A channel can copy a trusted name closely enough to fool a fast reader without copying a single character of it — a swapped letter here, an emoji there. Here is how the lookalike trick works, why it is a different con from copying someone's trades, and the one check that settles it.

What are you actually clicking?

Someone told you the name of a channel. A friend, a review, a thread. You open Telegram, type the first few letters, and a result comes up spelled the way you remember, with the picture you expected. You tap it and join.

You may have joined the channel you were told about. You may have joined a second channel whose name is built to be read as the first one. Nothing in the moment tells the two apart, because the trick does not rely on you making a mistake. It relies on you being right — on the name looking exactly like the one you already trust — while the underlying characters are not the same characters at all.

This is a specific, cheap, and old trick, and it is worth understanding on its own terms, because the defence against it is not "be more careful." Careful reading is exactly what it defeats.

How does a name look right while being wrong?

Start with what a name is made of. To you, a channel title is a shape your eye recognises in one pass. To software, it is a sequence of code points — numbered slots in the Unicode character set. The letter you read as a lowercase Latin "a" is code point U+0061. There is another character, U+0430, that most fonts draw as an identical shape. It is a Cyrillic letter. Side by side at reading speed, you cannot tell them apart. To a computer, and to a search box, they are two completely different characters.

That gap is the whole con. There are three common ways to work it.

Swap a letter for a lookalike. Replace one Latin letter with its twin from another alphabet — a Cyrillic character that renders as "a," "e," "o," "p," "c," or "x," or a Greek one that renders as "o," "n," or "u." The name reads identically. It is, to every system that matches on characters, a different name, so it does not collide with the original and can exist alongside it. This is the family of tricks known in security work as homograph or confusable attacks; the same technique is used to register web-address lookalikes, documented by Unicode itself in its security guidance cited below.

Wedge in a glyph you read past. An emoji, a ninja face, a flame, a decorative separator dropped into or beside the name. Your eye treats it as styling and reads the letters around it. The channel now has a name that is technically distinct from the original — different characters, different length — while carrying the same word you were looking for. Emoji in a channel title are completely normal, which is exactly why one more does not register as a warning.

Swap the punctuation. A different kind of space, a different dash or underscore, a full-width version of an ordinary symbol. Invisible to a reader, decisive to a matcher.

There is a nastier variant worth naming because it is invisible by design. Certain formatting characters carry no shape at all but change how text is laid out. A right-to-left override, dropped into a name, reverses everything printed after it — so a string of characters can be stored one way and displayed as an entirely different word. You are not reading a cleverly chosen letter there; you are reading a rendering instruction. Nothing about the displayed name reveals it.

Isn't this the same as a clone channel?

No, and the difference is the useful part.

A clone copies the content — it reposts another channel's actual trades, sometimes within seconds, so that following it feels like following the original. We wrote that mechanic up separately in clone signal channels: one operation running several feeds, the same calls landing in several places at once. There, what is copied is the substance.

Name-mimicry copies the label and nothing else. The channel behind a lookalike name may post completely different trades, or no trades, or a straight deposit funnel. It is not trying to be a convincing twin of the original's output. It is trying to be mistaken for the original at the instant you decide which one to join, and after that it is on its own.

The two can stack — a lookalike name over a cloned feed is a complete disguise — but they fail differently and you catch them differently. A clone you catch by comparing what two channels post and when. A lookalike you catch by comparing the exact characters of the name, which is a check you can run on a single channel before you have seen it post anything at all.

Why can't you just read carefully?

Because the attack is built precisely against reading. The letters are chosen so that the correct, attentive reading of them is wrong. Your eye is doing its job perfectly and still arriving at the wrong channel. This is why "look closely" is not advice here — closeness is what gets defeated.

What actually separates the two names is not visible at reading speed:

Look at the username, not the display name. A Telegram channel has a display title, which can be anything, and a public username — the t.me/... handle — which lives in a far narrower character set. The handle is much harder to disguise than the pretty title above it. If someone gave you a channel by name, the thing to confirm is the exact handle, character for character, ideally from a source that is not the same place that is pushing you toward the channel.

Copy the name into a plain text field. Paste the channel title into a search box, a notes app, anything that shows raw text. A lookalike letter will often break the search — you will not find the real channel, because you are not searching for it — or the field will render the odd character differently from the styled title. If pasting the name you "know" fails to match the channel you meant, that mismatch is the finding.

Distrust a name you arrived at by tapping, not typing. The dangerous path is a link or a forwarded card that carries the name pre-formed, so you never type the characters yourself. Typing the name from scratch and seeing which channel your own keystrokes resolve to removes the substituted letters, because your keyboard produces the ordinary ones.

Treat an unexpected emoji or symbol in the name as a question, not a decoration. Not proof of anything — plenty of honest channels are proud of their ninja — but a reason to check the handle rather than trust the title.

What does ChainRated do about it?

We list channels by the names they call themselves, and we cannot rename them — the name belongs to the channel, and rewriting a lookalike title into something tidier would just produce a page nobody can find in Telegram. So instead of judging any name in isolation, we compare every name against every other name in the index by what it looks like.

For each listed channel we compute a comparison form — a "skeleton" of the name. Confusable letters are folded to their plain Latin equivalent, emoji and decoration are dropped, invisible formatting characters are removed, and case is flattened. Two names that a reader could not tell apart collapse to the same skeleton even though their raw characters differ. The method is not ours by invention; it is the skeleton approach defined in Unicode's own security standard, applied to channel names instead of web addresses.

That turns "does this name read like another channel we already list?" from a guess into an indexed lookup. A new or edited name is checked against the catalogue on the way in, and a match — same skeleton, different actual characters — is flagged as a lookalike of a specific existing entry. Note the two things it deliberately does not do. It does not flag a name merely for containing Cyrillic or Greek letters; most honest Russian-language channels mix scripts, and treating that as an accusation would train everyone to ignore the one case that matters. And it does not flag two channels genuinely, identically named the same thing — that is an ordinary collision, not a disguise. The finding is narrow on purpose: spelled differently, reads the same as something already here. This is the state of the mechanic in our index as of August 2026.

It is worth being clear about what this proves and does not. A shared skeleton establishes that two names are visually confusable. It does not establish intent, or that either channel is dishonest, or which one came first. It is a reason to check, surfaced automatically, not a verdict.

The check, in one line

Confirm the exact handle of the channel you meant to follow — from a source independent of whoever is steering you to it — before you read a single post.

Everything downstream of that assumes you are looking at the channel you think you are. A track record, a pinned methodology, a wall of green results: all of it belongs to whatever handle you actually joined, and if that handle is a lookalike, you are verifying the wrong entity with real care. The checks that tell you whether a channel's results hold up are covered in how to verify a crypto signal channel, and they only mean something once identity is settled. It is also worth knowing that a "verified" badge answers a narrower question than people assume — the three separate things it can mean are laid out in what a verified badge actually proves, and none of them is a promise about the trades.

A lookalike name rarely travels alone, either. It tends to arrive with the other tells of a channel built to extract a deposit rather than earn a following — which is why it sits alongside the rest of the red flags of a signal channel rather than being the whole story.

What this does and does not protect

Checking the characters of a name protects you from one specific loss: joining the wrong channel because its label was built to be misread. That loss is entirely inside your control, and it costs a few seconds to close.

It does not tell you the channel you did mean to join is any good. A correctly identified channel can still be a poor one; the name being genuine says nothing about the trades being genuine. Those are separate questions, checked separately.

And it is worth holding the modesty of the tool in view. Our skeleton comparison catches names that fold onto something already in our index. It cannot see a lookalike of a channel we do not list, and a determined operator can always reach for a substitution nobody has catalogued yet. It narrows the gap; it does not close it. The habit that closes it is the cheap one — confirm the handle from an independent source, character for character, before anything the channel says gets a chance to matter.

Sources

  • Confusable and homograph attacks, the "skeleton" comparison method our own name-folding is modelled on, and the invisible formatting characters that make some disguises impossible to read: UTS #39: Unicode Security Mechanisms, Unicode Consortium.
  • The web-address version of the same trick, where a lookalike domain stands in for a trusted one: IDN homograph attack, Wikipedia.
  • Our name-folding mechanic — skeleton comparison, the confusable table, invisible-character stripping, and the deliberate exclusions — is implemented in core/channel_names.py in this repository. As of August 2026.