How to Set Up a TON Wallet: Custody, Recovery, and Safe Transactions

This is an educational security guide, not financial advice. Wallet interfaces, supported networks, and service terms can change. Confirm every transaction in the current wallet and official documentation.

A crypto wallet does not store coins in an app. Assets remain recorded on a blockchain; the wallet holds keys and creates messages that authorize changes to that record. The most important setup decision is custody: who controls the signing key and who can help if access is lost?

Custody models

Custodial wallets

A custodial service controls the blockchain keys or controls the account system used to execute transactions. The service may provide password recovery, identity checks, internal transfers, and support. In exchange, you depend on its availability, account rules, security controls, and withdrawal process. A balance shown in a custodial interface may be an internal record rather than an on-chain transaction.

Telegram’s Wallet help centre documents its services and current conditions. Read the current terms before depositing funds. Never assume that a Telegram bot is official merely because its name resembles Wallet; follow the link from the official help centre.

Self-custody

With self-custody, the recovery phrase or private key controls the wallet. The provider cannot reset it. Anyone who obtains the phrase can usually control the assets, while losing it can make the assets inaccessible. A support agent, developer, or “recovery service” must never receive it.

Tonkeeper is a self-custody wallet. TON Space is a wallet experience integrated into Telegram; its custody model and available functions must be checked in the current product documentation. These names describe products, not a safety guarantee. Choose based on the custody model you understand and the recovery process you can perform.

Set up a wallet safely

Use the provider’s official website, Telegram’s official app listing, or the current TON documentation. Check the domain character by character and avoid sponsored links, forwarded files, and unsolicited direct messages. Install updates through the platform’s normal store or the provider’s documented route.

For Telegram Wallet, start with Wallet help. For the TON ecosystem, use TON documentation and the official Tonkeeper website. Do not enter a recovery phrase into a website.

2. Understand what account you are creating

Read whether the flow creates a custodial account, an externally controlled wallet, or a wallet connected to an existing Telegram identity. Note how deposits, withdrawals, internal transfers, and recovery work. If the product does not clearly explain custody, pause before depositing.

Record the network separately from the asset. TON, jettons, NFTs, and assets on another chain can use different address formats and transfer routes. A matching ticker is not enough.

3. Create and protect recovery material

For a self-custody wallet, create the wallet in a private environment. Write the recovery words on paper or another durable offline medium. Do not photograph them, store them in cloud notes, paste them into a password manager without understanding the threat model, or send them through Telegram, email, or support chat.

Keep the backup protected from visitors, malware, fire, and water. Do not make extra copies casually. If a provider offers an alternative backup mechanism, read exactly who can access it and whether it changes custody.

4. Verify the backup with a recovery test

Before depositing meaningful funds, test that the written backup works:

  1. install the wallet from its official source on a separate or reset device;
  2. choose the restore/import flow;
  3. enter the words offline and confirm that the expected address appears;
  4. compare the address with the original wallet;
  5. remove the test installation and keep the backup offline.

Never “test” a phrase by entering it into a web form or sending it to another person. If the restored address differs, stop. Do not transfer funds until the discrepancy is understood.

Address, network, and memo checks

An address is not a human-readable name. Copy it from the recipient’s trusted wallet and compare the beginning and end after pasting. For a first transfer, send a small test amount that is small in context, not a fixed dollar amount. Wait for the result in an independent explorer before sending the remainder.

Confirm all of the following:

  • the selected network is the one the recipient supports;
  • the asset is the intended TON coin, jetton, or NFT;
  • the recipient address is correct;
  • a memo or comment is required, optional, or prohibited;
  • the wallet shows enough TON for the network message and service charges;
  • the recipient has confirmed receipt on-chain.

Some custodial services require a memo or tag to credit a deposit. A self-custody address may not use one. Never invent a memo and never assume that a transfer can be reversed.

The TON transaction-fee documentation explains why fees vary by message and contract. A fee quoted in an old guide is not a current guarantee.

Telegram Wallet and TON Space

Telegram-based wallet features can be convenient for payments and Mini Apps, but convenience adds trust boundaries. Telegram account access, the wallet service, and the blockchain are not the same system. A Telegram login does not prove that a bot or Mini App is official.

Use the current Wallet identity-verification documentation to understand when a service may request identity information. Do not create a second account to bypass a service rule. Do not send identity documents to a bot or site that is not linked from the official help centre.

When moving assets between a custodial Wallet balance and an on-chain TON wallet, read whether the action is an internal transfer, a blockchain withdrawal, or a cross-chain operation. Check destination network, address, memo, and the displayed fee before confirming.

TON Connect permissions

TON Connect lets a TON application request a wallet connection and send transaction requests. A connection is not approval of every future transaction. The protocol also does not certify the application.

The TON Connect documentation describes the protocol. Before signing:

  1. confirm the Mini App domain and project identity;
  2. inspect the destination address, value, asset, payload, and valid-until time;
  3. reject unexpected transfers, unlimited approvals, or unrelated NFT operations;
  4. use a separate wallet for unfamiliar applications;
  5. disconnect after the task and review wallet connections regularly.

Telegram Mini Apps are web applications launched from bots or Telegram interfaces. Read the official Mini Apps documentation. A Mini App can prepare a request; your wallet still needs to show and obtain approval for the transaction.

Phishing and compromise recovery

Common phishing messages promise an airdrop, urgent verification, a refund, or a support intervention. The attacker may copy an official logo and ask for a recovery phrase, a one-time code, or a signature. No legitimate support workflow needs your recovery phrase.

If a Telegram account or custodial account may be compromised:

  1. secure the email and Telegram account first, including active sessions and two-step verification;
  2. contact the provider only through its official help centre;
  3. stop signing and revoke or disconnect suspicious wallet sessions;
  4. move remaining self-custodied assets to a newly generated wallet if the phrase or device is compromised;
  5. preserve transaction hashes and report theft to the relevant service and authorities.

If the recovery phrase was exposed, consider the wallet compromised even when no funds have moved. Creating a new wallet with the same phrase does not fix the exposure.

Key official sources

Use the current provider documentation and the wallet’s transaction screen as the source of truth. A wallet can help sign a transaction, but it cannot make an unsafe recipient, contract, or website trustworthy.

Coins from this guide