ar
Feedback
AML Crypto: all about crypto crime

AML Crypto: all about crypto crime

الذهاب إلى القناة على Telegram

AML Crypto about cryptojacking, hacks and blockchains, investigations and protecting your assets. Feedback: @AMLcrypto

إظهار المزيد
لم يتم تحديد البلدالعملات المشفرة24 245
3 973
المشتركون
لا توجد بيانات24 ساعات
-277 أيام
-15230 أيام
أرشيف المشاركات
😞 Why do we keep falling for scammers? Reality is usually messier than we’d like. A beautiful illusion often feels easier to
😞 Why do we keep falling for scammers? Reality is usually messier than we’d like. A beautiful illusion often feels easier to live with. That’s why people are drawn to self-deception: lies offer hope, simple answers, and the comforting illusion that life is under control, that happiness is just around the corner. 🤯 Often, deep down, a person knows they’re being deceived. But instead of facing an uncomfortable truth, they desperately search for reasons to believe otherwise. 🙉🙊🙈 And when we point out the obvious red flags, the victim says: “But he promised he was honest…” Of course he did. What scammer would ever admit they’re lying?
This is the real trap: not just malicious intent from outside, but our own desire to believe. The only true protection is critical thinking. It won’t eliminate every risk, but it can help you stop in time — and keep your money safe.
As harsh as it sounds: don’t be a trusting child. The price of naivety is far too high. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

🎯 5 Signs You’re Dealing with Crypto Scammers Save this - it might come in handy. All examples are based on real AML Crypto
+4
🎯 5 Signs You’re Dealing with Crypto Scammers Save this - it might come in handy. All examples are based on real AML Crypto investigations. 👉 Full breakdown on our website: amlcrypto.io 1️⃣ “Technical error. To unlock your transfer, send the same amount again.” A classic psychological trap: pay once more - lose once more. No legitimate platform ever asks you to make an extra payment just to withdraw your own funds. 2️⃣ “Check your assets via an AML website.” A fake “partner service” designed to steal access to your wallet. Real exchanges run their own checks. They will never ask you to connect your wallet to some third-party site. 3️⃣ “Pay a tax in order to withdraw your funds.” Being asked to pay “tax” before withdrawing is almost always a scam. In most countries, taxes are paid directly to the tax authority by the user - not through crypto platforms. 4️⃣ “Your transaction is frozen by the blockchain’s AML team. An insurance deposit is required.” Remember: blockchain is a technology, not an organization. It doesn’t send notifications, freeze accounts, or act on behalf of regulators. Crypto wallet support teams do not send messages on behalf of OFAC, SEC, FinCEN, or any other authority demanding insurance deposits or fees. 5️⃣ “Top up your deposit to ‘comply with platform rules.’” No legitimate platform will ever require you to increase your balance in order to access funds that already belong to you. If someone tells you to “lend” money to complete a transaction - it’s a clear scam. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

💬 Talking to a Bybit representative? Make sure they really work for the company! Just like on any large platform with an act
💬 Talking to a Bybit representative? Make sure they really work for the company! Just like on any large platform with an active community, Bybit is not immune to fraudsters. By knowing their tactics, you can protect your funds. 🔎 Common schemes used by scammers to steal users’ assets or personal data: • Transferring funds to a Bybit Web3 wallet followed by convincing the user to undergo an “AML check.” • Sending fake payment receipts. • Applying pressure and demanding a refund of the transfer. • Sending SMS messages from a “bank” claiming that funds have been credited to your account. 📌 After such incidents, many users turn to official groups such as Bybit Community or Bybit-P2P Advertiser CIS for help. However, scammers often monitor these chats and are the first to contact victims, pretending to be “Bybit support” in an attempt to scam them again. ✅ How to protect yourself:
Make sure that the person claiming to be a Bybit manager is indeed an official representative of the company. You can verify this using the Bybit Verification Tool — simply enter their phone number, email address, social media account, or website address into the search bar: 👉 https://www.bybit.com/en/verification/
💪 Stay safe and protect your assets! Your AML Crypto! 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

🏴‍☠️ The Multisig Trap: A Scam for Those Trying to Steal This isn’t a new scheme — but it’s a powerful lesson. Because the v
🏴‍☠️ The Multisig Trap: A Scam for Those Trying to Steal This isn’t a new scheme — but it’s a powerful lesson. Because the victim here is someone who tried to profit from someone else’s “mistake.” 💡 How it works: • In a Telegram group, a message appears from a supposed “newbie”:
“I don’t understand how to withdraw from my wallet… Here’s my SEED phrase.”
• The wallet appears to hold between $1,000 and $10,000. Some users warn: “Never share your seed phrase! Move the funds now!” Others quietly start checking the address — and the balance is real. Then someone gets a bold idea:
“Why not help myself to the funds? Teach the fool a lesson…”
But there’s a catch: The wallet has no native tokens — so to make a transaction, you need to send a few dollars in gas (ETH, BNB, etc.). 🎭 The twist: • You send a small amount to cover gas fees. • But when you try to move the funds… you can’t. • It’s a multisig address — a second signature is required. • Your money is gone. The scammer just earned from your greed. We’ve seen cases where scammers earn thousands of dollars this way, depending on how widely the message spreads. ✍️ The moral of the story: If someone seems “too dumb” to be real… …it might mean you’re the actual target. Try to cheat the system — and you’ll likely become the one who gets played. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

Public Figure Hacked: Send 1000 USDT, Get 2x the Disappointment 👻 It all starts with a seemingly “hot” giveaway from a famou
Public Figure Hacked: Send 1000 USDT, Get 2x the Disappointment 👻 It all starts with a seemingly “hot” giveaway from a famous person or project. At first glance, it looks totally legit: • The account is real and verified (blue checkmark, full post history, large following). • A post/story/tweet appears:
“To celebrate our new project launch, we’re giving away crypto! Send 1000 USDT and get 2000 back!”
• A wallet address is provided. • Sometimes, other users comment they’ve already received their doubled funds. 🎭 What’s really happening: • The account has been hacked — the real owner has no access. • Scammers are posting everything, including the “success stories.” • You send your crypto to the address. • Of course, you never see those 2000 USDT. You just lose your money. ⚠️ Red flags to watch for:In crypto, there is no such thing as “send 1000, get 2000.” Ever. From anyone. ✅ Never participate in a “giveaway” from just one post or tweet — that’s the classic scam trigger. ✅ Don’t rush. These scams rely on emotional traps: greed, hype, FOMO. ✍️ Remember: If something looks too generous to be true — …it probably means you’re the real prize. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

🧾 The P2P Trap: Fake Receipts and Fiat You Never Received There’s a growing scam in P2P crypto trades — and it primarily tar
🧾 The P2P Trap: Fake Receipts and Fiat You Never Received There’s a growing scam in P2P crypto trades — and it primarily targets newcomers to the space. Fraudsters can see your experience level. Most P2P platforms display how many trades you’ve completed. Beginners are chosen on purpose. The whole scheme relies on a common misconception: That the exchange acts as a guarantor for the fiat transfer. Yes — the exchange locks the crypto in escrow during the trade. But it has no control over fiat payments. 🚨 How the scam works: • You initiate a trade to sell crypto for fiat. • The buyer sends a message: “Payment sent! Here’s the receipt.” • The “receipt” shows: • The payment is allegedly completed; • The recipient is listed as the exchange, not you; • A note like:
“Confirm receipt — the exchange will send you the money.”
🎭 What’s really happening: • The exchange does NOT send or manage fiat — it only holds your crypto in escrow. • Fiat is supposed to land directly in your bank account — from the buyer. • These “receipts” are fake. Their goal is to make you confirm the trade prematurely. • Once you confirm, your crypto is released to the scammer. But no fiat ever arrives. ⚠️ What to watch for: ✅ The exchange doesn’t guarantee fiat delivery. It only releases crypto if you manually confirm receipt. ✅ Any “receipt” that: • Lists the exchange as the recipient, or • Claims that “the exchange will send the money” after confirmation — …is a 100% red flag for fraud. 🦉 How to protect yourself: ✅ Only trust your actual bank account — not screenshots, “receipts,” or SMS messages. ✅ Never confirm a P2P trade until the fiat is in your account. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

SaaS Goes Dark: How Ransomware Demands Crypto Ransoms Today, ransomware isn’t about a “lone genius with a laptop.” It’s a str
SaaS Goes Dark: How Ransomware Demands Crypto Ransoms Today, ransomware isn’t about a “lone genius with a laptop.” It’s a structured criminal business model. Services are sold using a SaaS model (Ransomware-as-a-Service), and attacks are launched at scale. How it works: • There are groups that breach corporate infrastructures. The access they gain is then sold on darknet forums and in Telegram groups. Techniques include phishing, brute force, RDP attacks, and more. • Developers offer ready-to-use ransomware on a subscription basis — full-fledged “products” that encrypt files in just a few clicks. These tools are constantly evolving, with faster, stronger encryption. • These kits often include a full infrastructure for receiving ransom payments in cryptocurrency — complete with victim instructions and automatic generation of BTC/USDT wallet addresses. • Organizers take a cut from each successful payment. What the victim sees: • Working files are suddenly encrypted. • A message appears on screen:
Your files have been encrypted. To receive the key, send X BTC/USDT to the specified address.
Why crypto? • Crypto is a convenient tool for such schemes: ✅ A certain level of anonymity ✅ Speed ✅ Irreversibility of payments • Once funds are received, criminals use mixers and cross-chain transactions to obscure their trail. The usual pressure tactics: ✅ Threats to delete files ✅ Threats to leak data to competitors ✅ Threats to publish sensitive information (if such files are found) 🦉 How to reduce the risks: ✅ Make offline backups ✅ Patch vulnerabilities, especially in remote access tools ✅ Train employees not to open suspicious emails or attachments ✅ Implement incident response procedures ✅ If encrypted — immediately contact law enforcement and infosec experts ✍️ Remember: modern ransomware isn’t chaos — it’s an industry. If you’re not preparing in advance — attackers already are. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

🤝 The “Trusted” Escrow That Will Definitely Scam You (The Fake OTC Deal Scheme via Telegram) Here’s another popular scam tar
🤝 The “Trusted” Escrow That Will Definitely Scam You (The Fake OTC Deal Scheme via Telegram) Here’s another popular scam targeting crypto users — a fake OTC deal with an “escrow” agent inside a Telegram group. 👉 OTC (Over-the-Counter) refers to deals made outside official exchanges. 🧩 How the scheme works: • Scammers create a Telegram group posing as an OTC crypto/fiat trading hub. • The group looks alive — fake buyers, sellers, and an “escrow agent” are actively chatting. • The feed includes fake trade screenshots, staged reviews, and staged “successful deals”. • The group is pumped up with bots and fake engagement to build fake trust. Then they start adding real crypto users via ads, reposts, or cross-promo with other channels. 🎭 Here’s how they get you: • You join the group. Everything looks active and legit — feels trustworthy. • You find a deal: buying or selling crypto. • The counterparty insists on using the group’s “escrow” — says it’s safer for everyone. • The “escrow” (also a scammer) reaches out and gives you wallet details. • You send the funds. • Then? You get kicked from the group. Blocked. Funds gone. ⚠️ What to watch out for: ✅ No real OTC escrow operates inside some random Telegram group with zero reputation. ✅ Legit OTC deals happen through trusted referrals and known intermediaries — not strangers in public chats. ✅ All those “reviews”, testimonials, even “screenshots” — easily faked by bots and burner accounts. 🦉 How to stay safe: ✅ Never send funds to an escrow suggested by a random user in a Telegram group. ✅ Check reputation outside the group — ask people you actually trust. ✅ Avoid OTC trades in unknown groups. Stick to reputable P2P platforms with escrow. ✍️ Remember: The better the group looks and the easier the process feels — the more likely it’s a scam. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

🧠 Executive Impersonation: How a Scammer Hit the “Crypto Jackpot” by Posing as a Boss Here’s another scheme where attackers
🧠 Executive Impersonation: How a Scammer Hit the “Crypto Jackpot” by Posing as a Boss Here’s another scheme where attackers masterfully used OSINT and social engineering. Here’s how it unfolded 👇 👤 An HR specialist at a company was contacted by someone posing as a job applicant. The conversation seemed typical at first — the “candidate” asked detailed questions about internal processes, company structure, and team responsibilities. As it turned out later — this was only the reconnaissance phase. The scammer gathered data through: • conversations with HR, • outreach to tech support (posing as a customer), • and open-source intelligence: employee social media, public reports, press mentions. The result? • A full list of employees and their roles • Identified who handles payments and finances • Learned how payments are processed, including those made in crypto 🎭 Then came the final act: • The scammer created a clone of the company executive’s account (matching avatar and name in Telegram) • Reached out to the company’s accountant • Claimed there was an urgent task requiring a crypto payment to a specific address • Added a secondary distraction request to legitimize the pressure — involving a real employee And yes — it worked. The payment was sent. The crypto was gone. ⚠️ How this scheme works: ✅ Step 1 — Recon: gather as much detail as possible about company structure and payment flow ✅ Step 2 — Clone the executive’s account ✅ Step 3 — Create a sense of urgency: “urgent crypto payment” ordered by the boss 🦉 How to avoid falling for this: ✅ All financial operations should go through official, internal channels only ✅ If there’s any doubt — call the actual person (voice confirms identity) ✅ Don’t trust familiar names, avatars, or writing styles — they’re easy to fake ✅ Implement mandatory dual-approval for large payments ✍️ Remember: The more your internal structure is exposed online, the easier it is for attackers to exploit it. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

🦉 P2P Chargeback Attempt: A Real Case from AMLCrypto’s Practice Not long ago, a member of the AMLCrypto team encountered a c
🦉 P2P Chargeback Attempt: A Real Case from AMLCrypto’s Practice Not long ago, a member of the AMLCrypto team encountered a chargeback attempt on a completed P2P crypto-to-fiat transaction made via Bybit. Everything went as expected: ✅ He received the fiat to his bank account ✅ He confirmed the transaction and released the crypto But four days later, he got a call from his bank: A payment dispute had been filed for that exact transfer. As a team that deals with crypto fraud daily, we took this seriously. Within 24 hours, we identified the individual the buyer’s P2P account was registered to — and interestingly, they were located in the same city as our team member. We contacted this person and strongly encouraged them to meet in person to clarify the situation. 🔍 What we uncovered: The account was still legally registered to this user, but they had sold access to their P2P account to someone else. They believed that a written agreement and a recorded handover would protect them from liability. That’s a dangerous misconception. In reality, if the account is still in your name — you’re responsible for everything done through it. 💡 It got even more complicated: There were multiple people involved: • the original account owner • the person who bought the account • a middleman coordinating transactions • and a so-called “drop” (someone used to receive and forward funds) The middleman claimed he wasn’t behind the transfer — and blamed the drop. The drop? Unreachable. At first glance — typical fraud chain. But…
It turned out the “drop” was a victim of phone scammers who manipulated him into participating. In other words, our team member was dragged into a classic social engineering chain — often referred to as a “Black Triangle” scenario.
⚖️ We chose not to pursue criminal charges in this case: • The original account owner was cooperative • No real financial loss occurred • But we were fully prepared to escalate, if necessary 📌 The lesson: In many jurisdictions, law enforcement doesn’t always distinguish between willing fraudsters and those “just helping out.” If you’re part of a chain — even passively — you may still be held liable. Selling your account, “renting out” your credentials, or turning a blind eye to how they’re used can put you at serious legal risk — especially in multi-party schemes. 🛡 Protect yourself: ✅ Only trade with trusted counterparties ✅ Follow proper AML/KYC standards ✅ Never participate in “gray area” schemes 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

📲 Chargeback After P2P? When the Trade Is Over — But They Still Come for Your Money In an effort to combat fraud, banks and
📲 Chargeback After P2P? When the Trade Is Over — But They Still Come for Your Money In an effort to combat fraud, banks and payment providers offer chargeback and dispute mechanisms — meant to protect users who sent money by mistake or were scammed. But now, P2P scammers have learned how to exploit this system. Let’s break down how it works — so you know what to watch out for. 🎬 How the scheme works You sell crypto via a P2P platform — for fiat (USD, EUR, GBP, etc.), usually via: • bank transfer (ACH, SEPA, Faster Payments), • or card-based payment (Visa/Mastercard). 1️⃣ You list an offer or accept one from a buyer. 2️⃣ The buyer sends fiat — you see the funds in your account. 3️⃣ You confirm receipt, release the crypto. Everything seems legit. 👉 But a few days later — or even a week — your bank contacts you: The sender has filed a dispute or recall request for that payment. 🎭 What’s really going on The buyer claims the payment was a mistake or fraud and tries to reclaim the funds — even though the crypto trade is completed. In the case of a card transaction, this may be a chargeback. For bank transfers, it might be a recall request or a “fraud report” to trigger investigation. Banks typically can’t reverse the funds automatically, but they notify you and may pressure you to cooperate. This tactic works because many users don’t know the legal nuances — and panic, fearing legal trouble. In some cases, it may also be part of a more complex scam setup, like the Black Triangle. 🛡 How to protect yourself ✅ Stick to verified traders with strong reputations and positive reviews. ✅ Always request a screenshot or confirmation of the transfer inside the P2P platform chat. ✅ Confirm that the name on the bank transfer or card matches the buyer’s P2P account. ✅ A dispute or chargeback does NOT mean you’re required to return funds — the decision is up to you. ✅ Don’t be intimidated. If the trade was clean and transparent, you’re on legal ground. ✅ Save all chat logs and consult a legal professional if needed. ✍️ Remember: Dispute mechanisms are meant to protect victims — but in the P2P world, they’re increasingly used to pressure honest sellers. Stay cautious. Ask questions. Never return funds blindly. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

📲 SMS Trap: How One Message Can Steal Your Crypto on P2P Platforms When selling cryptocurrency for fiat on P2P platforms, sc
📲 SMS Trap: How One Message Can Steal Your Crypto on P2P Platforms When selling cryptocurrency for fiat on P2P platforms, scammers often use a scheme involving fake SMS or email payment notifications. Here’s how it works — so you know what to watch out for. 🎬 How the scheme works You decide to exchange your cryptocurrency for fiat (USD, EUR, GBP, etc.). You have, for example, USDT on a popular exchange (Binance, Bybit, MEXC, Gate.io, Kraken, etc.). 1️⃣ You go to the P2P section of the exchange. 2️⃣ You post an ad or select an existing offer. 3️⃣ As the payment method, you choose phone number transfer or instant payment app (🇺🇸 Zelle, Cash App, Venmo — USA; 🇪🇺 SEPA Instant, Revolut, bank-linked phone number — Europe). 👉 At this point, the counterparty receives your phone number or linked account details. 🎭 How the scammer operates • They use an exchange account registered under a fake or stolen identity (such accounts are sold on darknet marketplaces 🥷 for $20 to $300). • Instead of sending a real payment, they send you a fake SMS or email, pretending to be a notification from your bank or payment app. They typically don’t spoof the official sender name — the message comes from a random number or email (spoofing sender names has become more difficult).
📩 Example of such text: “Payment received: $1,200.00 USD via Zelle. Available balance: $4,350.00 USD.”
• After sending the message, the scammer starts pushing in chat: “Payment sent, please confirm the transaction.” • The victim, seeing the familiar template, rushes to complete the deal and confirms the transaction on the exchange — without checking the actual bank account or app. 🚨 What happens next • The cryptocurrency is immediately transferred to the scammer’s wallet. • Even if you quickly realize the scam and contact exchange support: • You confirmed the transaction yourself — from the exchange’s point of view, everything was executed correctly. • The scammer usually withdraws the funds instantly — making it nearly impossible to recover them. 🛡 How to protect yourself ✅ SMS or email ≠ payment confirmation. Always verify the actual receipt of funds in your banking app or online banking. ✅ Any pressure to “confirm quickly” is a clear red flag. ✅ Remember: if you confirm the transaction, the exchange is unlikely to refund your crypto — even if fraud is proven. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

👻 Fake Exchange: Great Rates, Friendly Operator — Money Gone More and more scammers are building their own crypto exchange w
👻 Fake Exchange: Great Rates, Friendly Operator — Money Gone More and more scammers are building their own crypto exchange websites — often without even trying to hide behind the names of legitimate brands (aka phishing exchanges). These platforms are widely promoted on Telegram, social media, and crypto forums — luring victims with “unbeatable rates.” 🎣 ❗️But it rarely stops there. The scam is usually combined with other tactics: • 💸 A fake broker (example) convinces the victim to buy crypto and “recommends” their trusted exchange; • 🚚 The exchange offers to process the transaction in person — via a courier who delivers cash, or at an office — but first asks the victim to complete a fake AML verification (example). 💡 In AMLcrypto’s investigations, we’ve seen cases where such exchanges would process small amounts at first — to build trust. But when the victim later sends a large sum — the scammers disappear. 👉 Important: this is no longer a “backyard scam.” It’s a well-structured business funnel. These actors are ready to nurture their victims for months. 🦉 How to protect yourself: ✅ Check the exchange’s domain registration date via WHOIS. ✅ Look for real reviews on independent platforms such as: • Trustpilot • Reddit (r/CryptoScams, r/CryptoCurrency, etc.) • Bitcointalk (Scam Accusations section) ✅ Verify that the exchange is licensed and/or listed with trusted regulatory bodies (e.g. FCA, FinCEN, BaFin), or in official VASP registries. ✍️ Remember: the more “amazing” the deal sounds — the higher the risk. 🛡 AMLcrypto.io | ✔ TG - Bot | 💬 Contact us

🤥 Phishing Metamask: How $1.4M Was Stolen — Despite a Safe and Proper Seed Storage One of the real cases from our practice:
🤥 Phishing Metamask: How $1.4M Was Stolen — Despite a Safe and Proper Seed Storage One of the real cases from our practice: 💰 $1.4M was stolen from a wallet whose seed phrase was stored on paper in a safe. The safe was accessible only to the wallet owner. 🧠 How did this happen? After purchasing a new MacBook Pro, the user started installing her usual apps. She typed “Metamask” into the search bar. The top result was a sponsored ad leading to a phishing website. The site looked identical to the official one, differing only by the domain extension. When clicking “Install Metamask,” the site did not redirect to the official Chrome Web Store, but instead immediately prompted her to enter her seed phrase — supposedly to “restore” her wallet. After entering the seed phrase, the site redirected her to the actual Chrome Web Store, where she installed the official Metamask extension. ⚠️ The prompt to enter the seed phrase again inside the extension seemed like a minor inconvenience at the time. ❗️ The user had no idea she had visited a phishing site — she believed she had installed Metamask from the “official website.” As a result, the attackers gained full access to the wallet and drained all the funds.
💡 Interesting fact from the investigation: we discovered that the client had visited a phishing site only after analyzing the browser history — she was completely unaware of it.
🚨 Important: scammers create such phishing sites not only for Metamask, but also for other popular crypto wallets — Trust Wallet, Phantom, and many others. 🔐 How to protect yourself: • ✅ Only use officially verified wallet websites. Cross-check information from multiple sources: official websites, social media, verified wiki articles, crypto forums, and trusted AI tools. • 🚫 Never click on sponsored ads in search engines to download wallets or apps. • 🔎 Double-check websites using site reputation tools — for example, https://www.scamadviser.com. • ⚠️ Stay alert: any unusual website behavior — strange prompts, seed phrase requests outside the expected flow — is a major red flag. • 🛡 Only enter your seed phrase in a verified official app or extension — and only when you are intentionally restoring your wallet. 🚨 Lost funds? AML Crypto can help investigate the incident, prepare a professional report, and increase your chances of recovery. We engage within just a few hours. 🛡 Web | ✔ TG - Bot | 💬 Contact us

💔 Blockchain Romance: A Love Story That Ended in a Mixer 📖 This is the story of one of our clients. Let’s call her Alena, 3
💔 Blockchain Romance: A Love Story That Ended in a Mixer 📖 This is the story of one of our clients. Let’s call her Alena, 35. She met a man on Telegram. Russian, living in Germany 🇩🇪 for over 10 years, works in IT. Polite, humble, always in touch. The conversation unfolded gradually: books, life abroad, moving, loneliness. After a couple of weeks, he brought up crypto. 💬 “You’re smart. I’ll help you figure it out. That’s how I earn — steadily.” He sent her a link to an “international exchange.” Looked completely legit: charts, balance, support chat. Alena deposited 1,000 USDT. 🟢 The very next day, her balance had grown by 5% — up to 1,050. He showed her how she could withdraw $200. The money actually arrived. 💬 “See? It works. But don’t withdraw now — better to grow the balance for higher profits.” Alena deposited more. And then more. Within two weeks, she had deposited 23,800 USDT. 🚨 When she tried to withdraw a large amount, an “error” popped up: “Withdrawals are temporarily locked. To unlock, please deposit an amount equal to your transfer.” ⚠️ He said it was a standard anti-money laundering (AML) check. “Things are strict in Germany,” he added. Alena sent more. The last transfer was done with a credit card 💳 — she had to buy more crypto. Then came a new requirement: “Please pay income tax.” 🤔 She got suspicious. She reached out to AML Crypto. 🔎 We explained: this is a classic scam. The site is a fake, mimicking a real exchange. No legitimate platform asks for additional payments for “unblocking” or “taxes.” 💡 We also emphasized: threats and begging don’t work — scammers hear it all the time. The only way forward is to start an investigation, collect digital traces, and contact law enforcement. 🤦‍♂️ Two days later, he messaged again — “generously” offering to transfer part (!) of the funds within the platform, but said half still had to be paid upfront. 🔍 What AML Crypto’s analysis revealed: • 💱 The funds were swapped via Uniswap: USDT → ETH • 🕸 The ETH was dispersed across numerous blockchain addresses • 🌪 Then it was funneled through Tornado Cash, a mixing service • 🧩 One address had previously been linked to a similar scam • 🏦 A centralized exchange was also identified, from which native tokens were sent to one of the scammer’s addresses to cover gas fees — allowing for an official request to help identify the individual behind the activity
📄 With such a request, law enforcement may obtain: • ✅ KYC data: full name, documents • 📧 Registered email and phone number • 🌐 Login logs with IP addresses • 📊 Full transaction history • 💼 Account balances and current assets • …
⚖️ Even if the account is registered to a drop (fake identity), this data helps build connections, collect digital traces, and create a solid evidence base. ❤️‍🩹 Love isn’t a reason to take out credit. Trust without verification can cost you dearly. 🛡 Web | ✔ TG - Bot | 💬 Contact us

🚨 CLIPPERS — When the Enemy Is Already in Your Clipboard! You’re an experienced crypto user. You don’t fall for “investor-ex
🚨 CLIPPERS — When the Enemy Is Already in Your Clipboard! You’re an experienced crypto user. You don’t fall for “investor-experts”, you never connect your wallet to shady fake AML-check websites, and no one’s going to trick you with a fake token during a swap. Your crypto is under control, and your decisions are sharp and calculated. That’s what one of our clients thought — until the day he personally sent 19,800 USDT straight to a scammer. 😐 How did it happen? A regular business conversation in Telegram. He asked the counterparty for a blockchain address to send 19,800. Ctrl+C — copied the address, Ctrl+V — pasted into the recipient field. 💸 Clicked “Send”. Transaction went through. Status: Success. But the counterparty replied: “Nothing received.❓ A typo in one of the 34 characters of the Tron address? Double-checked… 😱 WTF… Every single character is different. 📛 That’s a clipper. 🔍 What is a clipper and how does it work? A clipper is malicious software that silently replaces any copied blockchain address with one from a scammer’s list. It lives in your system undetected — until the right moment. 🛠 How the scheme works: 1. The virus gets onto your device — usually via “free” software, cracks, fake updates. 2. When you copy a wallet address, it’s automatically replaced with the attacker’s address. 3. You paste the fake address and send the funds — without even noticing. 🛡 How to protect yourself from clippers: ✅ Use the satoshi test — first send a small amount and confirm receipt. ✅ Install antivirus software and run regular system scans. ✅ Don’t download software from sketchy sources. Paying for a license is cheaper than losing all your assets.
💬 AML Crypto helps victims of clippers and other crypto scam schemes. We: 🔎 trace the movement of stolen funds 🧠 tag and identify scammer addresses 📄 prepare documentation for appeals 🤝 communicate with exchanges and law enforcement
🛡 Web | ✔ TG - Bot | 💬 Contact us

🤥 Beware of ENS: Scammers Are Exploiting Trust Since the launch of Ethereum Name Service (ENS), it’s been widely adopted not
+1
🤥 Beware of ENS: Scammers Are Exploiting Trust Since the launch of Ethereum Name Service (ENS), it’s been widely adopted not only by regular users but also by scammers. And although the scheme isn’t new, it still works—especially among victims with low crypto literacy. 🧠 How does it work? ENS allows replacing a long wallet address with a readable name. Instead of 0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045, you can simply use vitalik.eth. Convenient—but risky. Here’s how scammers operate: 1. They create spoofed domains like vital1k.eth instead of vitalik.eth. 2. They register ENS domains that mimic real wallet addresses. For instance, Bybit’s hot wallet is 0xf89d7b9c864f589bbF53a82105107622B35EaA40. A scammer registers 0xf89d7b9c864f589bbF53a82105107622B35EaA40.eth. If someone sends funds to that ENS address by mistake, the money goes straight into the scammer’s wallet. 3. Using social engineering, scammers impersonate exchange representatives and convince victims to send funds to .eth addresses—creating an illusion of trust and legitimacy.
🧐⚠️ This exact domain is already registered. If you try to send anything to 0xf89d7b9c864f589bbF53a82105107622B35EaA40.eth, the funds will go to 0x43df365C5286c3b15bec82188c877871c1EbB9c6—not where you expected.
🔐 How to protect yourself: • Don’t trust ENS domains blindly. Always check what address is behind them: https://ens.domains/ • Never send crypto to an ENS address unless you’re 100% sure—especially if the amount is significant. • Improve your crypto literacy. Basic attentiveness is one of the strongest tools for self-protection. 🚨 Already lost your funds? AML Crypto can help you trace the assets, prepare a professional report, and increase your chances of recovery. We act quickly, lawfully, and have real-world case experience. We’re ready to step in within hours of your request. 🛡 Web | ✔ TG - Bot | 💬 Contact us

🧨 Scam with MEMO: When You Send Money to a Scammer Yourself — Without Even Realizing It Scammers have learned to exploit a s
🧨 Scam with MEMO: When You Send Money to a Scammer Yourself — Without Even Realizing It Scammers have learned to exploit a specific feature of certain blockchain networks — MEMO / TAG / Payment ID, which is a mandatory parameter for transfers on networks like XRP, EOS, WAX, and others. 📌 In these networks, exchanges use a shared deposit address for all users — unlike Ethereum, Tron, or Bitcoin where each user gets a unique address. To credit your funds correctly, the exchange requires you to specify a MEMO / TAG / Payment ID — this is your personal identifier on the platform. 💡 Enter the wrong MEMO — and the money goes to someone else. 🎯 Scammers are taking advantage of this. 🎭 How the scam works: 1️⃣ They create an account on an exchange and receive their own MEMO. 2️⃣ They contact you pretending to be from the exchange or support team. 3️⃣ They provide a legitimate exchange address to avoid suspicion. 4️⃣ But they insert their own MEMO instead of yours. 5️⃣ You copy everything and send the funds. 6️⃣ The exchange receives the funds and, based on the MEMO, credits the scammer’s account. They quickly withdraw the assets. ⚠️ From a technical point of view — everything was correct. ❌ But your money didn’t go to you. And getting it back is extremely difficult. 🧠 Why this is dangerous 🚫 Exchanges don’t verify whether the MEMO actually belongs to you. 🙈 Users often think MEMO is just a “comment” field — not a critical part of the transaction. 🧾 Everything looks “clean” — no phishing, no address spoofing. ✅ How to protect yourself 🔐 Always copy the MEMO directly from your personal account on the exchange. 📵 Never trust payment details sent via messengers or forums. 🧩 Understand how transfers work in your chosen blockchain network. If you use exchanges, wallets, or send crypto, it’s crucial to know which parameters impact the transaction. MEMO is not optional — it’s a vital element. Spend 10 minutes learning how your network works — it could save you thousands. 🛡 Web | ✔ TG - Bot | 💬 Contact us

🙈🙊🙉 The “Black Triangle”: How Victims, Money Mules, and P2P Crypto Sellers Get Caught in a Money Laundering Scheme The Bla
🙈🙊🙉 The “Black Triangle”: How Victims, Money Mules, and P2P Crypto Sellers Get Caught in a Money Laundering Scheme The Black Triangle is a real and growing scam pattern where unsuspecting individuals become part of a laundering chain — sometimes without even knowing it. 📌 How the Scam Works 1️⃣ The Victim Scammers impersonate: — bank fraud prevention teams, — law enforcement officers or federal agents, — representatives of tax authorities, healthcare, social services, or even schools. They create urgency using pretexts like: 🔹 unauthorized access to your online banking or accounts, 🔹 identity theft alerts, 🔹 unclaimed tax refunds or legal notices, 🔹 school data updates for your child, 🔹 security upgrades for your home. ❗️The outcome — they convince the victim to: — transfer funds to a “secure holding account”, — apply for personal or payday loans to “protect your credit”, — provide remote access or personal data via screen sharing tools or fake websites. Once access is gained, loans are issued in the victim’s name and the funds are withdrawn — starting the laundering phase. 2️⃣ The Money Mule (Drop) The loan funds are transferred to a bank account controlled by a third party — often someone who has sold or rented access to their account on forums or to “money flipping” recruiters on social media. Scammers fully manage the account, while the mule may think they’re just helping with “crypto arbitrage” or “job-related payments” — unaware they’re enabling a crime. 3️⃣ The P2P Crypto Seller Scammers go to a peer-to-peer crypto exchange (e.g., Bybit, Binance P2P, MEXC, Telegram Wallet, LocalBitcoins) and look for a crypto-for-fiat listing. 💸 Using the mule’s account, they send fiat money to the wallet or bank details of the P2P seller. The seller receives the payment, releases USDT or BTC — and believes it’s just another trade. But the fiat originated from fraud. ⚠️ The seller now becomes part of the laundering chain — whether they realize it or not. 🎯 What happens next? The real victim realizes what happened and files a complaint. Law enforcement traces the flow of funds — first to the mule, then to the P2P seller’s account. This can result in: — account freezes, — law enforcement inquiries, — KYC reviews or delisting from platforms, — potential legal exposure. ✅ How to Reduce Risk (for P2P Sellers): — Avoid first-time buyers with incomplete profiles — Never accept payments with misleading notes (e.g., “for goods” or “invoice”) — Cancel trades if the payment source looks suspicious — Ask for proof of identity and ownership of the payment method — Always wait for the receipt and proper confirmation before releasing crypto 👮 For Law Enforcement Investigators: — When a user claims they’re involved in a P2P trade, request:  • exchange account details,  • exact transaction or trade ID,  • wallet info and fiat side account confirmation. — Send formal data requests to the exchange to identify both sides of the trade. 💡 Money laundering isn’t always obvious. The Black Triangle shows how fast trust-based systems can be abused. If you’re a victim, seller, or platform seeing suspicious activity — act early. Time is everything in these cases. 🛡 Web | ✔ TG - Bot | 💬 Contact us

☠️ The Counterparty’s Fake Shadow: Similar Address Attack 📅 This scheme has been active since 2022 and is still in use today
+1
☠️ The Counterparty’s Fake Shadow: Similar Address Attack 📅 This scheme has been active since 2022 and is still in use today. Scammers monitor active blockchain wallets and generate millions of addresses that are visually similar — typically matching the beginning and end of legitimate addresses. When you send or receive a transaction, the attacker sends a small amount (e.g., 0.001 USDT; in some cases we’ve seen up to 8 USDT) from one of these similar addresses to your wallet. The goal is simple: to mislead you into copying the fake address instead of the legitimate one — and ultimately send your funds to the scammer.
In November 2024, AML Crypto was among the few companies brought in within minutes to investigate an incident where a user mistakenly transferred $129 million USDT to a scam address.
The funds were recovered thanks to swift action, the scammers’ panic over such an unusually large sum, and coordinated efforts by analytics firms, law enforcement, and regulators. Within the first hour, a detailed analysis of the fake address network and sources of funds was conducted — despite the use of bridges and attempts to obscure the trail. The graph provided illustrates the analysis of fund sources related to this attack, specifically tied to a 1.01 USDT transaction — a key lead that helped identify services leaving digital traces of the perpetrators.
Returning only 90% of the funds wasn’t enough to let the attackers “swap their black hats for white ones” — the attempt to pose as ethical hackers failed. They were forced to return every last dollar.
🦉 How to Stay Safe: ✅ Never copy addresses from your transaction history — they may have been spoofed to resemble a legitimate address. ✅ Verify the entire address, including the middle part — don’t rely solely on the beginning and end. Make sure it matches exactly. 🛡 Web | ✔ TG - Bot | 💬 Contact us