What Is an OTP Bot?
An OTP bot is an automated calling or messaging tool that tricks victims into revealing one-time passcodes — the six-digit codes sent by SMS or authenticator apps as a second factor. Attackers who already hold a victim's password use the bot to defeat the remaining barrier: it phones the victim posing as their bank or a security team, prompts them to "confirm" the code they just received, and forwards the captured code to the attacker within its short validity window.
How an OTP Bot Attack Unfolds
The attack begins with credentials, usually obtained through data breaches and replayed via credential stuffing. The attacker enters the stolen username and password on the real site, which triggers a genuine OTP to the victim's phone. Simultaneously, the OTP bot calls the victim with a convincing script — spoofed caller ID, professional voice prompts, urgency about "suspicious activity" — and asks them to enter the code on their keypad. The bot relays the digits to the attacker's session, and the account takeover completes with a fully valid second factor. Subscription OTP-bot services sold on Telegram and underground forums industrialize this flow: operators paste a phone number and target brand, and the service handles the call, the script, and the code capture.
Why OTP Bots Work
The attack succeeds because it targets the person rather than the cryptography. The code is genuine, the login is genuine — only the person typing the code into the phone believes they are talking to their bank. Voice cloning and natural-sounding text-to-speech have made the calls increasingly convincing, and because the victim hands over the code voluntarily, fraud systems see a login with a correct password and a correct second factor.
Defending Against OTP Bots
User-side education helps — no legitimate institution asks customers to read out or key in a security code over the phone. Structurally, phishing-resistant factors such as passkeys and hardware keys remove the shareable secret entirely: there is no code to trick anyone out of. On the service side, the attack has an automation dependency that predates the phone call — the credential validation and login attempts that supply the bot with working passwords are machine-driven. Verifying at the login that a real person in a real browser is signing in, the invisible check bot protection such as CaptchaFox performs, cuts off the automated credential testing an OTP-bot campaign is built on. Our article on account takeover attacks covers the wider attack chain.
About CaptchaFox
CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.
To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.