How to stop scam DMs in crypto groups: wallet-age gating
How Cherry stops scam DMs in crypto groups: a wallet-age gate, silent hidden requests, a 0.01 SOL notify fee, shadow drops, and bans only humans issue.
Most answers to how to stop scam DMs in crypto groups are a list of habits: never open a verify link, check the admin list before you reply, turn off messages from strangers. Cherry (cherry.fun) is a wallet-to-wallet messenger and community app for crypto: you sign in with a wallet, DM any wallet address, and join or create token-gated, NFT-gated and paid group chats, with no phone number, email or KYC. Because an account is a wallet and not a free username, spam can be gated and priced where it starts. This page is the mechanism: what each layer blocks, what the spammer sees, and where the layers stop working.
What the anti-spam layers do on Cherry
Nine layers sit between a spammer and your members, and most of them are deliberately quiet. This is the whole model as of 11 September 2026.
| Layer | What triggers it | What the sender sees |
|---|---|---|
| IP firewall | any connection from a banned IP address | a refusal, before sign-in |
| Wallet age, public surfaces | a too-new wallet posts in a public group or channel, or reviews a paid group | a notice in place of the composer, with the reason |
| Wallet age, private surfaces | the same wallet sends a cold DM or a private-group invite | a normal send; the message lands in the recipient’s hidden requests |
| DM economics | a first DM to someone who has not accepted you | free lands silent in Requests; paid sends a push after the fee confirms |
| Word blacklist | a group message contains a listed word | their own message, on their own screen, nowhere else |
| Group mute | a muted member posts in that room | the same silent drop, scoped to one room |
| Bot cold outreach | a bot DMs a wallet that never opened its chat | delivery into hidden requests, with no push |
| Bot display names | a self-serve bot claims a brand or an authority word | the name is refused when the bot is created |
| Signature requests | a bot asks a wallet that never accepted its chat to sign | a refusal, not a prompt in the wallet |
Two rules sit behind them. Silent degradation is the default, because a spammer who gets an error learns which edit gets through. And no layer bans anyone on its own: automation drops or limits the action and records the attempt, then a human reviews it.
How it works
Every layer keys off the wallet, the one identifier on Cherry a spammer cannot mint for free.
New wallets wait to post in public
Cherry looks at how long a wallet has been used on-chain, and a wallet with little or no history counts as new. A restricted user is shown no countdown, since printing the threshold would hand a wallet farm the recipe for pre-ageing burners.
What the verdict changes, and what it leaves alone:
| Action by a too-new wallet | What happens |
|---|---|
| Post in a public group or channel | refused, with the reason on screen |
| Review a paid group | refused, which keeps review scores honest |
| Create a public group, or make a private one public | allowed since 31 July 2026: an empty group is not a spam surface |
| Cold DM to a stranger | allowed, routed to the recipient’s hidden requests with no push |
| Private-group invite | allowed, forced to hidden, with no invite notification |
| Paid DM or paid invite | not gated at all: the fee is the escape hatch |
| Reading anything | never gated |
The notice reads “Sending messages is limited for new wallets” in a group, “Posting is limited for new wallets” in a channel, and “Free requests are limited for new wallets” in the DM composer. The remedy is the honest one: use the wallet on-chain.
This is the one check that errs on the side of blocking. If Cherry cannot read a wallet’s history at that moment, it treats the wallet as too new until a later check can. Every other layer errs the other way: when a check cannot run, the message goes through, so a failed check never takes the chat down with it.
A free DM is a request, a paid DM is a notification
A first message to someone who has not accepted you is free and silent: it lands in their Requests folder, under the Hidden sub-tab, with no push. Declining is silent too, and the sender keeps a pending request they cannot distinguish from a message nobody opened, so there is no signal to retry. The composer offers two modes, labelled “Free” with the sub-line “No notification” and “Notify · 0.01 SOL” with “Sends a push”; the fee is 0.01 SOL by default as of 10 September 2026. Cherry delivers the message only after the transfer confirms on-chain, so an abandoned wallet prompt sends nothing. Message requests and paid DM covers the full flow, and DM a wallet address covers a recipient who has never signed in.
Blocked messages drop without an error
The word blacklist runs on group messages, which are not end-to-end encrypted, so Cherry can see the text. A message with a listed word reaches nobody, while the sender still sees it on their own screen. Matching ignores case and catches the word inside longer text, so a scam domain is caught mid-sentence. Cherry maintains the list, and every drop is kept for a human to review. A group mute works the same way inside one room: a muted member’s messages vanish quietly, with no error to learn from.
Bots earn no trust for being bots
Anyone has been able to create a bot in Cherry Portal since 30 June 2026, so making one takes a few clicks and a bot is as untrusted as an anonymous wallet. A bot’s DM to a wallet that never opened its chat lands hidden with no push, and hiding a bot sticks even if it writes again. A bot can reach only a limited number of new wallets per day, so a flood cannot bury the hidden folder. A cold recipient is never shown a signature prompt from a bot: the request is refused, because a prompt detached from a conversation is a phishing setup. Bot names are compared after ignoring case, accents, look-alike letters and number swaps, so “Сherry”, “ch3rry” and “C-h-e-r-r-y” all read as Cherry and none can be registered. What a user reads is the label in the DM header, which Cherry sets and the developer cannot change: amber for a bot, green only for a verified one. Cherry API and bots documents what a bot can do once it is in a room.
What is different from verify bots and open groups
The contrast is about what proves an identity and who enforces the rule.
Telegram’s FAQ says sharing a group with you is enough for someone to contact you, and its answer to impersonation is to report the scammer to a support account. The same FAQ describes the economic brake Cherry also uses: a fee in Telegram Stars for messages from people who are not in your contacts. The gap is what a display name is worth. A username costs nothing, so a copy of an admin’s name and picture is a full disguise, and the follow-up is a DM carrying a verify link.
On Cherry the account is the wallet, and display names come from names that wallet owns on-chain, such as a .sol name from SNS or a .skr name from a Solana Seeker. The name is backed by something the holder paid for and still holds. Gating is checked by the app against the chain, so nobody has a reason to send you a verification site: there is none. Token-gated chat
describes that check and the re-verification that follows it. Inside the Hidden requests folder, where impersonators land, the app keeps a standing warning: “Be careful — official accounts always have a special badge next to their name”.
These rules hold wherever a message comes from, so a modified app or a script meets the same limits as a person typing in Cherry.
Who uses it and for what
Three groups feel these layers for different reasons.
Domain-gated communities use the wallet as the ticket, which prices out burners with no manual vetting. SNS Club, open to holders of a .sol domain, had 1,455 members and 3,872 messages as of 11 September 2026.
Seeker Club
, gated by a .skr domain that is soulbound and verified once, had 8,637 members, 58,196 messages and 4.9 stars from 41 reviews the same day. A throwaway wallet passes neither check, and the wallet-age gate covers the surface gating does not: reviews.
Paid community owners get a second brake. A one-time entry fee, in SOL or in USDC, doubles as an anti-spam fee: a spammer can pay it, but not two hundred times, and the receipt is durable so a member who leaves can return without paying twice. Reviews come only from active members, and an owner cannot review their own group. Paid communities and channels has the economics.
Sites and dApps that embed a Cherry room set their own rules per embed in Cherry Portal: a minimum wallet age, a list of blocked words that drop a message silently, a link policy, and switches for images and GIFs. See embeddable chat for the rest of the widget.
Limits and honest caveats
DMs are end-to-end encrypted with keys derived from your wallet signature, so Cherry cannot read them or filter their content. Everything above about DMs is about delivery and notification. Group chats are not end-to-end encrypted, by design, which is what lets the word filter, moderation and bots work at all.
The word filter matches text as written, so spacing tricks and look-alike letters get past it. Treat the list as a first pass against a known scam domain, never as the defence.
Because wallet age errs on the side of blocking, a legitimate new wallet can be restricted for a while when Cherry cannot read the chain. Creating a public group is not gated, only posting into one, so a new wallet can still stand up a group nobody reads.
Per-embed rules do not apply to the room’s owner, admins and moderators; Cherry’s global word list applies to everyone. Acting on a raid is manual: shadow bans, full bans, per-group bans and IP bans are all issued by a person.
How to stop scam DMs in crypto groups you run
Five steps, in the order that removes the most spam per minute of effort.
- Gate the room on something that costs money to hold: a token balance, an NFT from a collection, or a domain. The check runs against the chain on join and again in the background.
- Charge entry if the room is worth paying for. One-time SOL or USDC entry turns volume spam into a bill.
- Promote one or two members you trust to moderator, so a kick or a ban during a raid does not wait for you to wake up.
- Moderate in order: open a member, then “Mute” (“Can read, can’t write”), then “Kick” (“Can rejoin later”), then “Ban” (“Can’t rejoin until unbanned”).
- Tell members to use “Report” in the message menu, which opens “Report message” with a category and a box for what happened.
Create a group at chat.cherry.fun and set its gating before you invite anyone.
FAQ
How do you stop scam DMs in crypto groups? Price and gate the account instead of reading the message. On Cherry an account is a wallet: a first DM from a stranger lands silently in the recipient’s Requests folder with no push, a new wallet is routed the same way, and the only path to a notification is a paid DM that costs 0.01 SOL by default as of 10 September 2026 and is delivered only after the payment confirms on-chain.
What is wallet age protection? It is a check on how long a wallet has been used on-chain. Cherry treats a wallet with little or no on-chain history as new and keeps it from posting in public groups and channels until the wallet has been used. Sites that embed a Cherry room can also set their own minimum wallet age in days.
Can a brand-new wallet post in a public group? No. A wallet Cherry classifies as too new is refused when it posts in a public group or channel and when it reviews a paid group, and the composer is replaced by a notice headed “Sending messages is limited for new wallets”. It can still read everything, create a group, and send DMs that land in the recipient’s hidden requests.
What is a shadow ban in a crypto chat? It is a drop that looks like a send. A blacklisted word, a group mute or an admin’s shadow ban means the message reaches nobody, while the sender still sees it on their own screen. The silence denies a spammer the feedback they need to tune around the filter.
Does Cherry read my DMs to filter spam? No. DMs are end-to-end encrypted with keys derived from your wallet signature, so Cherry cannot read them. The word filter runs only on group messages, which are not end-to-end encrypted by design. The DM defences decide where a message lands and whether it notifies, never what it says.
Sources
Try Cherry
Sign in with a wallet, DM any address, and join token-gated and paid communities. No phone number, email, or KYC.