How to Verify a Crypto Trading Tool Isn't a Scam

A practical checklist for spotting a crypto trading bot scam before you connect an exchange API key — covering custody, key permissions, transparency, and the red flags that separate real infrastructure from a trap.

Connecting an automation tool to your exchange account means handing software a credential that can act on your money. That's a high-trust decision, and it's exactly why a crypto trading bot scam can be so costly: by the time you notice something is wrong, the tool may already have the access it needs. The good news is that most fraudulent or unsafe tools share a handful of tells. This guide gives you a concrete checklist to verify a trading tool before you connect anything — focused on facts you can check, not vibes.

Start with the one question that matters most: custody

The single biggest dividing line between safe and unsafe tools is whether the tool ever takes custody of your funds. A non-custodial tool connects to your exchange with an API key and places orders on your behalf — your balance stays on the exchange, in your account, the entire time. A custodial tool asks you to deposit funds into a wallet or account it controls.

If a tool asks you to send crypto to an address it manages, or to deposit money it will "trade for you," treat that as a stop sign. You cannot independently verify what happens to funds you no longer hold. Many of the most damaging schemes are simply deposits that never come back. If you're unclear on the distinction, our guide on custodial vs non-custodial trading bots walks through it in detail.

Check what API permissions the tool actually requires

If a tool connects via exchange API keys, look closely at the permissions it asks you to enable. Every major exchange lets you scope a key to specific actions. A legitimate execution tool needs permission to read your account and place trades — and nothing more.

The red flag is withdrawal permission. No tool that merely places trades on your behalf has any reason to move funds off the exchange. If a tool requires withdrawal access, or pressures you to skip the permission settings, walk away. Setting up a key correctly takes a few minutes; our walkthrough on trade-only API keys and how to set them up shows exactly which boxes to check on the major exchanges.

A quick permissions checklist

  • Reading and trading: yes. The tool needs these to function.
  • Withdrawals: never. Leave this disabled. If the tool can't work without it, that's your answer.
  • IP allow-listing: use it. If the tool publishes its outbound IP addresses, restrict the key to those addresses through your exchange.

Look for transparency about how the tool works

Serious infrastructure is willing to explain itself. Vague tools hide behind marketing. Before you connect, look for clear, specific answers to a few questions:

  • How are API keys stored? The answer you want is encryption at rest with a managed master key — not silence, and never plain text. We explain the standard in our post on how we encrypt exchange API keys.
  • Who runs this? Look for a real company, named people, documentation, and a way to contact support. Total anonymity is not automatically fraud, but it removes your recourse if something goes wrong.
  • What does it actually claim to do? A tool that describes itself as execution infrastructure is making a checkable promise. A tool that promises outcomes is making one nobody can keep.

The promise red flag: anyone guaranteeing results

This one is worth stating plainly. Any tool, channel, or person that guarantees profit, advertises fixed returns, or calls itself "risk-free" is describing something that does not exist in trading. Markets move against positions; automation does not change that. Guaranteed-return language is one of the most reliable signals that you are looking at a scam rather than a service. A trustworthy execution tool sells reliability and security — the boring promise that your signals become orders correctly — not performance.

Pressure tactics and other behavioral tells

Beyond the technical checks, watch how a tool tries to win your trust. Common manipulation patterns include:

  • Urgency. "Limited spots," countdown timers, and "act now or miss out" exist to stop you from doing exactly the due diligence on this page.
  • Unsolicited contact. A DM, group invite, or "account manager" reaching out first is a classic vector. Real tools rarely cold-message you about your money.
  • Fake social proof. Screenshots of profits and testimonials are trivial to fabricate. Weigh verifiable facts — custody model, permissions, documentation — far more heavily than screenshots.
  • Reluctance to let you start small. A legitimate tool is fine with you testing carefully. Pressure to commit large sums quickly is a warning, not an opportunity.

A practical pre-connect checklist

Before you connect any tool to your exchange, confirm:

  • It is non-custodial — your funds stay on your exchange.
  • It works with trade-only keys and never asks for withdrawal permission.
  • It is transparent about key storage, ownership, and what it does.
  • It makes no profit or guaranteed-return claims of any kind.
  • It doesn't rely on urgency or pressure to get you to connect.

Verify, then connect

Scam-spotting in crypto automation comes down to a mindset shift: don't ask whether a tool looks trustworthy, ask whether you can verify its claims. Custody, key permissions, and storage are all things you can check directly — through your own exchange settings and the tool's own documentation. SignalToExchange is built to pass this checklist by design: it is non-custodial execution infrastructure that connects with trade-only keys, so your funds never leave your exchange and the platform can place orders but never withdraw. If that's the kind of tool you're looking for, Request access / start your free trial →

Automated trading involves risk. SignalToExchange is execution infrastructure and does not provide financial advice, trading signals, or guarantees of any kind.

Secure Signal Routing Infrastructure

Non-custodial execution. Trade-only API keys. Independent infrastructure built for reliability.

Request Early Access

Trade-only API key enforcement. No withdrawal permissions. No custody.