They did not roll their own crypto, it's using AES with Diffie-Hellman key generation. [0]
You can now argue whether that's still "from scratch". (Is building something on top of TCP "from scratch"?)
You can now argue whether that's still "from scratch". (Is building something on top of TCP "from scratch"?)
Look at the description of their protocol, particularly the handshake, which negotiates number-theoretic parameters, and try to make a list of all the checks they'll need and the additional protocol that they'd need to specify just to make the handshake secure.
Not only that, but the crypto in Telegram is idiosyncratic; for instance, this is the only system I've ever seen that used IGE mode.