Google’s AI lists a wallet drainer as the top free AML checker. We read its code and followed the money

PublicAML · On-chain investigation · 8 October 2026

Ask Google which crypto AML checkers are really free, and its AI answer puts a site called AML.legal first: “100% free with no account required”. The site says the same about itself — no wallet connect, no seed phrase. For Bitcoin that is true. Paste an Ethereum or Tron address and you are taken to a different page, hidden from search engines, where you are asked to connect your wallet and sign a USDT approval. The code behind that page is a wallet drainer; its own comments call it one. On Tron the approval goes to a contract that has already taken 10,069 USDT from six addresses. Seventy-one addresses have signed approvals to it, the latest two days ago.

#1

in Google’s AI answer for “free crypto aml checks”, 8 Oct 2026

71 addresses

have approved the drainer contract to spend their USDT; 53 of them in September

10,069 USDT

taken from six addresses in seven transactions so far

2 sites

use the same contract: aml.legal and amlsecurity.financial

What Google shows

On 8 October 2026 we searched Google for “free crypto aml checks”. The AI-generated answer offered a list headed “Truly Free & No-Signup AML Checkers”. The first entry was AML.legal Wallet Scanner, described as “100% free with no account required”, followed by a comparison table that gave it “Unlimited” checks, no account, and Bitcoin, Ethereum, Tron and BSC. The site also appeared in the source cards next to the answer. The screenshot is below.

Google’s AI answer for “free crypto aml checks”, captured on 8 October 2026: AML.legal is listed first and appears in the source cards
Google’s AI answer for “free crypto aml checks”, captured on 8 October 2026: AML.legal is listed first and appears in the source cards

This is not a paid advertisement, and we do not suggest Google was paid. It is the search engine’s own AI summary repeating what the site says about itself. That is the problem: the site is written to be believed by exactly this kind of reader.

What the site says, and what it does

The home page is unusually candid in tone. It lists six checks and admits two are “not wired”. It says the scan runs in your browser and invites you to open developer tools and watch. Under the button it promises: No wallet connect. No seed phrase. No storage. No KYC. For Bitcoin, Solana, Litecoin and the other chains this is roughly what happens: the page matches your address against a downloaded list of 879 OFAC addresses and shows a score.

For Ethereum and Tron — the two chains where USDT lives — something else happens. A separate script, net-redirect.js, watches the address field. Its own header comment explains the plan: when an Ethereum or Tron address is typed or the network is picked, the address field and the list of datasets are hidden and the “Run free AML check” button opens /check or /tron/check, described in the code as the “wallet-connect page”.

Those two pages are excluded from search engines in the site’s robots.txt, with a comment: “Wallet-connect check pages (both chains) — keep out of the index.” So the pages Google can read say “no wallet connect”, and the pages that require one are the pages Google is told not to read.

On them you choose a token — USDT first — connect a wallet, and sign. The site’s own video description says so in plain words: “Trust Wallet is connected and a one-time USDT approval is signed”, after which a risk score appears.

An AML check never needs your signature

Checking an address means reading public data about it. Nothing has to be signed, because nothing has to be changed. An approval is the opposite: it is a permission, written to the blockchain, for someone else to move your tokens. It does not expire and it does not ask again. Anyone who holds it can take the approved amount at any time, including tokens that arrive later.

So the request itself is the tell. A tool that asks you to approve USDT in order to “screen” your wallet is not screening it.

What the code is

We downloaded the scripts and read them. We did not run them and did not connect a wallet.

The Ethereum page loads a well-known drainer kit. It carries a setting named Receiver, a flag named CF_Drain_Succeeded, routines for token approvals, Permit signatures and NFT transfers, and configuration comments in Russian — one of them tells the operator to enter “the domain attached to the drainer’s server”. The receiving address is fetched from that server only after a wallet connects, so we cannot name it.

The Tron page is obfuscated, but its configuration decodes to one line that matters: the approval spender is the contract TKEviNj8x4pu5BnE5r9vLNQj9tL3stkb5V. A third script reports each visitor to a Telegram bot, in Russian — who connected, from which device, and “total on wallet” in dollars.

A second site, amlsecurity.financial, serves the same Tron configuration with the same contract.

What the contract has done

The contract was deployed on 15 July 2026 by TB8Lm8AX9jof9f537wcF4oqZwE5feuTC44. Since then 71 addresses have signed 128 USDT approvals to it. Forty-nine of the approvals are for an unlimited amount and the rest for 100 to 400 million USDT — in practice, everything. Two addresses approved in July, 11 in August, 53 in September — the home page gives 1 September as its publication date — and five in the first week of October, the latest on 6 October.

The deployer has called the contract’s withdrawal function seven times. Those calls moved 10,069 USDT out of six addresses, between 8 August and 29 September. Six of the seven payments went to one wallet, TRkA7dbycPbTyDBEzHSc4xHx4sJqmjjXfM; the first went to the deployer itself. The largest victim lost 6,793 USDT in two withdrawals three hours apart on 23 September.

The receiving wallet passed everything on within hours, in 16 payments of a few hundred dollars each: some swapped through a Tron exchange protocol, one of 700 USDT to a deposit address at Bybit, the rest to addresses without a label.

The sums are small so far. Most wallets that approved held little: when we checked, the approvers we looked at had a few dollars between them. Some of the 71 are probably the operators’ own test wallets. But an approval does not expire, and every one of these addresses will lose whatever USDT it receives next for as long as the approval stands.

When (UTC)FromToAmountTx
15 Jul 2026, 12:14TB8Lm8AX…euTC44TKEviNj8…stkb5Vcontract deployed
the contract the site names as approval spender is created
43e04358…59f8b6
19 Aug 2026, 13:37TLkSf8Aj…mhXzjRTRkA7dby…mjjXfM1,300.92 USDT
first sizeable withdrawal from an address that had approved
85f25bc9…8a8ba0
23 Sep 2026, 12:34TWXebhZf…va87QvTRkA7dby…mjjXfM2,612.00 USDT
largest victim, first withdrawal
7f06dbfc…7cd398
23 Sep 2026, 15:55TWXebhZf…va87QvTRkA7dby…mjjXfM4,181.52 USDT
same victim, three hours later
2f6c9f19…5ed653
29 Sep 2026, 16:35TSGzX6od…tiGv85TRkA7dby…mjjXfM1,898.22 USDT
latest withdrawal so far
a2254d4c…d6d5a7
29 Sep 2026, 23:13TRkA7dby…mjjXfMTEAQ9BGb…mig2V6700 USDT
one of 16 onward payments, to a deposit address at Bybit
—

If you used it

If you connected a wallet on aml.legal or amlsecurity.financial and signed anything, revoke the approval now. On Tron, open your address on Tronscan, go to the approvals list and cancel the one for the contract above; on Ethereum use a revoke tool such as revoke.cash. Until it is revoked, do not receive USDT on that address. Revoking costs a small network fee and takes a minute.

The rule for next time is short: an address check needs the address and nothing else. Any “AML check” that asks you to connect a wallet, sign, approve, or enter a seed phrase is a theft attempt, whatever the page says about itself and wherever you found the link.

What we did

None of the three addresses was in our database when we started. We have now marked the contract, its deployer and the receiving wallet as phishing. We did not mark the people whose money was taken or the addresses that only signed an approval. You can check any address — without connecting anything — on the address check page.

What this page does not say

It does not say who runs the site; the name its markup points to may be invented or stolen and we do not repeat it. It does not say Google was paid or acted knowingly — only what its AI answer showed on the day we looked. It does not say every one of the 71 addresses is a victim. On Ethereum we describe the code but name no receiving address, because none is visible without connecting a wallet, which we did not do.

Check an address yourself

Free, no sign-up. Paste any address to see whether it is linked to this or any other incident:

Sources: the public files of aml.legal and amlsecurity.financial, downloaded and read on 8 October 2026 (not executed, no wallet connected); Tron chain data via TronGrid, read the same day; a Google search result page captured on 8 October 2026. This is an information resource about transactions between addresses, not financial or legal advice, and it names no individual as responsible for anything.