Are Telegram Trading Bots Safe? The Custody Truth Nobody Leads With

Last verified: September 19, 2026 (fake AI-agent case added; fake-site example added September 13; custody mechanics and incident table verified August 15). No referral links on this page. This is the page we wish had existed when we started using these bots.

Search this question and you will find bot companies grading their own homework and affiliate sites that answer "yes" above a signup button.

Here is the actual mechanics, the actual incident history, and the one rule that follows from both.

Where your money actually sits when you use a trading bot YOUR WALLET Ledger, Phantom, MetaMask, Rabby You hold the keys The bot never connects to it. There is no wallet-connect step. you send one deposit THE BOT'S WALLET Created for you, living on their servers They hold the keys This is what trades. If they are hacked, this is what is exposed. The market buys and sells The rule that follows: only deposit what you actively trade.
Every Telegram trading bot works this way. Your own wallet is never connected, which protects it, but the wallet doing the trading belongs to the bot. Both major exploits on record hit that second wallet, and both bots refunded users in full.

What actually happens to your money

When you start any Telegram trading bot, it generates a fresh wallet for you. This is the design's genius and its risk in one move.

The genius: you never connect your personal wallet, never sign approvals with it, so a bot cannot touch what you did not deposit. Your existing funds are structurally out of reach.

The risk: the generated wallet's keys live on the bot's infrastructure. Whatever the interface says about encryption or "your keys", if the bot's servers can sign your trades in milliseconds, the bot's infrastructure can spend your deposit.

That is custody in everything but name, and it applies to every bot in this category: Maestro, Banana Gun, BasedBot, BonkBot, Trojan, all of them. Each review on this site opens with the same custody line, and our full comparison table carries a custody column for exactly this reason.

Some document key export (BonkBot, Trojan), which helps you recover funds if the interface dies. It does not change who holds the live keys.

One clarification, because it confuses beginners: "you never connect your wallet" does not mean you can never use an existing address. Several bots offer to import a wallet by pasting its private key.

That does not change the custody model, it extends it: an imported key lives on the bot's infrastructure exactly like a generated one.

So if you import anything, import a dedicated trading wallet that holds only what you trade, and never, under any circumstances, the wallet where your long-term funds sit.

The incident record through August 2026

DateBotWhat happenedOutcome for users
Oct 2023MaestroRouter contract exploited, ~280 ETH taken from 106 users. Maestro's 2023 exploit, honestly toldFully refunded within ~1 day (610 ETH paid out) source
Sept 2024Banana GunTelegram message oracle flaw, ~$3M drained from 11 users. Banana Gun's two incidentsFully refunded from treasury, 2FA added source
Late 2025GMGN (terminal)Phishing clone sites, not the platform itself, stole $700K+ from users. The GMGN security fileIndividual losses, not refundable by the platform source
June 2026BullX (terminal)No hack: trading suspended indefinitely, withdrawals left openFunds retrievable, platform unusable source

Methodology: this table is compiled from official team announcements, specialist press and public post-mortems, and every row links its source. If you know of an incident that is missing, tell @BetmanJoe and it will be added within 24 hours, dated.

Read the pattern: the serious bot teams refunded everything, fast, because their business dies otherwise.

The unrefundable losses came from fake sites, and the strangest failure mode was not theft but a platform simply stopping. All three risks are real and none of them is "the bot stole my money".

New in September 2026: the fake "AI trading agent" that swaps your wallet extension. On September 17, 2026, HP's threat research documented a campaign run through a fake AI trading bot site, tradingclaw[.]pro. The installer abused a Microsoft-signed tool to get past SmartScreen, then dropped a stealer that replaced the browser wallet extension with a copy that sends your password to the attacker. Seven extensions were targeted, including MetaMask, Phantom and Coinbase Wallet source.

HP's own line is the one to keep: a familiar unlock screen does not prove the extension is the one you installed. None of the tools on this site will ever ask you to download and run an installer. If a "trading agent" does, that is the whole answer.

The one rule, and its corollaries

Only deposit what you actively trade. The bot wallet is your trading float, not your bank. If the bot vanished overnight, the number lost should annoy you, not change your year.

Legit is not the same as safe

The bots we review are legitimate businesses: real volume, published fees, multi-year records. Most of their teams are also anonymous, unaudited, and hold your deposit.

Both facts are true at once, which is exactly why this site marks incidents and custody on every comparison row and every review, including the ones we are paid a referral on. You deserve both facts in the same table.

FAQ

Can I lose more than I deposit?

No. Spot bots trade what you fund and nothing more. There is no leverage unless you seek out perps products, and no approval that reaches your other wallets.

How do I get my money back out?

Every bot has a withdraw command, and the friction is in the details rather than the button. We wrote one out step by step, screenshot by screenshot: how to withdraw from FOMO. The shape is the same elsewhere.

Is there a tool that never holds my money?

Yes, and it is worth knowing the category exists: wallet trackers watch addresses and alert you without ever taking a deposit. No custody, no float rule, no incident risk of this kind. They do not trade for you either, which is the trade-off.

Is it safer to use a web terminal instead?

Terminals like Axiom that connect to a wallet you control are structurally less custodial. Terminals with in-app wallets (GMGN, Photon) sit in between, and we put those two against each other in GMGN vs Photon. The float rule serves you identically in all three designs.

Which bot has the best safety record?

BonkBot and Trojan have no incidents on record; Maestro and Banana Gun each have one breach and one full refund. We weigh those roughly equally, and explain why in the Solana comparison and the multichain one.

Get it before it hits the site

New tools the week they launch. The settings and fees that quietly cost you money. Alpha I would tell a friend.

Free, unsubscribe in one click. Spot an error on the site? Reply and tell me, it gets fixed the same day.