How to stop bots and multi-accounts in Telegram mini apps and airdrops
Telegram mini apps made it easy to reward millions of users, and just as easy for farms to pose as millions of users. Accounts are cheap, bots can tap all day and referral trees grow overnight. This guide covers how to tell real players from farms before the airdrop or the withdrawal.
Short answer
Telegram initData tells you which account opened the mini app, not who is holding the phone, so scan the device in Telegram's built-in browser and check it before the claim or withdrawal. Link accounts by device and wallet, delay and cap referral rewards, and hold instead of banning.
- Strongest links
- One device or one TON or USDT wallet behind many accounts.
- Premium accounts
- A useful positive signal, not proof: farms buy Premium too.
- Account ID
- Use a prefix such as tg:12345 and verify initData on your server first.
- When to check
- When the mini app opens and when the user claims.
Why mini apps attract farms
A Telegram account costs a few cents and a phone number. Tap-to-earn games, quest apps and airdrops pay per account, per referral or per task. That turns account creation into a business: one person with a room of phones, emulators or a script can register hundreds of accounts, refer them to each other and claim the rewards of all of them.
The damage shows up late. Token distributions go to farms instead of players, referral budgets pay for fake users, advertisers who paid for "users" through offer tasks reverse the conversions, and real players leave when the leaderboard is full of bots.
What Telegram tells you, and what it does not
A mini app receives signed initData from Telegram: the user ID, name, language and whether the account has Premium. Always verify the signature on your server; unsigned data can be forged by anyone calling your API directly.
What initData does not tell you is who is holding the phone. Two hundred accounts on one device look like two hundred users. The account age is not included, the language is whatever the account set, and there is no phone number or IP address. You need signals from the device and the connection.
Signals that expose farms inside a mini app
The mini app runs in Telegram's built-in browser, so a browser collector works there like on a website. These are the signals that separate farms from players:
| Signal | What it catches |
|---|---|
| Device shared by accounts | One phone or emulator logging in as many Telegram users |
| Emulator or virtual machine | Android emulators and VM farms running many clients |
| Automation detected | Scripts and headless browsers tapping for accounts |
| VPN, datacenter or Tor | Farms hiding behind servers, often the same few networks |
| Timezone and language mismatch | Residential proxies that change the IP but not the device |
| Wallet shared by accounts | Several accounts claiming to one TON or USDT address |
| Too fast, too regular | Tasks completed at machine speed or at the same second every time |
None of these alone proves fraud: families share phones and some players use VPNs. Two or three together, or one strong one like a shared wallet, make a clear case.
Referral trees and airdrop farms
Farms love referral programs because they can refer themselves. The pattern is a tree where the parent and most children share devices, networks or the claiming wallet. Paying referral rewards only when the referred account passes the same checks, and only after it has been active for a while, removes most of the profit.
- Delay referral rewards until the referred account has passed its first check and done something real, such as completing a task days later.
- Cap rewards per device and per wallet, not only per Telegram account.
- Check the whole tree when one account is confirmed as fraud: its referrer and siblings often share the same devices.
Sponsored tasks and offerwalls inside mini apps
Many mini apps pay for their rewards with sponsored tasks: join a channel, start another bot, install an app or complete an offer from an offerwall. The sponsor pays per completed task and checks the quality later. When farms complete those tasks, the sponsor sees channels full of accounts that never read a post and installs that never open again, and your mini app is the one that loses the deal.
Check the account before paying for a task the same way you check it before a claim, and log each task start with the offer ID. When a completion arrives much faster than the task allows, or from a device already linked to other accounts, hold the reward. It protects the sponsor relationship as much as your own budget.
Measuring how much of your audience is a farm
Before changing any rule, get a number. Run the checks in shadow mode for a few days and look at three figures: the share of accounts linked to at least one other account by device or wallet, the share of claims from emulators, VMs or datacenters, and how many accounts share each wallet. Healthy communities have a small, stable share. A tap-to-earn game in the middle of an airdrop campaign often finds that a third or more of its "users" sit on a few hundred devices.
That number is also what you show partners and token holders: a clear, dated measure of how many rewards went to people rather than farms.
Check before the claim, not after the airdrop
Once tokens are distributed or a withdrawal is sent, the money is gone. The moment to check is the claim: when an account asks to withdraw, connects a wallet or becomes eligible for the airdrop. At that point you have its full history: devices, networks, tasks, referrals and the wallet it wants to be paid to.
- Collect a device scan when the mini app opens and when the user claims.
- Send the claim to your fraud check with the Telegram user ID as the account and the wallet as the payout address.
- Pay clean accounts at once, hold the ones in review for a manual look, and refuse the blocked ones with a neutral message.
// Server side, after verifying Telegram initData.
$r = $cg->evaluate([
'event' => 'cashout',
'account_id' => 'tg:'.$telegramUserId,
'request_id' => $request->input('cg_request_id'),
'payout_method' => 'ton',
'payout_address' => $wallet,
'amount' => $usdValue,
'currency' => 'USD',
]);
if ($r->isBlocked()) {
return response()->json(['status' => 'not_eligible'], 403);
}Keeping it fair for real players
Aggressive anti-bot rules annoy exactly the players you want to keep. A few habits help:
- Hold instead of ban when the evidence is thin, and release quickly after a look.
- Explain eligibility rules in the app (one account per person and per device) before the event, not after.
- Offer an appeal through the bot. Farms rarely appeal; real players do.
- Start in shadow mode. Score everyone for a few days, read the flagged accounts and only then start holding claims.
Next steps
The guide to blocking at signup, click and cashout shows where to act, the multi-accounts guide covers linking accounts by device and wallet, and the referral abuse guide goes deeper into referral trees. CashoutGuard starts free up to 1,000 monthly users; see pricing.