← Back to Hub Aggregator

How to Verify a Telegram Bot Before Using It (2026 Security Guide)

Updated: February 2026 • Security guide • Related: Telegram scam types guideBot rating methodology
Rule #1 — no exceptions: No legitimate wallet, app, or earning bot will ever ask for your 12 or 24-word seed phrase. Not for "verification", not for "recovery", not to "unlock" your earnings. Anyone asking is a scammer. Block and report immediately.
Hub Aggregator Scam Monitoring: Scam pattern detection, phishing technique tracking, and bot verification methodology in this guide draw from Hub Aggregator's review and monitoring of 1,200+ Telegram mini apps since 2024, including direct documentation of security incidents, wallet connection abuse patterns, and user-reported scam cases.

The Telegram earning ecosystem grows alongside its scam ecosystem. For every legitimate Stars-earning app, there are imitations designed to steal your time, your funds, or your wallet keys. Most scams share recognizable patterns — knowing them lets you eliminate 95% of risk in under 5 minutes per bot.

Scam Type Breakdown: What You're Actually Facing

Scam TypeHow It WorksKey Red FlagRisk Level
Seed phrase harvesterBot or chat asks for your 12/24 words to "verify" or "connect" your walletAny seed phrase requestCritical — instant wallet drain
Fake withdrawal feeBot lets you "earn" but requires a "tax" or "fee" payment before you can withdrawPay-to-withdraw requirementHigh — upfront money lost
Off-chain balance trapBot shows growing balance but has no actual blockchain connection — balance is imaginaryNo on-chain transaction historyHigh — time wasted, no funds exist
Admin impersonation DMScammer DMs you pretending to be project admin, offers "special help" with a payment linkUnsolicited admin DMHigh — leads to seed phrase or payment
Fake KYC in chatBot asks you to send ID documents directly in chat to "verify your account"Document request inside TelegramMedium — identity theft
Guaranteed ROI schemeBot promises fixed daily returns (e.g., "2%/day") — Ponzi until it exitsFixed guaranteed returnsMedium — funds lost at exit
Malicious TON ConnectBot connects via TON Connect then pushes deceptive transaction approvalsSuspicious transaction requestsMedium — requires your confirmation

The 7 Red Flags: Spot Them Instantly

  1. Seed phrase request: Any format, any reason. Block immediately. This one is binary — there are no legitimate exceptions.
  2. Pay-before-withdraw: Requiring a "fee", "tax", "activation payment", or "insurance deposit" before you can withdraw earnings is an advance-fee scam. The earnings don't exist.
  3. No on-chain verification: If you can see your growing balance inside the bot but there's no transaction history on tonscan.org tied to your wallet, the funds are imaginary. Check the blockchain.
  4. Admin DMs offering help: Real admins never message users first in private about payments, deposits, or account issues. Immediately block any "admin" who DMs you unsolicited.
  5. Documents in chat: Legitimate KYC is handled by external encrypted services (Sumsub, Jumio, etc.) via a verification link — never by sending photos directly into a Telegram chat.
  6. Fixed guaranteed returns: "2% daily guaranteed", "150% in 7 days", "risk-free profit" — these are either Ponzi schemes or outright fraud. Real earnings fluctuate based on activity.
  7. Anonymous team, no digital footprint: A Telegram channel with no website, no named founders, no GitHub, no prior project history, and a single support contact is the highest-risk profile.

5-Minute Verification Process

Before using any bot outside the Hub Aggregator verified catalog, run through this sequence:

  1. Minute 1 — Search: Google "[bot name] scam" and "[bot name] not paying". Check Telegram scam databases and subreddits like r/Telegram or r/CryptoCurrency.
  2. Minute 2 — Team check: Does the team have public LinkedIn profiles, a project website, or a GitHub? "We are an anonymous team" is not automatically disqualifying, but it raises the minimum due diligence required.
  3. Minute 3 — On-chain verification: If the bot claims to use TON smart contracts, look up the contract address on tonscan.org. Unverified contracts with no audit are medium risk. No contract at all means all balances are off-chain.
  4. Minute 4 — Community quality check: Visit the bot's Telegram group. Is support active and helpful? Do members discuss actual payouts with transaction screenshots, or are posts mostly referral links and vague hype?
  5. Minute 5 — Early withdrawal test: After your first session, as soon as you reach the minimum withdrawal, attempt a small withdrawal. Legitimate bots process this. Scam bots often allow "earning" indefinitely but create barriers when you try to take funds out.

If You've Already Connected a Suspicious Bot

Immediate action steps if you suspect a bot you've connected is malicious:
  • Via TON Connect: Open Tonkeeper or TON Space → go to Connected Apps / DApps → find and disconnect the suspicious app. This revokes its ability to request transactions from your wallet.
  • If you shared your seed phrase: Your wallet is compromised. Create a new wallet immediately. Transfer all remaining funds to the new wallet before the attacker does. Do not use the old wallet again.
  • If you sent payment: Crypto transactions are irreversible. File a report with Telegram (@notoscam), document the bot username, addresses used, and transaction IDs. Recovery is unlikely but documentation helps future victims.

How Hub Aggregator Screens Bots

Before any bot appears in the Hub Aggregator catalog:

Find verified bots and mini apps → Browse Hub Aggregator's catalog of 1,200+ verified Telegram earning apps, filtered by security score, payout type, and category.

Frequently Asked Questions

What is the #1 sign a Telegram bot is a scam?

A request for your seed phrase or private key — 100% of the time, no exceptions. No legitimate bot needs your 12 or 24-word seed phrase. Block and report immediately without further interaction.

How can I verify a Telegram bot is legitimate?

5-point check: (1) Search the bot name + 'scam' online. (2) Check if the team has verifiable public history. (3) Test a small withdrawal before accumulating balance. (4) Verify smart contracts on tonscan.org. (5) Check community engagement quality.

What should I do if I already connected a suspicious bot?

If connected via TON Connect, disconnect immediately in your wallet's Connected Apps section. If you shared your seed phrase, create a new wallet and transfer funds immediately — treat the old wallet as permanently compromised.

Can a Telegram bot steal funds without my seed phrase?

A TON Connect-connected bot can request transaction approvals that you must manually confirm. It cannot transact autonomously. However, phishing bots trick users into approving malicious transactions. Always read transaction details — especially recipient address and amount — before confirming.

Are admin DMs in Telegram support chats legitimate?

No. Legitimate project admins never initiate DMs offering help with payments or recovery. This is universally a scammer impersonating staff. Real support operates through official public channels or ticketing systems. Block any "admin" who DMs you first.