. A rug pull sits in between: the code often works exactly as written, and that is the point, because the theft was engineered in from the start. The entire legal problem, as the Pump.fun ruling shows, is that intent is the dividing line, and intent is the hardest thing to prove on a ledger that records what happened, not why.

Why the securities case collapsed

For years, the assumed path to holding rug-pull operators accountable ran through securities law. If a token is an investment contract under the Supreme Court’s Howey test, then selling it unregistered is illegal, disclosure duties attach, and a long bench of enforcement precedent comes into play. The Pump.fun plaintiffs built their headline claim on exactly this theory. McMahon rejected it in terms that will echo through every memecoin case that follows.

Howey requires, among other things, a common enterprise: the fortunes of the investors have to be tied together and tied to the efforts of a promoter. McMahon held that pooling SOL into a token-specific bonding curve does not create one, because there is no venture funded by the pooled assets. Money goes in, a price moves along a mathematical curve, and money comes out; nobody is funding a business whose success everyone shares.

Then she turned the plaintiffs’ own narrative against them. Their theory was that insiders bought early, pushed the price up, and sold before the collapse. But that, the judge noted, is the opposite of a common enterprise. If the insiders profit precisely when the latecomers lose, their fortunes are not shared; they are adverse. The very mechanism that makes a rug pull a rug pull is the mechanism that defeats the common-enterprise prong of Howey. It was an elegant, and for the plaintiffs devastating, piece of reasoning, and it is why the dismissal came with prejudice rather than a chance to replead.

This did not come from nowhere. It tracks the position the SEC itself had staked out 18 months earlier, and it leaves the securities route to rug-pull liability effectively closed for the thing most rugs actually are: thin, issuer-less memecoins with no shared venture behind them. The weapon the entire industry had prepared to fight over turned out to be pointed at the wrong target.

The two weapons that survived

If securities law is the wrong tool, what is the right one? McMahon’s answer was almost old-fashioned. The two predicate acts she allowed to proceed are among the oldest in the federal fraud toolkit, and neither depends on a token being a security.

The first is wire fraud. The complaint points to public statements by chief executive Alon Cohen describing Pump.fun as an unruggable fair launch platform and an even playing field. If a court later finds those claims were false or misleading when made, and that they were used to induce transactions over interstate wires, that is wire fraud, full stop. It does not matter whether the underlying token is a security, a commodity, or a collectible. What matters is that a named human being made a factual promise to the public that was not true.

The second is the one that should make every launchpad and DeFi front end nervous: unlicensed money transmission under 18 U.S.C. 1960. McMahon reasoned that Pump.fun’s bonding-curve contracts accepted one form of value and transmitted another as part of an exchange run for a fee, and did so without registering with FinCEN as a money transmitting business. In plain terms, the court treated the smart contract itself as a money-moving business that needed a federal license it never obtained. That is a theory with reach far beyond one launchpad, and it is the part of the ruling that quietly worries lawyers for every on-chain protocol that takes a cut of a swap.

Put the two together and the surviving case is not about what a token is. It is about what people said, and what their software did for money. That is a completely different map of liability from the one the industry spent years preparing to defend.

Follow the words, not the code

The wire-fraud survival carries a lesson that goes well past this one case: in a rug pull, the legally dangerous object is usually not the contract, it is the sentence. Unruggable. Fair launch. Liquidity locked forever. The team can’t sell. Each of those is a factual claim about the world, and if it is false when published, it converts an ambiguous market loss into a prosecutable fraud.

This inverts how most builders think about risk. The instinct in crypto is that safety lives in the code: renounce ownership, lock the LP, publish the audit, and you are covered. But code that works as written is exactly what a rug pull relies on, and the contract did what it said is not a defense to having lied about what the contract would do. A courtroom does not care that a mint function was visible on a block explorer if the founder went on social media and swore it would never be used.

It also explains why enforcement keeps landing on the most visible people rather than the most culpable code. A pseudonymous developer who ships a honeypot and says nothing is genuinely hard to reach. A named founder with a verified account who markets a platform as unruggable has handed prosecutors a paper trail. The ones who talk are the ones who get sued. Silence, grimly, is the better legal strategy, which is part of why the loudest corners of the market are not always the safest places to put money.

The SEC’s quiet retreat

The ruling did not happen in a vacuum; it ratified a position the SEC had already taken. In February 2025, the agency’s Division of Corporation Finance issued a staff statement saying most memecoins are not securities, comparing them to collectibles and finding no common enterprise. Commissioner Hester Peirce put it bluntly to Bloomberg: “Many of the memecoins that are out there probably do not have a home in the SEC under our current set of regulations,” she told The Block.

Not everyone at the agency agreed, and the dissent matters because it predicted precisely the gap the Pump.fun ruling later confirmed. Commissioner Caroline Crenshaw warned that the staff statement functioned, at best, as “a roadmap for crypto enterprises looking to evade oversight by labeling themselves as a meme coin,” in her published response. Her point was that the profit linkage between promoters and buyers could still satisfy Howey in the right case. McMahon’s ruling, in effect, sided with Peirce: for issuer-less tokens with adverse rather than shared fortunes, there is no securities hook to hang liability on.

This is the quieter half of a broader shift, the SEC’s retreat from the aggressive enforcement-by-litigation posture of the previous cycle that HOGE Wire has tracked in detail in our analysis of crypto enforcement in 2026. The agency that spent years suing exchanges has, on memecoins specifically, essentially ceded the field, leaving the work to the Justice Department’s fraud statutes and FinCEN’s money-transmission rules. The regulator most people associate with crypto fraud is now the one least likely to bring the case.

Legal readers cautioned against over-reading the result. Crypto attorney Ariel Givner, in comments reported by Protos, noted that the decision does not establish that memecoins broadly fall outside securities law; it turns on the absence of a shared profit motive between issuer and buyers in these specific tokens. A differently structured token, with a genuine common venture behind it, could still be a security. The door is narrower, not gone.

The scale the courtroom is reacting to

Numbers explain why a federal judge was willing to stretch a money-transmission statute to reach a smart contract. Pump.fun industrialized token creation. A 2025 study by the blockchain surveillance firm Solidus Labs, widely reported, found that 98.6% of the tokens launched on the platform ended as rug pulls or acts of fraud, out of more than seven million tokens issued since the start of 2024, as CoinDesk reported. Pump.fun spokesperson Troy Gravitt dismissed the report, telling CoinDesk that “What Solidus Labs lacks is a basic understanding of memecoins.”

It is worth killing a statistic here, because it shapes how people understand the damage. A figure of 2.8 billion dollars in rug pulls circulates constantly, usually attributed to Chainalysis. It does not appear in any primary Chainalysis report. It is almost certainly a corruption of Solidus Labs’ separate finding that the median rug pull extracts about 2,800 dollars, not 2.8 billion. That distinction matters: the typical rug is tiny, a few thousand dollars taken from a handful of wallets, and the aggregate damage comes from sheer volume plus a small number of mega-rugs, not from a uniform fortune stolen every time.

Claim you will seeWhat the primary source actually says
2.8 billion dollars in rug pulls, per ChainalysisNo such figure in any Chainalysis report; likely a garbling of a 2,800 dollar median
98% of Pump.fun tokens are frauds98.6% ended as rugs or fraud, per Solidus Labs via CoinDesk
Rug pulls are a clean line item in crime dataChainalysis counts value moved on-chain, not market cap erased
Every rug steals a fortuneMedian extraction is roughly 2,800 dollars; damage is volume plus rare mega-rugs

The verified macro numbers are grim enough without inflation. Chainalysis reported roughly 17 billion dollars in crypto scams and fraud for 2025, with about 14 billion dollars confirmed on-chain and the average scam payment rising from 782 to 2,764 dollars year over year. The firm does not break out a rug-pull-specific line, which is itself telling: on-chain analytics measure the value that moved, not the market capitalization that evaporated, and most of what a rug destroys is the latter.

The toll booth that kept printing money

Here is the part that complicates every tidy morality tale. The platform at the center of the largest rug-pull class action in history is not a failed business. It is one of the most profitable products in crypto. Pump.fun’s weekly fees have topped 10 million dollars, with its revenue at times overtaking the perpetuals giant Hyperliquid, according to crypto.news. The company has plowed a large share of that revenue into buying back its own PUMP token, running one of the biggest buyback programs in the sector.

The economics are a toll booth. Pump.fun does not need any individual token to succeed; it collects a fee on creation and on every trade along the bonding curve, so it earns the same whether a token moons or rugs. When 98.6% of your inventory ends in fraud and you still book record revenue, the fraud is not a bug in the business model, it is the throughput. That is a structural problem no red-flag checklist can solve, and it is the uncomfortable fact sitting underneath the courtroom drama.

The buyback mechanism deserves a hard look, because it is the same flywheel that powers the perpetual-DEX tokens HOGE Wire has examined in our study of whether the buyback flywheel actually works: route protocol revenue into token repurchases, shrink the supply, and hope the price follows. For a launchpad, it means the token that represents the house takes a cut of an activity that is overwhelmingly fraudulent, then hands it back to holders as a scarcity story. The flywheel works mechanically; whether it should is the question the courtroom is now, indirectly, being asked.

PUMP itself tells the story in its price. After bottoming near 0.00116 dollars in mid-2025, the token traded around 0.0063 dollars in early October 2026, a market capitalization close to 2.9 billion dollars and a fully diluted valuation above 5 billion dollars, ranking inside the top 45 cryptocurrencies by value, per CoinGecko. A multi-billion-dollar asset built on a machine that mostly produces fraud is not a contradiction the market seems eager to resolve.

When intent is the whole case

The Pump.fun ruling turned on intent, and intent is exactly where the two most famous cases of the cycle diverge. They are worth holding side by side, because together they mark the boundary of what the law can and cannot reach.

LIBRA is the clean case. On 14 February 2025, Argentine president Javier Milei posted, then deleted, an endorsement of a token that spiked more than 2,000% in about forty minutes to a peak market capitalization near 4.4 billion dollars before collapsing, with insiders estimated to have pocketed around 87 million dollars on the first day, CoinDesk reported. The pattern, a sudden promotion from a trusted name, a concentrated insider position, and a fast exit, is the textbook presidential rug, and it has spawned criminal probes across Argentina, the United States, and Spain.

Mantra is the hard case. On 14 April 2025, the OM token fell more than 90% in about an hour, erasing roughly 6 billion dollars in market value, according to CoinDesk. But the team blamed reckless forced liquidations on exchanges in thin Sunday liquidity, not a deliberate exit, and while on-chain data showed team-linked wallets moving tokens before the crash, no investigation has proven an insider cash-out. The project kept operating. Was it a rug or a collapse? More than a year later, that question still has no settled answer, and that ambiguity is precisely why intent-based fraud charges are so hard to bring. The chain shows the movement; it does not show the motive.

This is the gap McMahon’s ruling works around rather than through. Wire fraud needs a provable lie. Money transmission needs an unlicensed money-moving business. Both are easier to establish than the thing everyone actually cares about, which is whether the founder always meant to run. The law reached for the crimes it could prove, not the one it wished it could.

The criminal track running in parallel

Civil class actions are only one front. The Justice Department has been building a quieter, and in some ways more dangerous, criminal case against the market’s plumbing. In March 2026, prosecutors in the Northern District of California unsealed Operation Token Mirrors, charging ten people across four market-making firms with manipulating token markets, as detailed by TRM Labs.

The operation was a sting. The FBI and IRS Criminal Investigation created their own token, Lexobit, and hired market makers to trade it, then watched them wash-trade. In one firm’s sampled activity, 99% of transactions were self-dealing between linked wallets, manufacturing fake volume to make dead tokens look alive. Several defendants were extradited from Singapore, and some have entered guilty pleas. It is not technically a rug pull, but it is the same ecosystem: the fake volume that market makers sell is the credibility a rug needs to attract victims in the first place.

Notice the common thread with the Pump.fun ruling. Neither case bothers with whether a token is a security. Operation Token Mirrors is a straight market-manipulation and fraud prosecution; the Pump.fun case survives on fraud and money transmission. The enforcement establishment has, in effect, converged on a single strategy: skip the metaphysics of what a token is, and prosecute the humans for lying and for running unlicensed money businesses. It is less ambitious than reclassifying an entire asset class, and far more likely to produce convictions.

Why the money-transmission theory is the real precedent

Of the two surviving charges, wire fraud is the familiar one; prosecutors have used it against confidence men for a century, and applying it to a founder who published the word unruggable is a short step. The genuinely new move is the money-transmission theory, and it is the part of the ruling most likely to outlive this case. By treating a bonding-curve contract as a money transmitting business, McMahon imported a body of law written for wire services and check cashers into the heart of DeFi.

The logic does not stop at launchpads. A money transmitting business, in the federal sense, is one that accepts value from one party and transmits it to another, or converts one form of value into another, for a fee. That description fits an automated market maker. It fits a swap router. It fits most of the on-chain plumbing that charges a few basis points to move or exchange value. If a court can treat Pump.fun’s contracts as an unlicensed money business, the same reasoning is available against any protocol whose front end takes a cut, and that is a prospect that should concern builders far from the memecoin casino.

The reason this matters more than the securities fight is that money-transmission liability does not depend on how a token is classified, the question that has tied up crypto policy for a decade. It asks only whether value moved for a fee and whether anyone registered with FinCEN. Those are almost always easy to answer, and in DeFi the answer is almost always no. The securities debate was a philosophical standoff; the money-transmission theory is a checklist, and crypto has a long history of failing checklists.

None of this is settled. Surviving a motion to dismiss means a claim is plausible, not proven, and the founders will argue that a permissionless smart contract is not a business they operate in the way FinCEN rules contemplate. But the fact that the theory cleared the first hurdle at all is the signal worth watching. For years the industry treated decentralization as a shield against exactly this kind of liability. The Pump.fun ruling suggests that where a named company collects fees from a contract it wrote and still controls, the shield is thinner than its builders hoped.

Can engineering close the gap the law can’t?

If the law can only reach a rug after the fact, the obvious question is whether code can prevent one before it happens. The honest answer is partly, and only against the crude attacks.

The hard rug has well-understood on-chain tells, and they can be designed out. A renounced owner key means no privileged function can drain the pool. A disabled or burned mint authority means no one can print fresh supply to dump. Time-locked, verifiably burned liquidity means the pool cannot be yanked. These are the checks that tools like RugCheck, GoPlus, and Honeypot.is automate, and they genuinely catch the honeypots and hidden-mint contracts that make up a large share of hard rugs.

But the privileged-key problem is deeper than any single checklist, because control, not code, is usually the real vulnerability. A setup that looks decentralized can still be a rug if one person quietly holds a quorum of the keys, a point HOGE Wire has made at length in arguing that the permission, not the exploit, is the attack. The move toward smarter account models and delegated permissions, which we unpack in our explainer on how smart accounts work, changes what a single signature can authorize, and the cryptography underneath custody keeps improving, but none of it can tell you whether the human holding the keys intends to use them honestly.

Then there is the blind spot nothing on-chain can see: the legal, pre-announced insider unlock. No scanner flags a vesting schedule as a rug, because it is not one, technically. It is disclosed, it is in the documentation, and it can still hand insiders the exact outcome a rug delivers. Audits do not help here either. An audit is an objective review of a project’s code, not a verdict on the honesty of the people running it. A contract can pass every automated check and still be controlled by someone who always planned to leave. Engineering raises the floor; it does not close the gap where intent lives.

What it means if you are still trading memecoins

Strip away the doctrine and a few practical conclusions fall out of the 2026 legal map, and they are not the ones most traders assume. The first is uncomfortable: the ruling protects almost nothing for buyers. It does not make rug pulls illegal in some sweeping new way; it keeps alive a narrow set of charges against a few named people in one case, and it explicitly closes the securities route many assumed was the broad remedy. If you are buying memecoins, the law will not catch most of the people who take your money, and it has now said so clearly.

The second is that verification still beats faith, but verification has hard limits. The crude rugs are checkable in minutes, and skipping that check is inexcusable; the table below is the short version of what to look for. The sophisticated rugs, built by operators with clean deployer wallets, disclosed unlocks, and no public lies, are engineered to pass exactly the checks you can run. Clearing a scanner is a floor, not a verdict.

Red flagWhat to checkTool or method
Live mint authorityCan supply be printed after launch?GoPlus, RugCheck
Owner not renouncedCan a privileged function drain funds?Block explorer, RugCheck
Unlocked or short-locked liquidityIs the pool actually locked, and for how long?Honeypot.is, LP lock records
Concentrated holdersDo a few wallets control most of the supply?Holder distribution on explorer
Pre-announced unlockWhen does insider supply vest?Tokenomics docs, vesting schedule
Unruggable marketingAre there public guarantees that could be false?The team’s own social posts

The third conclusion is the one the courtroom underlined: the loudest signal of safety is often the most dangerous. A founder who promises an unruggable fair launch has told you two things at once, that a rug is the relevant risk, and that they are willing to make factual claims they may not be able to keep. The ruling that keeps Alon Cohen in a federal courtroom turns on exactly that kind of promise. In a market where silence has become the safer legal posture, treat loud guarantees as a tell, not a comfort.

The deeper takeaway of 2026 is that the law stopped trying to redefine what a token is and started asking a simpler question: who lied, and who moved the money. That shift will not refund a single rugged wallet. But it has finally given prosecutors a weapon that works, and it has told every named founder with a verified account and a bonding curve that the chain may be beyond reach, but they are not.

Frequently Asked Questions

Are rug pulls illegal in the United States?

There is no single rug-pull statute in US law, but the conduct can violate several existing laws. The August 2026 Pump.fun ruling let wire-fraud and unlicensed-money-transmission charges proceed against the founders, while dismissing the securities and gambling claims. Whether a specific rug pull is prosecutable usually depends on whether operators made provable false statements or ran an unlicensed money business, not on the token itself.

Why were Solana Labs and the Solana Foundation dropped from the lawsuit?

Judge McMahon found no evidence that the Solana entities or their executives knew the platform was being used for fraud. Knowing that a blockchain is heavily used is not the same as knowing it is being used to commit crimes, so the infrastructure layer was dismissed while the claims against Pump.fun’s own founders survived.

Did the ruling decide that memecoins are not securities?

Not as a general rule. The court held that the two specific tokens at issue were not securities because there was no common enterprise between buyers and promoters. Attorney Ariel Givner cautioned that a differently structured token with a genuine shared profit venture could still qualify as a security. The decision narrows the securities route; it does not erase it.

How can I check whether a token is a rug pull before buying?

Scan the contract with a tool such as RugCheck, GoPlus, or Honeypot.is to check for a live mint authority, an un-renounced owner, unlocked liquidity, and concentrated holders. These catch crude hard rugs in minutes, but they cannot flag a legal pre-announced insider unlock or a founder who simply plans to sell, so no check is a guarantee.

What is the difference between a rug pull and a hack?

A hack is when code does something its authors did not intend, usually because an attacker exploited a flaw. A rug pull is when the code works exactly as written and the theft was designed in from the start. The distinction is intent, which is why rug-pull cases are so hard to prosecute: a ledger records what happened, not why.

Anneke de Vries is a security correspondent at HOGE Wire, covering DeFi exploits, on-chain forensics, and crypto enforcement.

Share 𝕏 Post Telegram