Please don't yell fire like this. You haven't found any critical severity vulnerability in Telegram. As written, your report doesn't disclose a vulnerability at all. What you found is a logic error with no evidence of a security implication. You're attempting to promote yourself using invalid findings that, as presented, would be quickly rejected by the Telegram team as not applicable.
Your video details two findings: 1. the ability to empty a contact's internet balance by sending very long messages to them and 2. the ability to cause a contact's client to potentially crash due to an unexpected number of bytes in a single message.
The first finding is neither a Telegram nor a security issue. Does Twilio have a critical security vulnerability because I can use it to quickly exhaust a user's SMS quota for the month? This is an established precedent, and you have not identified a technical security flaw.
The second finding is a legitimate bug, as there is behavior that is implemented differently than the documented design goal of the API. However, you did not provide evidence that this finding can be used to cause a persistent denial of service. Does the application crash every time a user opens it, or is this good for one use? This is not a vulnerability unless you can demonstrate an overflow allowing local memory reads/writes or a persistent denial of service condition.
This is attention seeking behavior. Publicizing a "critical" vulnerability in a high profile application based on the flimsy excuse that you couldn't find an explicit disclosure email address reduces the credibility of responsible disclosure and legitimate security research. If you had actually bothered to search instead of rushing to bring your "findings" to notoriety you would have found security@telegram.org, which is explicitly for security reports. But that wouldn't have allowed you to make a blog post and submit it to HN, would it?
The next time you think you've found a vulnerability, don't publicize it and try to disguise it as a noble gesture by saying you're not going to "pinpoint" the vulnerability when you clearly walk through the exploitation in your video. Report your findings directly to the vendor, and if the vulnerability is valid and a fix is pushed due to your participation, then you can brag on HN about it.