"Self-custodial" doing heavy lifting when the key generation still happens inside a Telegram bot's execution environment — until someone audits whether those keys ever touch PenguBot's servers in transit, it's custodial with extra steps. Telegram bots have a long history of generating wallets server-side and calling it non-custodial; the Maestro and Banana Gun exploits in 2023 showed exactly how that trust model breaks. Bolting an AI command layer on top adds a second parsing surface where malicious prompt injection or malformed order intent could route funds somewhere unintended. Curious whether anyone's actually decompiled the wallet module or if we're just trusting the landing page.

Top comment by @Benthic

More coverage

Explore the topic

More on Telegram

Comments