NexFlow › Is Trojan bot safe
Is Trojan bot safe?
Trojan on Solana is a legitimate, long-running trading product — the January-2024 bot built by the ex-Unibot team, now a suite with a web Terminal and Onchain Exchange. Its honest risk profile is the Telegram-bot category's: a key stored encrypted on someone else's server, a Telegram account as the control plane, and a standing wave of clone handles that steal more money than any exploit ever has.
What Trojan actually is
Trojan launched January 4, 2024 — founded by a team that broke off from Unibot, one of the earliest Ethereum trading bots (the founder goes by Reethmos publicly). It started as a Telegram-native Solana trading bot and grew into a suite: the original bot, a web Terminal, and an Onchain Exchange layering perpetuals. Trades route into real on-chain pools — Raydium, pump.fun curves and the rest of Solana's DEX set — with limit orders, DCA, sniper automation and copy-trading on top. It charges a flat 1% per successful trade, 0.9% via referral, per its own fee docs.
The referral machine, seen clearly
Trojan's growth engine is the referral program — up to 35% of fees distributed across five layers of referrers, with the referee paying 0.9% instead of 1% for life. Understand what that design does to your information diet: every 'Trojan review' comment, every 'try this bot' reply, every comparison post is financially motivated — the person recommending the bot earns from your trading forever. It doesn't make the recommendation false, but it means the enthusiastic coverage you will read was bought by the incentive structure. Judge the product on its custody model and its docs, not on the carpet of referral links under every thread about it.
The custody question, without the marketing
Trojan calls itself self-custodial: user keys are 'encrypted using industry-standard encryption', the team says nobody at Trojan can access them, and you can export or withdraw freely. The independent framing is more precise: non-custodial in design, custodial in operation. The bot cannot sign your trades without key material it can reach — so a working copy lives server-side, encrypted, under whatever internal controls Trojan runs. Compare it honestly against the category, not against an ideal: it is the same operational posture as every Telegram trading bot and every generated-wallet terminal; it is strictly better than a bot that can't explain its key handling; and it is strictly weaker than a wallet where only your device signs. The defense is the float rule — a dedicated bot wallet holding only the trading budget, profits swept out — plus our Telegram-bot safety guide for the full category playbook.
The attack that actually steals money: clones
The documented, recurring loss event in Trojan's orbit is not a server breach — none is publicly on record through mid-2026 — it is handle phishing. Fake Trojan bots surface on a monthly rhythm: same avatar, same name styling, handles off by an underscore or a swapped letter, arriving via replies, 'support' DMs and search ads. The real handle is @TrojanSolBot, reached from the project's own site and channels. The clone's product is the moment you paste a key or sign its 'verification'. Three rules cover most of it: never enter through a link someone sent; never paste a seed phrase anywhere (the real bot never asks in a DM); and treat any unsolicited 'support' contact as hostile. Our clone-apps playbook maps the same shape on the wallet side.
Telegram as the control plane
A TG bot binds your wallet's control surface to your Telegram account: whoever runs your TG session drives the bot — SIM-swap and session-hijack are therefore wallet risks, not just chat risks. The mitigations are boring and real: Telegram two-step verification on, active-session audit monthly, and the trading float kept small enough that a hijacked session can only burn the budget, not the stack.
Where it sits in the category
| Surface | Who can sign | Fee shape | Main attack |
|---|---|---|---|
| Trojan | Server-side encrypted key, TG-account control | 1% / 0.9% w/ referral | Clone handles + TG hijack |
| BullX / Photon | Generated wallet, session-signing copy | 1% flat | Clone sites |
| Axiom | Your wallet or Turnkey MPC session | % tiered by volume | Clone sites + session policy |
| Own wallet | You alone | Venue/aggregator fees only | Approval phishing — smallest surface |
Whatever you trade through, the token-side risk doesn't change — the bot executes your buy, it can't make the token honest. /check-token reads the mint's authorities, concentration and measured depth before size goes in; the first-hour checklist orders the same checks for speed; and /swap is the lane with no middleman key at all.
The verdict in one line: Trojan is a real product with the Telegram-bot category's standard custody — an encrypted server-side key it can sign with. The risk isn't that it's fake; it's the float you leave in, the TG account you guard, and the clone handles that outnumber the real one.
Frequently asked
Is Trojan bot legit or a scam?
The real Trojan is a legitimate, long-running Solana trading product — launched January 2024 by a team that broke off from Unibot (founder publicly known as Reethmos), now a suite: the Telegram bot, a web Terminal and the Onchain Exchange. The scam version of 'Trojan' is the clone: fake handles like @solana_trojanbot surface monthly and harvest whatever key you paste in. Verifying the handle is the first safety check — the real bot is @TrojanSolBot, and even then, treat any DM 'from support' as hostile.
Does Trojan hold your private keys?
The honest answer has two layers. Trojan calls itself self-custodial: keys are 'encrypted using industry-standard encryption' and the team says no one at Trojan can access them — you can export or withdraw any time. The operational truth independent reviewers use: the key material lives encrypted on Trojan's servers because the bot must sign on your behalf — 'non-custodial in design, custodial in operation'. It's the standard Telegram-bot posture: you hold an exit door, the service holds a working key.
What are Trojan's fees?
A flat 1% on every successful trade, dropping to 0.9% permanently if you signed up through a referral — per Trojan's own docs; failed transactions are not charged. On top sit Solana network costs, priority fees and whatever slippage you configure. There is no subscription. The referral program pays up to 35% of fees across five layers — which is why 'Trojan referral' links carpet every replies section: the discount is real, and so is the incentive to get you to click.
Has Trojan bot ever been hacked or exploited?
No exploit of Trojan's own bot infrastructure is publicly documented through mid-2026 — the verifiable statement. The threat model that actually bites in this category is different: phishing clones (fake Trojan handles are a documented monthly occurrence), Telegram account compromise (your TG session IS the control plane — hijack the account and the attacker drives the bot), and the standing server-side key risk that every trading bot carries by design.
How do I spot a fake Trojan bot?
The real handle is @TrojanSolBot — verified, and reached from the project's own site/channels, not from replies or ads. Fakes copy the avatar, name and bio almost exactly; they differ in the handle (extra underscore, swapped letters) and in what they ask for — a real trading bot never needs your seed phrase in a DM, never 'verifies your wallet' on an external site, and never DMs you first. If a 'Trojan' found you instead of you finding it, it's the clone.
Is a Telegram bot or a web terminal safer?
Different weak points, same category risk. Telegram bots keep server-side key material and bind control to your Telegram account — account compromise = wallet compromise, and clone-handle phishing is constant. Web terminals (Photon, BullX) hold generated-wallet keys under a web login — similar signing custody, different phishing shape (fake sites vs fake handles). Connected-wallet surfaces (any DEX in your own wallet) remove the middleman key entirely — the trade is seconds of speed for a whole attack surface.