Tap-to-earn games were crypto’s most successful onboarding funnel. Notcoin, DOGS, and Hamster Kombat ran as Telegram mini-apps — games you play inside a chat app, tapping a coin, completing tasks, inviting friends — and each ended with a token airdrop to players. According to public reports, Hamster Kombat claimed a player base in the hundreds of millions at its peak. Whether those numbers are inflated matters less than the side effect: tens of millions of Telegram users learned that “tap a button, receive tokens later” is a normal thing that happens.

Scammers learned the same lesson faster. According to Kaspersky, fake Hamster Kombat bots multiplied during the game’s peak, and security firms issued repeated warnings about cloned tap-to-earn games. The scam does not need to beat Telegram’s security — it only needs to look enough like the real game that a player who already taps “confirm” reflexively keeps tapping.

This article maps the five scam patterns that run inside Telegram airdrop bots, explains how legitimate Telegram campaigns actually work, and gives you the verification sequence before you tap anything. It is part of our Airdrop Safety series.

Why Telegram Is the Perfect Delivery Channel

The tap-to-earn format solved the two oldest problems in phishing: getting the victim to the fake page, and getting them to act without thinking.

Distribution is built in. Telegram groups, channels, DMs, and forwarded messages move links at zero cost. A fake bot link spreads through the same channels that spread the real game — airdrop-hunting groups, task channels, comment sections under crypto channels. You can read the full map of how fake airdrops reach victims in how fake airdrops reach you.

The action is training. A real tap-to-earn game asks you to tap, complete tasks, and connect things dozens of times a day. Every session normalizes one more click on a screen you did not fully read. When the fake version shows a “connect wallet” or “verify” screen, it arrives pre-justified — the player’s recent experience says this is how the game works.

The reward is deferred. The whole premise is “accumulate points now, receive tokens later.” That deferral is a gift to scammers: when nothing arrives, players blame delays, not theft, for weeks. The fake bot can show a growing balance forever, because the balance is a number in a database the attacker controls.

Payments are native. Telegram supports TON transfers inside the app. Fake bots use this to collect “activation” or “withdrawal” fees natively, without ever touching a crypto website — the entire scam can run inside one chat interface.

Scam Pattern 1: Cloned Bots and Fake Mini-Apps

The base of every Telegram airdrop scam is a copy. Cloning a mini-app is cheap: the game screens are simple, the art is public, and the interaction pattern is standardized. The attacker registers a lookalike bot username — NotCoin_bot instead of the official handle, or a handle with substituted characters — and pushes it into the same groups where the real game spreads.

The clone differs from the original in exactly one place: the wallet screens. Where the real campaign’s token claim would link to an official claim page, the clone inserts its own — a phishing page built to harvest connections and signatures, frequently powered by commercial drainer kits. The wallet drainer economy operates as a service: kits rent out the signing interface, affiliates supply the traffic, and Telegram’s tap-to-earn wave supplied the best traffic the market had seen.

Detection is mechanical. Cross-check the bot or mini-app username against the project’s official channel, character by character — clones rely on lookalike substitutions. Confirm the campaign is announced at all, from the project’s verified X account or official site, not from the bot’s own claims. If you arrived at the bot through a forwarded message or a DM, you have not verified anything yet.

Scam Pattern 2: Seed-Phrase “Verification”

The most direct theft in the format asks for your recovery phrase. The screen dresses it up as “verify your wallet to receive tokens,” “sync your wallet,” or “import wallet for eligibility.” The wording changes; the mechanics do not: you type your seed phrase into an attacker’s form.

There is no legitimate version of this screen. None. A Telegram mini-app interacts with your wallet — at most — through a wallet connection that you approve from inside your wallet app. Wallet import is something you do in wallet software you chose and installed, never inside a chat app game. The moment a bot asks for 12 or 24 words, the question is not “is this airdrop real” but “has this wallet already been compromised” — and if you entered the phrase, the answer is to move your funds to a fresh wallet immediately, before reading another word.

Scam Pattern 3: Connect-Wallet Signature Traps

The more sophisticated clones skip the seed phrase and use signatures instead, because signatures look legitimate — your wallet shows a prompt, you have signed dozens of prompts. The claim page behind the fake bot requests one of the dangerous signature types: a token approval, a Permit2 authorization, an EIP-712 permit, or in the worst cases a raw eth_sign or EIP-7702 delegation. Each of these moves future funds without moving anything visible now. The mechanics of what each signature type lets an attacker do are covered in airdrop signature scams, and the single-signature takeover case in EIP-7702 airdrop phishing.

Two habits neutralize this pattern. First, interact from a dedicated low-value wallet — the burner wallet workflow exists precisely so that a bad signature costs pocket change, not a portfolio. Second, read the signature before confirming. A claim is a read operation from your wallet’s perspective; it almost never needs an approval, and it never needs a delegation.

Scam Pattern 4: Withdrawal-Fee Prepayment

The fee trap monetizes impatience. The bot shows a balance — earned or simply invented — and the “withdraw” button leads to a payment demand: a small TON transfer to “activate withdrawals,” cover “network fees,” or convert points to tokens. The amount is deliberately small, priced like a coffee so the victim’s risk calculation skips the “is this real” step entirely.

The payment completes; the withdrawal does not. Some versions escalate — an activation fee, then a “processing” fee, then a “minimum balance” fee — because a victim who has paid once is statistically likely to pay again to not “waste” the first payment.

The structural tell: in a legitimate claim, fees are gas, paid by your own wallet to your own transaction, to a verifiable claim contract on a block explorer. A transfer to a bot’s address to unlock a balance shown inside a chat app is not a fee. It is the purchase price of nothing.

Scam Pattern 5: Referral Loops That Weaponize Victims

Tap-to-earn games grow through referrals — your reward multiplies with every friend you bring. The scam version keeps that loop and aims it at people who trust you. Each victim who joins “for you” becomes a node recruiting their own contacts, and the scam spreads through the highest-trust channel that exists: a friend’s recommendation.

Some fake bots never steal from the player at all in the early stages. They build a graph of active crypto-curious users, then flip the switch — the “claim” phase opens, and the referral army is routed to a drainer page at once. Your defense extends past yourself: the moment you cannot verify a bot, stop forwarding it.

How Legitimate Telegram Airdrops Actually Work

The verification baseline is knowing what the real thing looks like.

StageLegitimate campaignFake bot
Entry pointLink from official channel / verified X / websiteDM, forwarded message, group invite
Gameplay phaseTapping and tasks only; no wallet requiredOften identical — that is the point
Wallet interactionOptional connect at claim time, official mini-app onlySeed phrase, wallet import, or signature prompts
ClaimOn-chain claim contract, announced officially”Unlock fee,” “activation payment,” or drainer claim page
FeesGas paid by your wallet to your transactionTransfer to a bot address
Source of truthProject’s official channels and contractThe bot’s own screens

The pattern to internalize: in the real format, nothing between “start playing” and “token exists” requires your wallet. A game that demands wallet access mid-loop has broken the format on purpose.

The Verification Sequence Before You Tap

  1. Find the official source independently. Search the project name, land on its official site or verified X account, and follow its Telegram link from there. Do not use the link that brought you.
  2. Match the username exactly. Compare the bot or mini-app handle against the official channel’s pinned announcement, character by character.
  3. Check the campaign timeline. Real campaigns publish snapshot and claim dates. A bot claiming a claim window “closes in hours” applies pressure because pressure works — see how deadline pressure is weaponized in snapshot verification scams.
  4. Inspect the claim contract on-chain when the claim goes live — contract age, deployer history, holder distribution. The five-step on-chain workflow is in airdrop scam checker.
  5. Play from a burner. Whatever the game, whatever the chain, the wallet you connect should be one you can afford to lose entirely.
  6. Revoke afterwards. If you signed anything, sweep your allowances with a revocation tool.

Limitations

This map covers the patterns, not the brands. New tap-to-earn campaigns launch continuously, and naming today’s “safe” list would age this article in weeks — the verification sequence is the durable part. Also note that even a fully legitimate campaign is a game with token economics attached: passing every safety check here means you will not be robbed, not that the token you receive will be worth anything. Safety and value are separate questions, and only the first one is on-chain.

The tap-to-earn era compressed the distance between “heard about crypto” and “signed a transaction” to a single chat app. The scams compressed the distance between “playing a game” and “losing a wallet” to a single screen. Both compressions are permanent — the format survived, which means the defenses have to be permanent too.

This article is part of our Airdrop Safety series.

Frequently Asked Questions

Are Telegram airdrop bots legit?

Some are. Notcoin, DOGS, and Hamster Kombat were real campaigns with real token distributions, delivered as Telegram mini-apps. But legitimacy is per-campaign, not per-format — for every real tap-to-earn game, there are cloned bots and fake mini-apps running the same visuals with a drainer behind the claim button. The format is neutral; the verification steps are not optional.

Why would a Telegram bot ask for my seed phrase?

It would not, if it were legitimate. Seed-phrase requests inside Telegram airdrop bots are presented as wallet 'verification,' 'sync,' or 'import to receive tokens' — none of which is a real technical requirement. A Telegram mini-app interacts with your wallet through a wallet connection at most, never through your recovery phrase. Any bot screen asking for 12 or 24 words is a direct theft attempt.

What do withdrawal-fee scams in Telegram bots look like?

The bot shows an accumulated balance, then demands a small payment — usually in TON — to 'activate' or 'unlock' the withdrawal. The payment goes to an attacker address and the promised tokens never arrive. Some versions loop the fee: an 'activation fee,' then a 'network fee,' then a 'conversion fee.' Legitimate airdrop claims may require gas on the destination chain, paid by your own wallet to a verifiable contract — never a transfer to a bot's address.

How do I verify a Telegram airdrop bot is official?

Start from the project's verified X account or official website and follow its link to Telegram — never from a DM, a group invite, or a sponsored message. Check the bot or mini-app username character by character against the official channel's pinned post, because clones use lookalike handles. Then confirm the campaign exists at all on the project's official announcements. If the only source for the bot is the bot itself, treat it as fake.

Can I participate safely without connecting a main wallet?

Yes, and that is the recommended setup. Use a dedicated low-value wallet for any airdrop interaction — the burner wallet workflow — and never import a wallet that holds your main funds into a Telegram mini-app. If a claim requires a signature, read what the signature authorizes before confirming, and revoke allowances afterwards. The tap-to-earn part of a legitimate game needs nothing from your wallet at all.