Solana trading bots are safe enough for small, disposable amounts, but none of them are fully safe: they trade from hot wallets, and bots have been hacked, exploited, phished and shut down. Treat any bot wallet like cash in your pocket, not a savings account.
This guide covers how bot wallets work, what has actually gone wrong, and how to reduce your risk.
Why bots carry extra risk
A trading bot or terminal is fast because it signs trades for you. To do that, it creates a wallet and keeps the ability to sign from it. That's the trade-off:
- The key lives online. Trojan's docs tell users to "always treat your wallet as a hot wallet" (Trojan).
- Your chat or login is the front door. For a Telegram bot, whoever controls your Telegram account can usually control your bot.
- "Non-custodial" varies. Most bots say you own the wallet and can export the key. That's better than a custodial exchange, but the platform's software and staff are still in the loop.
- The platform can change. Bots get sold (Padre to Pump.fun, per Blockworks) or stop trading (BullX, June 2026, per crypto.news).
What has gone wrong: real incidents
Bots in our ranking
Maestro (October 2023). A flaw in Maestro's Router2 contract on Ethereum let an attacker take 280+ ETH (about $500,000) from users' approved tokens. Maestro shut the contract down within about 30 minutes and said it would refund users (The Block); Decrypt later reported 610 ETH in refunds (Decrypt). Maestro review
BONKbot (March 2024, disputed). About 302 Solana wallets were drained of about $523,000. 113 of the victims had used BONKbot, but BONKbot said all of them had exported their keys and imported them into another app (Decrypt). BONKbot review
GMGN (October 2025). GMGN's anti-MEV nodes on BNB Chain were sandwich-attacked for about 13 hours, affecting 729 transactions (Crypto Economy). Days later, a phishing attack via a fake token website hit about 107 users (PANews). GMGN said it compensated users in full both times. GMGN review
Axiom (February 2026). ZachXBT alleged that an Axiom employee misused internal support tools to look up users' wallet data and track traders, potentially to front-run them. Axiom removed that access and said it was investigating (CoinDesk). No funds were reported stolen. Axiom review
We found no confirmed platform exploit of Trojan, Photon, Padre (Terminal) or FOMO as of September 25, 2026. Photon clone sites that drain wallets have been reported (Photon Guides).
Bots that didn't survive
Helius's history of Solana hacks lists several bot-related losses:
- Solareum (March 2024): a breach allegedly involving a developer the team had hired compromised imported private keys. Losses were estimated at $520,000 to $1.4 million; the platform shut down and users weren't reimbursed.
- Banana Gun (September 2024): a flaw in its Telegram message oracle let an attacker take 563 ETH (about $1.4 million) from 11 wallets. Users were refunded from the treasury.
- DEXX (November 2024): a private key leak in a centralized custody setup exposed user wallets, with about $30 million lost; not reimbursed as of late November 2024.
In these examples, the bots that refunded users (Maestro, Banana Gun, GMGN) kept operating, while Solareum shut down and its users weren't repaid. How a team responds to an incident tells you a lot.
The most common ways traders lose funds
Beyond platform hacks, watch for these simpler problems:
- Fake bots and clone sites. A look-alike Telegram handle or URL asks you to "connect" or paste a key. Trojan's docs: "Always use official links!"
- Hijacked Telegram accounts. Without two-step verification, a SIM swap or a stolen session can hand over your bot.
- Exporting keys into untrusted apps. That's what BONKbot said happened in 2024.
- Malicious approvals. GMGN advises users to regularly revoke unfamiliar wallet authorizations (GMGN).
- Copying the wrong wallets. Copy trading can follow a wallet into a rug. See best Solana copy trading bots.
10 steps to protect yourself
- Use a dedicated trading wallet. Never your main wallet.
- Keep only what you'd accept losing in the bot, and withdraw profits often.
- Enable Telegram two-step verification and any bot password, such as Trojan's Secure Action Password.
- Bookmark official links. Don't click bot links from DMs, ads or replies.
- Never share your private key or seed phrase. No real support team asks for it.
- Don't import bot keys into other apps unless you fully trust them.
- Turn on MEV protection where available to reduce sandwich attacks.
- Check the bot's incident history and how it responded. Our reviews list what we found.
- Test withdrawals early with a small amount.
- Watch for platform changes: acquisitions, token changes, trading pauses. Move funds out if something looks off.
How we factor safety into our ranking
Security is 25% of every rating on SolBotRank. Each bot starts at 9, loses a point per confirmed platform-side incident affecting users' funds or data since 2023, gets half a point back if users were compensated or the issue fixed, and loses half a point for disputed incidents. See our about page and the full ranking. New to all this? Start with what is a Solana trading terminal or how to use Trojan bot.
Risk note
Even with perfect security habits, memecoin trading is extremely high risk: tokens can lose most or all of their value in minutes, and there are no guaranteed returns. Bots can be hacked, shut down or exit-scam. Only trade what you can afford to lose completely.