Mixer scam checklist before you send
Use this mixer scam checklist before you send: verify the hostname, read the original terms, and stop when the destination or payment demand changes.
Start with the hostname
A clone can reproduce page copy, colors, and buttons. It cannot use the exact registered hostname while the legitimate site still controls it.
Read domains from right to left: the registered domain sits immediately before the final suffix. Everything to its left is a subdomain.
Run four checks in this order
A failed hostname or a changed payment demand is enough reason to stop.
- 1
Domain and URL anatomy
Most mixer scams are look-alike domains. Read the address bar like a forensic artefact before you trust anything on the page.
- Read the hostname right-to-left: the true site is the label immediately left of the final .tld (e.g. example.com in a.example.com).
- Watch for swapped or doubled characters, added hyphens, and alternate TLDs (.net / .io / .app) imitating a known .com.
- Be suspicious of look-alike Unicode characters that render like Latin letters.
- A padlock means the connection is encrypted. It says nothing about who owns the site.
- 2
Clone and impersonation checks
Clones copy the entire interface. The one thing they cannot copy is the exact, correct domain.
- Compare the hostname with a source you already trust. Do not rely on a link from a message, ad, or search result.
- Distrust unsolicited links in DMs, comments, and paid ads claiming to be the 'official' mixer.
- If a page shows fake live 'payout' tickers or countdowns to pressure you, treat it as manipulation.
- After any redirect, stop at the destination and verify its hostname before entering an address, amount, or other transaction detail.
- 3
Surprise AML-fee pattern
The most common exit scam: your funds are 'held for AML review' after deposit and released only if you pay more.
- Stop if a new fee appears after deposit. Legitimate terms are shown before payment.
- There is no such thing as a 'compliance fee to release your own funds' from an anonymous route.
- A shifting fee between quote and settlement is a red flag; the quote should hold.
- Walk away from any demand to pay more to unlock a deposit. Another payment does not resolve the contradiction.
- 4
Support and status verification
Check whether the operator behaves like something you can hold accountable, before you rely on it.
- Confirm a real support channel exists and answers a basic question before you transact.
- Check whether terms, fees, and network support are documented up front rather than improvised.
- Prefer routes that state their limits honestly over ones that promise anonymity or guaranteed acceptance.
- Stop when the operator will not answer a direct question about identity, fees, or timing.
Stop when the deal changes after deposit
Reasons to walk away
- Guarantees of anonymity, untraceability, or '100% clean' output.
- A fee or 'AML hold' that appears only after you deposit.
- A redirect lands on an unexpected hostname or keeps changing domains before the quote appears.
- Promises that any exchange will accept the funds with no questions.
- Pressure tactics: countdowns, fake live payouts, 'act now' scarcity.
- Look-alike domain, alternate TLD, or a link pushed via DM or ad.
Useful signals, not guarantees
- Fees and terms are stated clearly before you commit.
- The interface asks only for a destination address.
- The destination hostname is stable, readable, and can be checked before you enter transaction details.
- Limits are stated without guarantees of absolute anonymity.
- Asset and network are labelled explicitly to prevent a mismatch.
- Nothing changes between the quote and the settlement.
References for the safety checks
These sources provide category, enforcement, and domain-reputation context. A live hostname and route quote still need to be checked directly.
- Source: Public Advisory: Cryptocurrency Mixers, U.S. Secret Service
- Source: Crypto Mixers and AML Compliance, Chainalysis
- Source: Third-party domain reputation reviews, Scam Detector