What if the telegram account is being hack or being compromised, maybe sometimes you were login to a web and refuses to logout another user got to know about token that same account won't it be sent out without your noticed?
Ton wallet/bot is a custodial wallet, it tied your Telegram ID into the bot of the wallet. So, in any way your Telegram account is compromised, and the attackers found out you are using the bot, then they surely have the capability to empty out the funds.
So, you have to guard your Telegram account securely. Enable the 2FA, local passcode, etc. Besides it is custodial, the whole thing doesn't offer great security, IMO.