Blog 7 min read

How to Spot a Fake or Abandoned AI Bot on Telegram Before You Trust It

Alex Morgan

Alex Morgan

Published on 15.07.2026

How to spot fake telegram bots

Telegram’s open bot ecosystem is one of its biggest strengths — and, as we’ve covered before, a big part of why AI tools took off there in the first place. But that same openness means there’s no app-store review standing between a developer and a published bot, and no automatic mechanism removing one that’s stopped being maintained, changed hands, or was never legitimate to begin with.

An academic large-scale study of Telegram bots found that around 10% of finance-related bots had already been flagged with Telegram’s own scam warning label — compared to roughly 1% across other bot categories. Separately, fraud researchers at Revolut reported that Telegram now accounts for 58% of all reported job scams globally, up from 50% just two years earlier. Neither of those numbers is about AI bots specifically, but the pattern applies directly: the categories where AI tools are most active on Telegram right now — crypto, finance, personal assistants handling real tasks — are also the categories scammers gravitate toward.

This isn’t a reason to avoid Telegram bots. It’s a reason to spend two minutes checking before you hand one a conversation, a wallet connection, or admin rights in a group you care about.

The checklist: what to actually look at

1. Check when it was last updated — and whether it still responds correctly

An abandoned bot is different from a scam bot, but it can be just as risky, especially if it’s still logging your messages or holding permissions no one is actively monitoring. Look for:

  • A visible changelog, version history, or “last updated” note on the bot’s linked website or channel
  • Whether basic commands still work as described, or return outdated/broken responses
  • Whether the bot’s linked support channel or contact has had any recent activity

A bot that hasn’t been touched in months but is still fully live is arguably a bigger long-term risk than a new one — there’s no one left accountable if something goes wrong with the data it’s already collected.

2. Compare the username against the real thing, character by character

The most common impersonation trick isn’t sophisticated — it’s substituting a letter, adding a dash or underscore, or using a lookalike character (a capital “I” for a lowercase “l”, for instance) in a username that otherwise looks identical to a legitimate project’s. This works because most people glance at a username rather than reading it character by character.

What to do: If a bot claims to represent a company, project, or public figure, go to that entity’s official website or verified channel directly and copy the exact bot link from there, rather than trusting a link sent to you in a DM or group chat.

3. Check what it’s actually asking for against what it claims to do

This is the single fastest tell. A bot that generates images from text prompts doesn’t need your full message history. A price-alert bot doesn’t need admin rights in a group. A “customer support” bot that asks you to enter a login code or verification number is not doing customer support — that’s a credential-theft attempt, full stop, regardless of how official it looks.

What to do: Before granting any permission — group admin rights, wallet-connect access, contact list access — ask whether that specific permission is something the bot’s stated function could plausibly need. If the answer is no, stop there.

4. Be suspicious of urgency, guaranteed returns, or “verification” fees

Scam bots — including ones dressed up as AI trading assistants or crypto “advisors” — rely heavily on manufactured urgency: fake countdowns, simulated balances that appear to grow, or requests for a small “verification” or “unlock” payment before you can supposedly withdraw funds. Legitimate tools don’t need you to pay a fee to access money that’s already yours.

What to do: Treat any request for an upfront payment to “unlock,” “verify,” or “release” funds as an automatic red flag, no matter how convincing the surrounding conversation is.

5. Look for a real, specific privacy policy — not generic boilerplate

We’ve written before about what “free” AI tools actually cost you in terms of data, and the same checks apply doubly here. A legitimate bot — AI-powered or not — should be able to point to a specific privacy policy explaining what it stores and for how long. Vague, generic language that could describe literally any app is often covering for the fact that there isn’t a real answer.

6. Check for a way to actually reach the developer

Plenty of good tools are built by solo developers who don’t want to be publicly identified, and anonymity by itself isn’t automatically disqualifying. But a bot with zero visible way to contact its developer — no linked channel, no website, no support contact anywhere — combined with a request for sensitive permissions, removes any accountability if something goes wrong.

Quick reference: fake/abandoned bot red flags at a glance

SignalWhat it usually means
Username has a subtly altered spelling of a known brand or projectImpersonation attempt
Bot has Telegram’s built-in “SCAM” warning labelAlready flagged by other users — trust the warning
Asks for a login code, OTP, or 2FA codeAccount takeover attempt — never a legitimate request
Requests permissions beyond its stated functionOverreach — proceed only after questioning why
No updates, broken commands, dead support channelAbandoned — data may still be collected with no one accountable
Promises guaranteed returns or asks for an “unlock fee”Financial scam pattern
No privacy policy, or a generic one that fits any appCan’t verify data handling — treat with caution

Where this matters most in this directory

Some categories carry more inherent risk than others simply because of what they’re designed to access:

  • Crypto AI tools that request wallet-connect permissions combine financial exposure with conversational data exposure — exactly the category the arxiv study found carries the highest concentration of flagged scam bots.
  • Personal Agents accumulate context about you over time by design, which makes checking their update history and privacy policy more important than for a stateless chatbot.
  • Group & Teams bots with admin rights can see every message in a group, not just messages directed at them — a meaningfully larger surface area than a one-on-one bot.

None of this means avoid these categories. It means the checklist above matters more, not less, the more access a bot is requesting.

Frequently Asked Questions

How do I know if a bot has Telegram’s official scam warning? 

Telegram displays a warning message directly in the chat when you try to interact with a bot it has flagged as a suspected scam or fake account. If you see this warning, trust it — don’t proceed past it based on reassurances elsewhere.

Is an anonymous developer automatically a red flag?

Not by itself. Plenty of legitimate tools are built by solo or pseudonymous developers. The bigger concern is anonymity combined with a request for sensitive permissions and no way to reach anyone if something goes wrong.

What should I do if I think I’ve already interacted with a fake or scam bot?

Stop the conversation, don’t send any further information or payments, and report the bot directly to Telegram. If you’ve shared a login code or password, change it and log out of all active sessions immediately. If you’ve sent cryptocurrency, treat that transaction as very difficult to reverse and preserve transaction records in case you need to report it.

Are abandoned bots dangerous even if they’re not scams?

Potentially, yes. An abandoned bot with admin rights or stored conversation history that no one is actively maintaining is a data-governance gap — there’s no one accountable if that access is misused or if the bot changes hands later.