Vernum

What Is an OTP Bot? How It Steals Your Verification Code

Short answer

An OTP bot is automated software that calls or texts you posing as your bank, a delivery company, or a platform, asking you to read out or key in the one-time code you just received. The moment you provide it, the bot relays it to the attacker within seconds, who uses it on the real account before the code expires. No legitimate company ever asks for a verification code by phone or text.

What is an OTP bot is the kind of question you search right after a strange call: a number that looked like your bank's, a recorded voice claiming to have flagged suspicious activity, and a request to read out the code that had just landed on your phone. This isn't a human scammer improvising — it's what security researchers call an OTP bot, or OTP interception bot, and it's built specifically to automate this exact trick at scale. This guide covers how the bot actually works, how the code gets stolen, the warning signs to catch it early, and what to do if you already gave yours away.

What is an OTP bot, exactly?

An OTP bot is a rented or self-operated automated calling and texting service that dials or messages targets in bulk, using a recorded voice (sometimes AI-generated text-to-speech) or a prewritten text template. It spoofs the caller ID of a real bank, delivery company, or platform, then steers the target toward reading out or keying in a code under the pretext of "verifying" the account or "cancelling" a suspicious charge. Security firm Intel 471 and journalist Brian Krebs have both documented these tools being rented through Telegram and Discord, with the stolen code relayed back to the attacker over the same messaging channel within seconds.

What separates a bot from a human scammer making the same call is scale and speed: one bot can target thousands of people at once, and it forwards a stolen code to the attacker the moment it's captured. We cover broader warning signs of this kind of fraud in SMS scam warning signs; this guide focuses specifically on the automated version.

How do OTP bots actually steal a verification code?

An OTP bot doesn't breach your device — it gets the code out of you directly, through a script designed to sound legitimate. The sequence usually looks like this:

  1. The attacker already has your basic details: your number and which bank or platform you use with it, typically from a data leak, a phishing page, or social media.
  2. They trigger a real login attempt: a password reset or sign-in attempt on your actual account, which causes the platform to send you a genuine, valid code.
  3. The bot calls or texts you within minutes: spoofing the company's real number, it claims to have flagged suspicious activity and asks you to read out or key in the code to "cancel" it.
  4. The moment you provide it, the bot forwards it: whatever you say or type gets relayed within seconds to a Telegram or Discord channel the attacker is watching.
  5. The attacker uses it before it expires: since the code is usually valid for only a few minutes, they complete the real login almost immediately, often before you've even hung up.

Krebs on Security has reported success rates as high as 80% when a target answers and supplies accurate information — which explains why this method has spread as far as it has. We look at the risk of sharing a code more broadly in what happens if you share your verification code.

How can I tell if a call is an OTP bot?

Most OTP bot calls share a handful of recognizable tells.

If anything feels off, hang up and call the company back using the number on their official site or the back of your card. We cover similar red flags used by scam sites in how to spot a fake SMS verification site.

An OTP bot got my code, what do I do now?

The moment you realize you gave up the code, move through this quickly — every second counts.

  1. Change the account's password right away: If the attacker hasn't already changed it, this can still lock them out.
  2. Sign out of every other active session: Most services have a "log out of all devices" option in account settings.
  3. Move two-factor authentication to an authenticator app: Switching off SMS-based codes stops the same trick from working on your next login.
  4. Call the company directly if the account is financial: Use the number on their official site, not one given to you during the call, and ask them to freeze activity.
  5. Don't respond if the same number calls again: Once you've given up one code, the same bot or operator may try for a second — treat that follow-up as equally suspicious.

How fast you move through these steps largely decides how much damage gets done, since the leaked code's short window is still your best chance to shut the attacker out.

Troubleshooting: the code never arrived, the number was rejected, or the order timed out

This is a completely different situation from an OTP bot call — here nothing malicious happened, the code simply never showed up or the order had a problem. Here's the sequence to follow.

  1. Wait out the window and refresh the dashboard: Some carriers add a few seconds of delay; keep checking until the order window actually closes.
  2. Switch countries if the number gets rejected: Certain country codes are rejected more often by specific services; switching to one with strong availability usually solves it.
  3. Confirm the automatic refund if the order times out: If the code never arrives and the window closes, the coins you spent are credited back automatically, and you can place a new order right away.
  4. Try a different carrier if it keeps happening: Repeated failures on the same country-service pair usually resolve faster by switching carrier or country than by retrying the same combination.

We walk through the full ordering flow in SMS code not arriving, fixes.

Cheapest countries for WhatsApp (Vernum, September 19, 2026)

The table below shows the eight lowest-priced countries in Vernum's catalog for WhatsApp as of September 19, 2026. 1 coin = $0.01, confirmed via a live web search this session at roughly 48.80 TRY per USD.

CountryCoins≈ USD
🇿🇦 South Africa63$0.63
🇵🇸 Palestine67$0.67
🇦🇴 Angola93$0.93
🇨🇱 Chile93$0.93
🇨🇲 Cameroon93$0.93
🇮🇩 Indonesia93$0.93
🇰🇪 Kenya93$0.93
🇲🇦 Morocco93$0.93

All 193 countries in Vernum's catalog are currently available for WhatsApp; the cheapest is South Africa at 63 coins (about $0.63). A Turkey number is also on the list, at 432 coins (about $4.32) — so even if an OTP bot calls you, an account opened with a virtual number was never tied to your real number in the first place, which means there's nothing for it to track back to you long-term. Prices refresh hourly; the live list is always in the dashboard.

What is an OTP bot comes down to one thing: automated software built to get a real, live code out of you before it expires, using a spoofed number and a script designed to sound urgent and official. Knowing that no company ever asks for that code by phone, treating every such request as suspicious no matter what number is calling, and moving fast if you already gave one up stops most of these takeovers before they finish.

Frequently asked questions

What is an OTP bot?

An OTP bot is automated software scammers rent or run that calls or texts targets while posing as their bank, a delivery company, or a platform, asking them to read out or key in the one-time code they just received. The moment the code is entered, the bot forwards it to the attacker in seconds.

How do OTP bots actually steal a verification code?

The attacker first triggers a real login or password reset on your account, which causes the platform to send you a genuine code. At the same moment, the bot calls or texts you, spoofing the company's real number and asking you to confirm the code. The instant you say or type it, the bot relays it to the attacker, who uses it on the real login before it expires.

If the caller ID shows the real company number, can it still be an OTP bot?

Yes. Caller ID can be spoofed, so seeing the company's real number on your screen doesn't confirm the call is genuine. No legitimate company asks for a verification code over the phone or by text, regardless of what number appears to be calling.

An OTP bot got my code, what do I do now?

Change the account's password immediately, sign out of every other active session, and move two-factor authentication to an authenticator app if you haven't already. If the account is financial, call the company directly using the number on their official site, not one given to you during the call, and ask them to freeze activity.

What kinds of accounts do OTP bots usually target?

Security research has documented OTP bots targeting banking apps, crypto exchanges, payment services, and major tech accounts most often. Because the target is a short-lived but fully authoritative code, any account with SMS-based two-factor authentication turned on is a potential target.

Sources

← Back to blog