BTC:
ETH:
SOL:
BNB:
XRP:
Telegram trading bot

Trojan: chat speed depends on delegated wallet access

Trojan turns messages and buttons into Solana transactions. The convenience is real, but so is the authority behind it: encrypted keys, persistent automations, Telegram account security, and one-tap settings all sit inside the same workflow.

11 min readReviewed July 14, 2026Independent guide

The short answer

Trojan on Solana is a Telegram trading bot with market swaps, positions, wallet management, limit and DCA orders, copy trading, sniping, watchlists, bridging, and automated buy and sell rules. Trojan also offers a separate web terminal; this guide focuses on the Telegram bot because its chat interface, bot identity, and wallet authorization create a distinct risk model.

Telegram is the control surface, not the chain

Trojan's main menu exposes swaps, positions, orders, copy trading, wallet actions, and settings. Pasting a mint address can open a trade panel; with AutoBuy or confirmations disabled, a short interaction can submit an order immediately. Backup Trojan bots can share the same wallet addresses and settings.

That makes bot identity critical. Enter only through links published on the official Trojan domain, compare the exact username, and distrust direct messages, support outreach, copied bots, and “verification” prompts. A fake Telegram bot can imitate the interface while collecting a key, seed, password, or deposit. Review bot and DM scams before funding any chat-based trading wallet.

Exportable keys are not the same as local-only keys

Trojan allows users to export generated wallet private keys and import an external Solana wallet by pasting its private key. The product docs say keys are encrypted. Trojan's current terms are more specific: they state that Trojan or a third-party provider may retain an encrypted copy of a trading-wallet seed or key to sign transactions after the user delegates authority.

That is a hot-wallet model with remote signing capability, even though the user can export the key and the assets remain onchain. Do not import a primary wallet. Generate or dedicate a small operational wallet, export its recovery material, store it offline, and move long-term holdings elsewhere. Exporting a key does not prove that every encrypted server copy or delegated authorization has disappeared.

Secure both the Telegram account and sensitive actions

Trojan documents a Secure Action Password for sensitive wallet actions. Use it, secure Telegram with a unique password and two-step verification, review active Telegram sessions, hide lock-screen previews, and protect the email or phone used for recovery. These layers reduce account-takeover risk but do not change the underlying hot-wallet exposure.

Test export and withdrawal while the balance is small. Record how to reach the wallet without the primary bot, and verify that a backup bot is listed by Trojan before using it. If Telegram or Trojan is unavailable, an exported key should still let you move assets through a standard Solana wallet.

Gas, slippage, and MEV settings authorize different risks

Trojan publishes Fast, Turbo, and custom priority-tip choices, plus slippage and MEV protection settings. Its current buy guide describes 15% as the default slippage starting point. That is a vendor preset, not a universally safe tolerance. Fifteen percent authorizes a materially worse fill before the order fails.

Set slippage from the pool depth, route, volatility, and maximum acceptable loss. A larger tip can improve priority but cannot guarantee success. Trojan says its protected path may wait for a protected slot, trading speed for a different submission route. Neither setting protects against a malicious token, linked insiders, manipulated liquidity, or a bad entry.

A copy trade is your own delayed market order

Trojan supports fixed or percentage buys, copied sells or Auto Sell, maximum buy limits, first-buy versus duplicate-buy behavior, liquidity and market-cap filters, blacklists, retries, and separate buy and sell settings. Those controls can bound a strategy, but they cannot copy the target's time, price, size, or complete behavior.

Trojan's own documentation warns that sniper wallets can make followers exit liquidity and that custom programs are not copied because they can create fake swap patterns to exploit bots. Reconstruct the target wallet, cap every copy, exclude unverified programs, and judge follower P&L after latency, failed copies, fees, and unmatched sells.

Limit and DCA orders remain active instructions

Trojan limit orders can trigger on price, market cap, percentage change, migration, developer sale, or schedule. Limit sells include take-profit, stop-loss, and trailing-stop forms. DCA orders split buys or sells over time; the official DCA documentation warns that an order without a duration can continue until the selected wallet is exhausted or the token balance is gone.

A trigger submits a swap after its condition is observed. It does not reserve liquidity or guarantee the trigger price. Review active orders after every manual trade, transfer, migration, and wallet change. Pause copy trading and cancel DCA, auto-sell, and limit orders before assuming the bot has no remaining authority to act.

Cashback does not erase the fee

Trojan publishes a 1% charge on successful transactions and 20% cashback on trading fees. Record the full fee when charged and the rebate separately when it is actually credited. Add launchpad or DEX fees, network and priority costs, validator tips, token-extension transfer fees or taxes, price impact, and slippage.

The terminal percentage can dominate frequent entries and exits, while a fixed tip dominates small orders. Copy trades, DCA legs, retries, and automated exits can create far more paid transactions than one manual round trip.

A safer evaluation workflow

  1. Verify the bot from the official site. Save the exact username and reject every unsolicited admin or recovery message.
  2. Create a dedicated wallet. Export it, test it in a standard wallet, set the Secure Action Password, and fund a minimal balance.
  3. Keep confirmations on. Disable AutoBuy and persistent automations until manual trades are fully understood.
  4. Test one tiny swap. Match the mint, selected wallet, settings, fee, signature, and final deltas on Solscan.
  5. Rebuild any wallet before copying it. Inspect funding, transfers, programs, cost basis, exits, and whether the strategy is copyable.
  6. Audit active authority regularly. Review copy, limit, DCA, auto-buy, auto-sell, sniper, Telegram sessions, and wallet balances together.

What belongs in the journal

Record the exact bot identity, wallet address, mint and pool, confirmation mode, slippage, priority tip, MEV mode, automation rules, copied wallet and filters, platform fee, cashback status, venue costs, signature, landed deltas, and timestamp. Keep a current inventory of every active instruction that can still trade.

Primary sources

Turn the message into evidence

Record every instruction the bot can still execute.

Connect the chat action to its wallet, settings, signature, fees, and active follow-up orders.

Open the journal