Security
We hold no money, no keys, no surprises.
The actual answers crypto-native users ask. No marketing fluff, no vague "bank-grade encryption."
No custody
Member-to-group payments settle on-chain directly to the group owner. We never hold member funds. An optional small platform fee is forwarded to a fee-collector address. No escrow, no withdrawal queue.
No private keys
The verification flow uses SIWE-style signed messages. We see the signature, verify it recovers the claimed address, and store the binding. Your private key never leaves your wallet.
Encrypted in transit and at rest
Cloudflare terminates TLS at the edge with end-to-end encryption to the origin. The off-chain database is encrypted at rest, with daily backups.
One wallet per identity
Each Telegram identity is bound to exactly one wallet per chain. Re-binding requires signing with your currently-bound wallet first, so nobody can steal a member's spot.
What you sign
The verification message in full.
When you bind a wallet to your Telegram identity, you sign this exact text. No hidden payload, no ambiguous fields.
tokengate.launchpal.xyz wants you to bind your Telegram identity to this wallet. Telegram user id: 123456789 Wallet: 0xYour…Wallet Chain: besc Issued: 2026-04-28T12:34:56.789Z Nonce: 0x<32-byte random> By signing, you confirm this binding. This signature is single-use.
The nonce expires server-side (default 10 minutes) and is marked consumed after one use. The signature is verified against the claimed wallet address. If it doesn't recover correctly, the binding fails.