This guide explains decentralised-finance mechanics on TON. It is not investment advice and does not recommend a protocol or strategy. Contracts, interfaces, fees, and risk controls can change; verify current details before signing.
DeFi applications let smart contracts hold assets and execute rules without a traditional account manager. On TON, a user may interact with a decentralised exchange, liquidity pool, lending contract, bridge, or yield interface through a web app or Telegram Mini App. The interface is only a front end. The contract, wallet request, and settlement transaction determine what actually happens.
How a TON swap works
A swap exchanges one asset for another through a pool or routing contract. The app selects a route, displays an estimated output, and asks the wallet to sign a message. The pool’s reserves and its pricing function determine the execution result. A route can involve multiple pools and contract messages.
Before signing, verify the input asset, output asset, recipient, route, minimum received, deadline, attached TON, and transaction payload. A token name or symbol is not enough to identify an asset. Compare the contract address with the protocol’s official documentation and an independent explorer such as Tonviewer.
Price impact and slippage
Price impact is the movement caused by your own trade relative to the pool’s available reserves. Slippage is the difference between the expected and executed result. They are related but not identical: a volatile market, delayed message, route change, or fee can affect execution.
Set a tolerance that reflects the transaction you intend to make, and understand that a wide tolerance can permit a materially worse result. A transaction that fails because the minimum output is not met is different from one that succeeds at an unexpected price. Read the wallet prompt and the protocol’s current documentation.
Liquidity pools and LP shares
Liquidity providers deposit assets into a pool and receive a representation of their share. Traders use the reserves; the protocol may distribute fees or other rewards according to its contract rules. An LP share is not a bank deposit and does not guarantee that the original assets can be withdrawn in the same proportions.
Impermanent loss
When the relative prices of pool assets change, arbitrage trades can rebalance the reserves. An LP may then withdraw a different asset mix from the one deposited. The difference compared with simply holding the assets is commonly called impermanent loss. It can become permanent when the position is withdrawn. Fees or incentives may offset or fail to offset that difference; do not assume a positive result.
Before depositing, read the pool contract, withdrawal conditions, reward token rules, and what happens when a token is paused or migrated. Test the withdrawal interface with a small, context-appropriate transaction rather than relying on an interface balance.
Protocol and contract verification
Identify the official interface
Follow the protocol link from its official documentation. Check the domain carefully and avoid shortened links, copied Telegram bots, and unsolicited support accounts. A Mini App opened inside Telegram is still a web application with its own publisher.
DeDust’s official documentation is at docs.dedust.io. STON.fi publishes its protocol information at docs.ston.fi. Use those sources to identify contracts and supported operations. Do not choose a protocol because a channel calls it “best.”
Check the contract and controls
Compare pool, router, token, and farming-contract addresses with the protocol’s first-party documentation and an independent explorer. Review whether contracts are upgradeable, paused by an administrator, or able to change fees, token lists, or oracle sources. An audit can help identify code issues but is not a guarantee against loss.
Token contracts can include minting, blacklist, transfer-fee, or freeze controls. A pool can be drained by a bug, manipulation, or malicious administrator. If the documentation does not explain who controls the contract, treat the uncertainty as a material risk.
TON Connect and custody
TON Connect links a DeFi interface to a wallet. It does not certify the interface or contract. The TON Connect documentation explains the connection and transaction flow.
Keep long-term holdings separate from a wallet used for experimentation. Before signing:
- verify the application domain through a first-party source;
- confirm network, asset contracts, recipient, and route;
- inspect value, payload, minimum output, and deadline;
- reject unrelated NFT transfers or unexplained approvals;
- review the resulting messages in an independent explorer;
- disconnect the application after the task.
For custody and recovery practices, see the TON wallet setup guide. Never enter a recovery phrase into a DeFi site, bot, or support chat.
Oracle, bridge, and admin risks
Oracles
Lending, derivatives, and some automated strategies depend on price oracles. An oracle can be delayed, manipulated, unavailable, or based on a thin market. Check which source a protocol uses, how often it updates, and what happens when prices are missing.
Bridges
Bridges lock or monitor assets on one network and represent them on another. They add contracts, validators, relayers, and message-delivery assumptions. Verify the bridge operator, canonical asset, destination contract, and withdrawal process. A bridged token is not automatically the native asset.
Administration
An administrator may upgrade a contract, pause withdrawals, change supported assets, or alter parameters. Read the governance and emergency documentation. A decentralised interface can still depend on a small set of keys or a central service.
Pre-deposit checklist
Before depositing into a pool, lending market, or automated strategy:
- identify the official domain and contract addresses;
- read deposit, withdrawal, pause, and upgrade rules;
- confirm the asset and network;
- understand pool reserves, price impact, slippage, and LP-share accounting;
- check oracle and bridge dependencies;
- determine who controls admin keys;
- estimate variable network and protocol fees from the current wallet screen;
- use a separate wallet and keep recovery material offline;
- decide in advance what evidence you will keep if the transaction fails.
Do not deposit because a dashboard displays a large balance or because an anonymous channel promises passive income. A displayed rate is not a guarantee and may change as reserves, utilization, or incentives change.
Exit and incident response
To exit, use the protocol’s documented withdrawal path and inspect the wallet request. Confirm destination, asset, amount, minimum received, and any unlock or cooldown condition. If the interface is unavailable, do not follow a private “recovery” link or send funds to an agent.
If you signed an unexpected transaction, save the hash, disconnect the interface, and review wallet permissions. If a recovery phrase or signing device was exposed, create a new wallet from a clean environment and move remaining assets. Preserve the domain, bot username, original message, contract addresses, payload, timestamps, and explorer links.
Report impersonation or malicious messages through Telegram’s in-app tools. The internal crypto scam verification guide explains evidence preservation and reporting.