How Volume Bot Scams Work, and the Checks That Catch Them

By Kristjan Kask, Founder at PumpWave Labs6 min read

The five patterns are a seed phrase or private key request, a guaranteed trending slot, a dashboard that shows activity with nothing on chain behind it, a fee that only becomes clear after you have funded something, and a downloadable installer that drains the wallet it connects to. Four of those are caught by one question: can I verify what this does on chain before and while it runs? The seed phrase one needs no check at all, because no legitimate session ever needs your keys.

Short version

  • Nobody needs your seed phrase. Not for a volume session, not ever, no matter what the interface says.
  • A guaranteed trending slot is a promise about a third party ranking that the seller does not control.
  • Every trade a real session places has a signature. If you cannot find them on an explorer, they do not exist.
  • The fee should be a number you see before funding. Anything else is a negotiation you already lost.
  • Downloadable installers concentrate the risk: one binary, full machine access, and your wallet in the same room.

Pattern one: the key request

The most direct one. An interface asks you to paste a seed phrase or a private key "so the bot can trade for you". The justification is sometimes technically plausible sounding, and it is always wrong. A volume session needs a mint address and a payment. The wallets that do the routing are generated by the engine and funded from the session deposit, and your own wallet only ever signs a transfer you approve yourself.

There is no version of this that is acceptable. A key request ends the evaluation, and it ends it regardless of how polished the site is, how long it has existed or who recommended it.

Pattern two: the guarantee

A promised trending slot, a promised market cap, a promised price or a promised number of holders. None of these are inside any tool. Trending is a ranking computed by a third party from inputs the tool touches only partially, and price is decided by people who are not you. A seller who promises them is either describing something they cannot deliver or setting up the excuse for when it does not arrive.

The honest version of the claim is narrow and verifiable: the session routes this volume, across this many wallets, over this long, and here are the signatures. Everything past that is a forecast. What each board actually sorts on is set out in does a volume bot get you trending.

Pattern three: the theatre dashboard

A panel that shows orders filling, wallets rotating and volume climbing, all rendered in the browser and none of it on chain. This is the most sophisticated pattern, because the product looks like it is working right up until you check.

The check takes a minute. While the session is running, open the token on an explorer and look at recent transactions. You should see trades landing at the rate the panel claims, from addresses that are not yours, at sizes in the band you configured. If the panel says 800 orders have filled and the chain shows nine, there is nothing to discuss.

Do this on the first session, not the fifth, and do it while the run is live rather than afterwards.

Pattern four: the fee that appears later

You are quoted a rate, you fund a session, and then there is a network fee surcharge, or a withdrawal fee on the remaining capital, or a minimum you did not meet, or a per transaction charge stacked on the percentage you already agreed. The pattern relies on the money already being somewhere you cannot easily take it back from.

The defence is structural rather than vigilant: prefer an arrangement where the fee is a number displayed before you send anything, and where there is no balance to withdraw because nothing is custodied. The full breakdown of which lines are real and which are invented is in how much a volume bot costs.

Pattern five: the installer

A desktop application you download, often distributed through a chat group, sometimes with a legitimate looking site behind it. It asks to connect a wallet, or to import one, and it has full access to the machine that wallet lives on. Wallet drainers have been distributed this way at scale and the binaries are frequently signed and clean-looking.

A browser based session that never handles your keys has a much smaller blast radius, because the worst case is a transfer you declined to sign. If a tool must be installed, it should be because it genuinely needs local resources, and a volume session does not.

The check list

  1. Does it ask for keys?

    If yes, stop. There is no further evaluation to do and nothing else on the page matters.

  2. Is the fee visible before funding?

    Find the exact number in the interface before sending anything. If it only appears in a conversation, it is not a price.

  3. Can you verify the first session on chain?

    Run the smallest size available and watch the explorer while it runs. Count trades, check addresses, check sizes against your configuration.

  4. Is anything guaranteed?

    A promised trending slot or price is a promise about something the seller does not control. Treat it as information about the seller.

  5. What happens to unspent capital?

    The answer should be that it returns to the wallet that funded the session, automatically, with the token account rent released. Vagueness here is the whole scam in one answer.

How we are structured

PumpWave runs in the browser, never asks for a key or a seed phrase, and generates its own ephemeral wallets for the routing. The fee is a flat 1% of the target volume and it is displayed before anything is funded, from 100 SOL up. There is no deposit, no internal balance and no withdrawal flow, because there is nothing held to withdraw: the session capital funds the wallets and the remainder returns to the wallet that sent it. Every trade is an ordinary Solana transaction you can look up while it is happening, and we would rather you did.

Questions people actually ask

Is there any reason a volume bot would need my private key?

No, a volume bot never needs your private key. The routing wallets are generated by the engine and funded from the session deposit. Your own wallet only ever needs to sign a transfer you approve. A key request has no legitimate technical justification.

How do I verify a session is real?

Open the token on a Solana explorer while the session is running and compare what you see to what the panel claims: the number of trades, the addresses placing them, and whether the sizes fall in the band you configured.

Are Telegram-based volume bots more dangerous?

The interface is not the risk, custody is. The relevant question is whether the tool holds keys or asks you to import one, and that can be true or false on Telegram, on the web or in a desktop app.

What if a service has good reviews?

Reviews for this category are close to worthless: they are cheap to fabricate and the people posting them are anonymous. The on-chain check takes a minute and produces evidence rather than opinion.

Should I start with the smallest session?

Yes, always, with a service you have not used. The purpose of the first run is not the volume, it is finding out whether the trades appear on chain and whether the unspent capital comes back.

I connected a wallet to something suspicious. What now?

Move the assets to a wallet whose keys that site never saw, and revoke any token approvals granted from the old one. A read-only connection that only exposed a public key is not a compromise, but a signature you do not recognise is.

Run one and watch it land

Paste a mint, shape the session, see the exact fee before you fund anything. Flat 1% from 100 SOL, no install, no seed phrase.

Open the console
Kristjan Kask, Founder

Builds and runs the PumpWave session engine at PumpWave Labs in Estonia. Writes about Solana launch mechanics from the operator side: what settles, what it costs, what the board does with it. Corrections and arguments to support@pumpwave.net.