Beyond doubts with the protocol itself, I think the more important consideration is that most people never use it. Telegram is not encrypted by default. Users have to create a special "secret chat" with contacts that is ephemeral, and some Telegram clients don't even support that mode. Last I checked, there was no way to have group "secret chats" in any client at all.
The result is a situation where many users seem to think that Telegram is somehow secure by default, when it definitely isn't. Telegram even stores plaintext copies of everyone's entire message history on the server for multi-device sync.
I think what Telegram is doing right now is dangerous, and potentially another Lavabit in the making. I'd like to see them incorporate a modern end to end encryption protocol, and enable it by default.
To be transparent, I work on TextSecure and am involved with the WhatsApp end-to-end encryption project.