This article is educational, not trading or legal advice. A token, channel, or contract can change while you investigate it. Do not sign a transaction or transfer funds because a message creates urgency.
A pump-and-dump scheme coordinates attention and buying pressure around an asset, then sells into that demand. Telegram is well suited to the tactic: a public channel creates a narrative, a chat creates urgency, and a bot or Mini App can direct users to a contract or marketplace. The central risk is information asymmetry. Coordinators may know the distribution, unlocks, liquidity controls, and exit plan while followers see only the promotion.
How the coordination works
Build attention
The promoter presents a token as a private opportunity, imminent listing, exclusive signal, or community reward. Repeated posts, countdowns, referral contests, and copied endorsements create the appearance of independent demand. A large audience or a verified-looking profile does not establish that the contract is safe or that the market is fair.
Create a thin market
The token may have little freely traded supply or shallow liquidity. A small number of purchases can move the displayed price. The promoter then points to that movement as evidence that the project is succeeding. A chart can rise while the amount that could actually be sold is limited.
Sell into followers
Early holders or insiders sell while later participants are encouraged to buy. The price can fall when promotional messages stop, liquidity is removed, an unlock occurs, or the market discovers that demand was coordinated. A follower may be unable to exit at the quoted price because slippage, fees, transfer restrictions, or a missing buyer changes the result.
The same flow can occur without a token: a collectible, presale allocation, mining balance, or “investment group” can be used to collect deposits and then impose a withdrawal condition.
Observable red flags
Treat the following as signals requiring verification, not as proof by themselves:
- a demand to buy within a countdown or before a secret announcement;
- claims that a group has guaranteed allocation, insider access, or risk-free upside;
- pressure to recruit friends or pay a fee to unlock a higher tier;
- anonymous operators who cannot document the legal entity, contract, or distribution;
- a token address that changes without a clear first-party explanation;
- disabled comments, deleted questions, or bans for asking about supply and liquidity;
- a chart or balance shown without an independently verifiable transaction;
- a claim that selling is temporarily blocked for “technical” or “tax” reasons.
The most important red flag is a mismatch between the promotion and the transaction. If a post promises one asset or network but the wallet request names another, reject it.
On-chain verification
Contract and distribution
Find the contract address through the project’s official documentation, not a forwarded Telegram message. Compare it with an independent explorer. Check the network, deployment history, verified code where available, minting functions, blacklist or pause controls, fee settings, and administrator privileges. A familiar ticker is not an identity.
Inspect holder concentration. A few wallets controlling a large share can create significant selling pressure, but a dispersed holder list is not a safety certificate: wallets can be related, and exchange or contract addresses may distort the view. Record the holder list and block height or timestamp you used.
Liquidity and control
Identify the trading pair and the liquidity pool contract. Check whether liquidity is actually present, whether it is locked, who controls the lock, and when it can be withdrawn. “Locked liquidity” is not meaningful without a verifiable locker contract and expiry. A project may also retain the ability to mint, change fees, blacklist accounts, or upgrade the contract.
Do not connect a valuable wallet merely to inspect a token. Public explorers usually provide enough information for an initial review. If the project cannot explain its controls in official documentation, do not rely on a promotional guarantee.
Trades and exit conditions
Look beyond the last trade. Compare buy and sell transactions, the number of independent wallets, the size of trades, and the route through the liquidity pool. Wash trading or repeated transfers between related addresses can create artificial activity. A high displayed price does not prove that a normal-sized sell can execute.
If a simulator is available, treat it as an estimate. Confirm the minimum received, slippage, deadline, network fee, and any token transfer fee in the wallet. Reject unlimited approvals and unexpected payloads. Never pay a separate “withdrawal tax” to release a balance that is not independently verified.
For TON transactions, inspect the message and resulting state in Tonviewer. For other networks, use the explorer named in the project’s first-party documentation. The internal Telegram scam verification guide covers impersonation and fake support; the crypto signals guide explains why a signal is not independent research.
Why signal timing disadvantages followers
A signal arrives after someone has chosen what to promote, when to publish, and which data to omit. The follower does not know whether the sender already bought, receives an allocation, or plans to sell into the announcement. By the time a message becomes widely visible, the liquidity and price may already reflect the coordinated demand.
Even an honest alert can be unusable: the contract may have changed, the pool may be too shallow, or the quoted price may be from a tiny trade. Do not convert a message into an automatic order. Verify the asset independently and decide whether you are willing to lose the entire amount before interacting with it.
Preserve evidence
If a promotion appears fraudulent, preserve evidence before blocking or deleting it:
- exact usernames, channel and group links, and numeric IDs where visible;
- original message links, text, attachments, destination domains, and timestamps;
- contract, wallet, pool, and recipient addresses;
- transaction hashes and explorer URLs;
- payment receipts, exchange tickets, and withdrawal messages;
- a timeline of contact, deposit, signature, and attempted withdrawal.
Keep original exports unchanged and make a separate redacted copy for sharing. Do not include recovery phrases, private keys, passwords, or login codes. Note the time zone used for timestamps.
Reporting and incident response
Report the message, account, channel, or group through Telegram’s in-app reporting controls. Include the original message link and explain the impersonation, deceptive promotion, malicious contract, or payment demand. Use the current Telegram FAQ security guidance for account protection.
For internet crime involving a US nexus, submit the evidence to the FBI Internet Crime Complaint Center. For commodity or derivatives-related manipulation, consult the CFTC complaints and tips page. The CFTC digital-asset fraud guidance explains relevant warning signs. For investment promotions, review Investor.gov internet and social-media fraud guidance.
If you signed a malicious transaction, disconnect the application and review wallet permissions. If a recovery phrase or signing device was exposed, treat the wallet as compromised and move remaining assets to a newly generated wallet from a clean environment. Contact a custodial service only through its official help centre. Anyone promising guaranteed recovery for an upfront fee is a recovery scam.
What cannot be inferred
No channel size, token chart, audit badge, liquidity label, or influencer endorsement can prove future value or honest intent. On-chain data can show transactions and controls, but it may not reveal who coordinates wallets or what an operator plans to do next. Verification reduces avoidable risk; it cannot make a speculative asset safe.