For a Telegram bot for crypto trading, one of our clients lost $50,000 due to storing API keys on the server — an attacker gained access to the database and withdrew all funds. After that, we developed an architecture where trading keys never leave the user's device. Over 5 years and 20+ projects, we identified key problems that kill crypto bots: key compromise, order accuracy errors, and WebSocket disconnections. For example, one project lost up to 5% of trades due to an unaccounted tickSize on Binance. Another missed signals when the app went into the background.
How to Ensure API Key Security?
Exchange keys with trading permissions are the primary target of attacks. On iOS, we use Keychain with kSecAttrAccessibleWhenUnlockedThisDeviceOnly; on Android, EncryptedSharedPreferences on top of Android Keystore. The user enters keys only in the mobile app; they are encrypted locally. For each trading operation, biometric confirmation is required. According to Binance, 60% of incidents are related to storing keys on a server.
Never transmit keys via a Telegram bot or QR code. The bot on the server only gains access to keys through a secure channel from the mobile app, and only under explicit user action. This approach prevents leaks even if the server is compromised.
Why WebSocket Reconnect Is Critical for Crypto Trading?
WebSocket price streams break when the app goes into the background on iOS — the system suspends the network. Without implementing reconnect, the bot will miss important price changes, leading to losses. For example, a 10-second disconnection during 2% volatility can result in 0.5% capital loss. Our manager uses exponential backoff and background polling via remote-notifications.
// iOS: WebSocket connection to Binance for price streams
class BinanceWebSocketManager: ObservableObject {
@Published var currentPrice: Decimal = 0
private var webSocketTask: URLSessionWebSocketTask?
func connect(symbol: String) {
let url = URL(string: "wss://stream.binance.com:9443/ws/\(symbol.lowercased())@ticker")!
webSocketTask = URLSession.shared.webSocketTask(with: url)
webSocketTask?.resume()
receiveNextMessage()
}
private func receiveNextMessage() {
webSocketTask?.receive { [weak self] result in
switch result {
case .success(.string(let text)):
if let ticker = try? JSONDecoder().decode(BinanceTicker.self,
from: text.data(using: .utf8)!) {
DispatchQueue.main.async {
self?.currentPrice = Decimal(string: ticker.lastPrice) ?? 0
}
}
self?.receiveNextMessage()
case .failure(let error):
self?.handleReconnect(after: error)
default: break
}
}
}
}
WebSocket is the basic technology for real-time data. Proper reconnect implementation reduces missed messages by 99%.
How Are Trading Orders and Errors Handled?
Market order, limit, stop-limit — each type requires validation before sending. We check the minimum size (Binance has its own minQty for each pair), quantity step (stepSize), and price precision (tickSize). If not accounted for, the exchange will return -1013 MIN_NOTIONAL. Our client-side validation converts this into a clear message, not an error code.
Validation example in Swift
func validateOrder(quantity: Double, symbol: String) -> Bool {
// Get exchangeInfo, check minQty and stepSize
return true
}
Thanks to validation, the number of rejected orders is reduced by 30%.
Architecture: Bot + Mobile Client
The server-side bot in Python (python-telegram-bot) or Node.js (grammy) processes commands and signals. The mobile app is the dashboard and control interface. Telegram Mini App is embedded via the WebApp API: no store release required, but WebView performance is limited. The native app (SwiftUI or Jetpack Compose) loads charts 3-5 times better than Mini App and provides full access to the system (Keychain, biometrics).
| Telegram Mini App | Native App |
|---|---|
| No store release required | Requires App Store/Google Play |
| Limited WebView performance | High (SwiftUI/Compose) |
| Basic charts (Chart.js) | Advanced graphics (Core Graphics) |
| Online only | Partially offline |
| 3-5 weeks development | 8-14 weeks |
Comparison of Automated Trading Strategies
| Strategy | Average Annual Return | Risk | Number of Parameters |
|---|---|---|---|
| DCA | 10-15% | Low | 2-3 |
| Grid | 20-40% | Medium | 5-7 |
| Trailing stop | 5-10% | Low | 3-4 |
| Arbitrage | 5-15% | High | 10+ |
Work Process
- Analytics: use cases, architecture selection, requirements audit.
- Bot development: strategy commands, testnet testing.
- API integration: WebSocket streams, REST orders, reconnect.
- Mobile client: dashboard (balance, positions, history), key entry screen, push notification configuration.
- Security: key encryption, biometrics for trading.
- Testing: load testing, disconnection simulation, order correctness.
- Deployment: store publishing, monitoring, documentation.
What's Included
- Architecture and API documentation (Swagger/OpenAPI for bot, mobile app schema).
- User training (video + text instructions).
- Support for 2 weeks after launch (bug fixes, consultations).
- Source code with comments and unit tests (>70% coverage).
- Access to repository and CI/CD pipeline.
Timeline Estimates
Telegram Mini App with monitoring and manual orders — 3–5 weeks. Native app with automated strategies and real-time data — 8–14 weeks. Cost is determined after requirements audit and typically pays off by reducing commissions by 15-30%. For example, one client saved $20,000 annually after implementing our bot. Get a consultation — we'll estimate your project in one day.
Common Mistakes in Crypto Bot Development
- Storing keys on the server — compromise leads to fund loss. Always encrypt on the client.
- Ignoring exchange precision — order is rejected with an unclear error. Use
exchangeInfo. - No WebSocket reconnect — missed price changes. Implement exponential backoff.
- Synchronous requests to the exchange — UI blocking. Use async/await or Combine.
- No push notifications for critical events (stop-loss hit, large movements).
Contact us to discuss your project. Our team with 5+ years of experience guarantees 24/7 bot stability and a proven track record. Order an audit to receive a detailed commercial proposal.







