Are Telegram Trading Bots Safe? The Custody Truth Nobody Leads With
Last verified: September 19, 2026 (fake AI-agent case added; fake-site example added September 13; custody mechanics and incident table verified August 15). No referral links on this page. This is the page we wish had existed when we started using these bots.
Search this question and you will find bot companies grading their own homework and affiliate sites that answer "yes" above a signup button.
Here is the actual mechanics, the actual incident history, and the one rule that follows from both.
What actually happens to your money
When you start any Telegram trading bot, it generates a fresh wallet for you. This is the design's genius and its risk in one move.
The genius: you never connect your personal wallet, never sign approvals with it, so a bot cannot touch what you did not deposit. Your existing funds are structurally out of reach.
The risk: the generated wallet's keys live on the bot's infrastructure. Whatever the interface says about encryption or "your keys", if the bot's servers can sign your trades in milliseconds, the bot's infrastructure can spend your deposit.
That is custody in everything but name, and it applies to every bot in this category: Maestro, Banana Gun, BasedBot, BonkBot, Trojan, all of them. Each review on this site opens with the same custody line, and our full comparison table carries a custody column for exactly this reason.
Some document key export (BonkBot, Trojan), which helps you recover funds if the interface dies. It does not change who holds the live keys.
One clarification, because it confuses beginners: "you never connect your wallet" does not mean you can never use an existing address. Several bots offer to import a wallet by pasting its private key.
That does not change the custody model, it extends it: an imported key lives on the bot's infrastructure exactly like a generated one.
So if you import anything, import a dedicated trading wallet that holds only what you trade, and never, under any circumstances, the wallet where your long-term funds sit.
The incident record through August 2026
| Date | Bot | What happened | Outcome for users |
|---|---|---|---|
| Oct 2023 | Maestro | Router contract exploited, ~280 ETH taken from 106 users. Maestro's 2023 exploit, honestly told | Fully refunded within ~1 day (610 ETH paid out) source |
| Sept 2024 | Banana Gun | Telegram message oracle flaw, ~$3M drained from 11 users. Banana Gun's two incidents | Fully refunded from treasury, 2FA added source |
| Late 2025 | GMGN (terminal) | Phishing clone sites, not the platform itself, stole $700K+ from users. The GMGN security file | Individual losses, not refundable by the platform source |
| June 2026 | BullX (terminal) | No hack: trading suspended indefinitely, withdrawals left open | Funds retrievable, platform unusable source |
Methodology: this table is compiled from official team announcements, specialist press and public post-mortems, and every row links its source. If you know of an incident that is missing, tell @BetmanJoe and it will be added within 24 hours, dated.
Read the pattern: the serious bot teams refunded everything, fast, because their business dies otherwise.
The unrefundable losses came from fake sites, and the strangest failure mode was not theft but a platform simply stopping. All three risks are real and none of them is "the bot stole my money".
New in September 2026: the fake "AI trading agent" that swaps your wallet extension. On September 17, 2026, HP's threat research documented a campaign run through a fake AI trading bot site, tradingclaw[.]pro. The installer abused a Microsoft-signed tool to get past SmartScreen, then dropped a stealer that replaced the browser wallet extension with a copy that sends your password to the attacker. Seven extensions were targeted, including MetaMask, Phantom and Coinbase Wallet source.
HP's own line is the one to keep: a familiar unlock screen does not prove the extension is the one you installed. None of the tools on this site will ever ask you to download and run an installer. If a "trading agent" does, that is the whole answer.
The one rule, and its corollaries
- Save the key at creation. Every bot shows the wallet's private key once when it is generated. Store it like a password. With it, a dead interface does not mean dead funds.
- Type URLs, never follow them. The largest user losses of 2025 were clone sites. Bookmark the real bot and the real site once, from the official docs. One live example, seen in search results on September 12, 2026: a site calling itself "Axiom Pro, Robinhood Chain trading bot" on a domain that is not Axiom's. We did not open it and neither should you.
- Withdraw profits on a schedule. A float stays a float only if you skim it. Weekly is fine. The habit matters more than the interval.
- Distrust any bot promising returns. Real bots sell execution and charge about 1% per trade. "AI trading bot guaranteed profit" is a different product category: theft.
Legit is not the same as safe
The bots we review are legitimate businesses: real volume, published fees, multi-year records. Most of their teams are also anonymous, unaudited, and hold your deposit.
Both facts are true at once, which is exactly why this site marks incidents and custody on every comparison row and every review, including the ones we are paid a referral on. You deserve both facts in the same table.
FAQ
Can I lose more than I deposit?
No. Spot bots trade what you fund and nothing more. There is no leverage unless you seek out perps products, and no approval that reaches your other wallets.
How do I get my money back out?
Every bot has a withdraw command, and the friction is in the details rather than the button. We wrote one out step by step, screenshot by screenshot: how to withdraw from FOMO. The shape is the same elsewhere.
Is there a tool that never holds my money?
Yes, and it is worth knowing the category exists: wallet trackers watch addresses and alert you without ever taking a deposit. No custody, no float rule, no incident risk of this kind. They do not trade for you either, which is the trade-off.
Is it safer to use a web terminal instead?
Terminals like Axiom that connect to a wallet you control are structurally less custodial. Terminals with in-app wallets (GMGN, Photon) sit in between, and we put those two against each other in GMGN vs Photon. The float rule serves you identically in all three designs.
Which bot has the best safety record?
BonkBot and Trojan have no incidents on record; Maestro and Banana Gun each have one breach and one full refund. We weigh those roughly equally, and explain why in the Solana comparison and the multichain one.
New tools the week they launch. The settings and fees that quietly cost you money. Alpha I would tell a friend.
Free, unsubscribe in one click. Spot an error on the site? Reply and tell me, it gets fixed the same day.