Check a TON Wallet for AML Risk | AML Verifier

Check a TON Wallet for AML Risk

Before sending or accepting Gram, formerly known as Toncoin, USDT, or another asset on The Open Network, it is important to understand whether the wallet may be connected to sanctions, scams, stolen funds, mixers, high-risk exchanges, fraudulent services, or other suspicious activity.

A TON wallet can appear normal while still having direct or indirect exposure to risky transaction flows.

AML Verifier helps users check a TON wallet and review its blockchain risk exposure before completing a transaction.

Check a TON wallet

What Is a TON Wallet?

A TON wallet is a blockchain account used to manage assets and interact with applications on The Open Network.

In everyday language, the term “TON wallet” is often used to describe the public address associated with that account.

A TON wallet may be used to:

  • send and receive Gram;
  • hold and transfer USDT on TON;
  • manage other fungible tokens known as jettons;
  • interact with smart contracts;
  • use decentralized applications;
  • make payments;
  • receive assets from other users or services.

A public TON address can be shared and analyzed using blockchain data.

It is not the same as:

  • a private key;
  • a seed phrase;
  • a wallet password;
  • access to the wallet application.

Private credentials must never be shared with an AML screening service or counterparty.

Gram, Formerly Toncoin

Gram is the current official name of the native cryptocurrency of The Open Network.

It was previously known as Toncoin.

Following a community vote in 2026, Toncoin was renamed to Gram. The blockchain itself continues to be called The Open Network, or TON.

Gram may be used for:

  • transfers between TON accounts;
  • network and smart-contract fees;
  • staking-related activity;
  • payments;
  • interactions with applications;
  • transferring jettons;
  • processing messages on the network.

Some wallets, exchanges, applications, and older materials may continue to display the former Toncoin name or the TON ticker during the transition.

For this reason, users should confirm both the network and the asset before completing a transfer.

Why Check a TON Wallet?

TON transactions are publicly recorded, but the risk associated with a wallet cannot be determined simply by looking at its address.

A TON wallet may have direct or indirect exposure to:

  • sanctioned entities;
  • stolen cryptocurrency;
  • scams and fraudulent services;
  • phishing operations;
  • compromised wallets;
  • crypto mixers;
  • darknet-related services;
  • ransomware;
  • high-risk exchanges;
  • unlicensed gambling services;
  • fraudulent investment platforms;
  • suspicious P2P counterparties;
  • high-risk payment processors;
  • money laundering networks;
  • other suspicious services.

Checking a TON wallet before sending or receiving assets can help identify warning signs and provide additional context for the transaction.

When Should You Check a TON Wallet?

A TON AML check may be useful before:

  • accepting Gram from an unknown person;
  • receiving USDT or another jetton;
  • sending assets to a new counterparty;
  • completing a P2P transaction;
  • processing a customer withdrawal;
  • accepting a business payment;
  • completing an OTC transaction;
  • depositing assets to a centralized exchange;
  • interacting with an unfamiliar service or Mini App;
  • investigating a suspicious incoming transfer.

A check may also be useful after receiving assets if an exchange, payment provider, auditor, bank, or compliance team asks for information about their origin.

How to Check a TON Wallet

The process is straightforward:

  1. Copy the public TON address you want to analyze.
  2. Open AML Verifier.
  3. Select the TON network.
  4. Paste the wallet address.
  5. Start the AML check.
  6. Review the risk score and risk level.
  7. Examine the detected exposure categories.
  8. Review the transaction relationships.
  9. Save the report if necessary.

Make sure that you enter a wallet address rather than a transaction hash.

Start a TON wallet check

TON Wallet Address vs Transaction Hash

A wallet check and a transaction check answer different questions.

TON wallet address

A TON address identifies an account on The Open Network.

A wallet check helps analyze the broader blockchain activity and risk exposure associated with that account.

Transaction hash

A transaction hash identifies a particular on-chain transaction.

A transaction check may focus on:

  • the account processing the transaction;
  • incoming and outgoing messages;
  • the transferred asset;
  • the amount;
  • the transaction time;
  • the transaction status;
  • the risk connected to the specific transfer.

Because TON uses message-based interactions, one user action may produce multiple related messages and transactions.

For additional context, it may therefore be useful to review both the wallet and the relevant transaction chain.

What Does a TON Wallet Check Show?

The available results may include:

  • overall risk score;
  • risk level;
  • identified entity information;
  • sanctions-related exposure;
  • scam or fraud exposure;
  • stolen-funds exposure;
  • mixer exposure;
  • darknet-related activity;
  • ransomware connections;
  • high-risk exchange exposure;
  • gambling-related exposure;
  • suspicious service categories;
  • direct and indirect transaction relationships;
  • wallet activity information;
  • broader transaction-history context.

The report helps transform raw TON blockchain data into risk information that can be reviewed by individuals, businesses, and compliance teams.

TON Address Formats

TON addresses can be represented in different formats.

A user-friendly Mainnet address may commonly begin with:

  • EQ for a bounceable address;
  • UQ for a non-bounceable address.

TON addresses may also be represented in a raw format containing the workchain and account identifier.

Different representations can refer to the same underlying account.

When performing an AML check, use a valid address format supported by the service and confirm that the TON Mainnet network is selected.

Bounceable and Non-Bounceable Addresses

TON user-friendly addresses contain metadata indicating whether a message should be bounceable or non-bounceable.

Bounceable address

A bounceable address is generally used when the receiving account is active and capable of processing the incoming message.

If message processing fails, the remaining value may be returned according to the message rules.

Non-bounceable address

A non-bounceable address may be used when sending the first funds to an account that has not yet been initialized or when the receiving service specifically requests that format.

The bounceable and non-bounceable versions can represent the same underlying TON account.

This distinction is related to message delivery and does not create two separate wallet owners.

Always use the address format provided by the recipient, wallet, exchange, or payment service.

TON Wallets Are Smart Contracts

A standard TON wallet is implemented as a smart contract.

The wallet contract can:

  • verify an owner’s authorization;
  • process incoming external requests;
  • create outgoing internal messages;
  • transfer Gram;
  • interact with other contracts;
  • initiate jetton transfers.

A TON account may exist before its wallet contract has been deployed.

After funding and deployment, the account can become an active wallet contract.

Different wallet contract versions may provide different capabilities, but the public account address remains the key identifier used for blockchain analysis.

TON Uses Message-Based Transactions

TON has a message-oriented architecture.

Accounts and smart contracts communicate by sending and processing messages.

A user action may therefore produce:

  • an external request to a wallet;
  • an internal message from the wallet;
  • another message to a recipient or token contract;
  • additional messages generated during smart-contract execution;
  • several related transactions across the resulting message chain.

This is especially important when reviewing:

  • jetton transfers;
  • decentralized application activity;
  • swaps;
  • payments processed by contracts;
  • transfers involving custodial services;
  • complex smart-contract interactions.

The first visible transaction may not always represent the entire economic path of the assets.

For a complete analysis, the related messages, contracts, and destination accounts may also need to be considered.

Jettons on TON

Jettons are fungible tokens issued on The Open Network.

They serve a role similar to ERC-20 tokens on Ethereum.

Jettons may include:

  • stablecoins;
  • payment tokens;
  • utility tokens;
  • assets issued by applications;
  • exchange-related tokens;
  • other fungible digital assets.

USDT on TON is implemented as a jetton.

A jetton normally uses:

  • a master contract that defines the token;
  • a separate jetton wallet contract for each holder.

The jetton wallet contract is associated with the owner’s main TON address but is a separate on-chain contract.

For this reason, a jetton transfer may involve more contracts and messages than a simple transfer of Gram.

TON Wallet Check vs Jetton Check

A general TON wallet check reviews the broader activity associated with the owner’s address.

This may include:

  • Gram transfers;
  • jetton activity;
  • smart-contract interactions;
  • identified counterparties;
  • direct and indirect exposure;
  • broader wallet risk.

A particular jetton transfer may also involve:

  • the jetton master contract;
  • the sender’s jetton wallet contract;
  • the recipient’s jetton wallet contract;
  • the owner addresses;
  • internal messages used to complete the transfer.

The correct analysis should therefore consider both the main TON wallet and the relevant token-transfer path.

USDT on TON

USDT is available on The Open Network as a jetton.

A TON wallet may be used to receive both Gram and USDT, but they are different assets.

Gram

Gram is the native cryptocurrency used for network fees, transfers, and smart-contract execution.

USDT on TON

USDT is a stablecoin issued as a jetton on TON.

A wallet receiving USDT still needs a sufficient amount of Gram when network fees or further token transfers must be paid.

Before accepting USDT on TON, confirm:

  • the correct network;
  • the recipient address;
  • the authentic jetton;
  • the amount;
  • any required comment or payment identifier;
  • the counterparty’s AML risk.

USDT exists on several blockchains, so selecting the wrong network can result in loss of access to the assets.

TON Wallet Check vs USDT TRC20 Check

USDT is available on both TON and TRON, but these are separate blockchain networks.

USDT on TON

USDT on TON is implemented as a TON jetton and uses TON addresses and TON transaction architecture.

USDT TRC20

USDT TRC20 is issued on the TRON network and uses TRON addresses and TRC-20 smart contracts.

An address from one network should not be treated as an address from the other.

For users handling USDT on TRON, use the dedicated guide:

Check a USDT TRC20 wallet for AML risk

Comments, Memos, and Payment Identifiers

TON transfers can include a text comment or another payload.

Some exchanges, payment processors, custodial services, or merchants may require a specific comment, memo, invoice identifier, or payment reference.

Sending assets without a required identifier may make it difficult for the receiving service to credit the correct account.

Before sending funds:

  1. confirm the destination address;
  2. confirm the network;
  3. confirm the asset;
  4. check whether a comment or memo is required;
  5. copy the identifier exactly;
  6. verify the wallet’s AML risk;
  7. send a small test amount when appropriate.

An AML check evaluates blockchain risk but does not replace correct payment instructions.

Direct and Indirect Exposure

TON AML analysis should consider both direct and indirect exposure.

Direct exposure

Direct exposure exists when the checked wallet sends assets directly to or receives assets directly from an identified address, entity, or service.

For example:

TON wallet A → Identified high-risk service

There is no intermediary wallet or service between the checked account and the identified entity.

Direct exposure is generally easier to interpret because the relationship is immediate.

Indirect exposure

Indirect exposure exists when assets pass through one or more intermediary wallets, smart contracts, or services.

For example:

TON wallet A → Intermediary contract → High-risk service

Indirect exposure does not automatically prove that the wallet owner knowingly interacted with the final high-risk entity.

Its significance may depend on:

  • the number of transaction or message hops;
  • the amount involved;
  • the percentage of wallet activity involved;
  • how recently the exposure occurred;
  • whether the pattern is repeated;
  • whether an intermediary belongs to an identified cluster;
  • the type of high-risk service;
  • the purpose of the transaction.

A small historical connection several hops away may require a different response from a recent and repeated flow involving substantial value.

How to Understand the TON Wallet Risk Score

A risk score summarizes multiple blockchain risk signals into one result.

In general:

  • Low risk indicates that no significant high-risk exposure was detected in the available data.
  • Medium risk indicates that some exposure, uncertainty, or unusual activity requires additional review.
  • High risk indicates stronger connections to identified high-risk entities, services, or transaction patterns.

The score should not be interpreted in isolation.

You should also review:

  • which categories were detected;
  • whether exposure is direct or indirect;
  • which asset was transferred;
  • the amount involved;
  • the percentage of activity involved;
  • the timing of the activity;
  • how frequently the pattern appears;
  • whether an identified entity is involved;
  • the context of the current transaction.

Learn how to understand a crypto wallet risk score

Risk Score and Risk Categories Are Different

The overall risk score provides a summary.

The detected categories explain why the score was assigned.

Two TON wallets may have the same risk level but very different underlying exposure.

For example:

  • one wallet may have limited indirect exposure to a mixer;
  • another may have direct exposure to stolen funds;
  • another may repeatedly interact with a high-risk service;
  • another may receive assets from a scam-related cluster;
  • another may have suspicious P2P activity.

The same score should not always lead to the same decision.

The detected categories, messages, contracts, and transaction paths often provide more useful context than the headline score alone.

Sanctions Exposure on TON

A TON wallet may be associated with a person, organization, service, or cluster included in a sanctions list.

Sanctions-related exposure may be:

  • direct;
  • indirect;
  • historical;
  • recent;
  • limited;
  • substantial.

A sanctions connection does not always have the same meaning in every jurisdiction.

Businesses should consider:

  • applicable legal obligations;
  • internal compliance policies;
  • the transaction context;
  • the specific sanctions information detected;
  • the asset involved;
  • whether exposure is direct or indirect.

A sanctions-related match may require escalation or enhanced review.

Stolen Funds and Scam Exposure

A TON wallet may receive assets associated with:

  • compromised wallets;
  • phishing attacks;
  • fraudulent investment schemes;
  • fake trading services;
  • impersonation scams;
  • malicious Mini Apps or bots;
  • unauthorized withdrawals;
  • stolen payment funds;
  • other fraudulent activity.

A wallet may receive stolen assets directly or indirectly through several wallets or smart contracts.

Direct receipt of recently stolen assets may require greater scrutiny than a distant historical connection.

However, exposure alone does not automatically prove who committed the original theft or fraud.

Review:

  • the complete transaction and message route;
  • the amount;
  • the asset involved;
  • the timing;
  • the counterparty;
  • the explanation for the transaction.

Mixer and Obfuscation Exposure

Some users may interact with services or transaction patterns intended to make tracing more difficult.

Obfuscation exposure can increase analytical uncertainty.

However, this exposure alone does not automatically prove criminal activity.

Its significance depends on:

  • whether the exposure is direct or indirect;
  • the amount;
  • the timing;
  • the frequency;
  • other detected categories;
  • the complete transaction context.

A single distant indirect connection may require a different response from repeated direct interaction.

High-Risk Exchanges and Services

A TON wallet may interact with:

  • centralized exchanges;
  • decentralized applications;
  • payment processors;
  • custodial services;
  • gambling platforms;
  • OTC services;
  • P2P counterparties;
  • Telegram-based applications;
  • unidentified services.

Some services may be classified as high risk because of:

  • weak customer verification;
  • exposure to illicit activity;
  • regulatory concerns;
  • suspicious transaction patterns;
  • use by fraudulent networks;
  • insufficient or unreliable attribution.

Interaction with a high-risk service is an important indicator, but it should still be interpreted in context.

TON and Telegram-Based Transactions

TON is closely connected with the Telegram ecosystem.

Users may encounter TON-based activity through:

  • wallet applications;
  • Mini Apps;
  • bots;
  • digital-asset marketplaces;
  • payments;
  • collectible assets;
  • P2P transfers;
  • services using TON Connect.

Convenient access does not eliminate counterparty or blockchain risk.

A Telegram username, bot interface, or Mini App does not by itself prove that the operator is trustworthy.

Before sending assets, confirm:

  • the recipient;
  • the wallet address;
  • the asset;
  • the network;
  • the payment purpose;
  • the AML result;
  • any required memo or comment.

P2P Activity on TON

P2P transactions may involve counterparties whose identity and source of funds are not fully known.

Before accepting Gram, USDT, or another jetton through a P2P transaction, it may be useful to check the sender’s wallet for exposure to:

  • stolen assets;
  • scams;
  • mixers;
  • sanctioned entities;
  • high-risk services;
  • fraudulent payment schemes;
  • suspicious P2P clusters;
  • other high-risk activity.

A wallet check does not replace:

  • identity verification;
  • proof of payment;
  • source-of-funds review;
  • full due diligence.

It adds blockchain context to support a more informed decision.

Does a Low-Risk TON Wallet Guarantee Safe Funds?

No.

A low-risk result means that no significant high-risk exposure was identified based on the data available at the time of the check.

It does not guarantee that:

  • the counterparty is trustworthy;
  • the transaction is legitimate;
  • the assets were obtained legally;
  • every relevant account or contract has been identified;
  • the wallet will remain low risk;
  • an exchange will accept the assets;
  • another analytics provider will reach the same result.

Blockchain intelligence may change when:

  • new wallet clusters are identified;
  • stolen assets are traced;
  • scam reports are confirmed;
  • sanctions lists are updated;
  • law-enforcement information becomes public;
  • historical accounts or contracts receive new attribution.

For important transactions, it may be useful to save the report and repeat the check later.

Can a TON Transaction Be Reversed?

Confirmed TON transfers generally cannot be reversed through the blockchain protocol.

If assets are sent to:

  • the wrong address;
  • a scammer;
  • a compromised wallet;
  • a high-risk counterparty;
  • an unsupported service;
  • a service without the required memo;

there may be no simple way to recover or credit them.

That is why checking the wallet and payment instructions before sending assets is usually more useful than investigating only after a problem occurs.

Checking a TON Wallet for OTC Transactions

OTC transactions may involve large values and complex settlement arrangements.

Before completing an OTC transaction, it may be useful to:

  1. verify the counterparty;
  2. confirm the TON address;
  3. confirm whether the asset is Gram, USDT, or another jetton;
  4. confirm any required memo or identifier;
  5. perform an AML wallet check;
  6. review the risk score and categories;
  7. analyze the transaction and message path;
  8. request source-of-funds information if needed;
  9. document the final decision;
  10. save the report.

The exact procedure depends on the transaction value, jurisdiction, counterparty profile, and applicable compliance obligations.

TON Wallet Checks for Businesses

Businesses that accept, send, or process TON-based assets may use wallet screening as part of a risk-based AML process.

A possible workflow includes:

  1. collecting the customer or counterparty address;
  2. confirming the TON network;
  3. confirming the asset;
  4. confirming any required payment identifier;
  5. performing the AML check;
  6. reviewing the overall risk score;
  7. reviewing the detected categories;
  8. escalating medium- or high-risk results;
  9. requesting additional information when necessary;
  10. documenting the final decision;
  11. repeating the check when the wallet is used again.

The appropriate response depends on:

  • the business model;
  • transaction value;
  • customer profile;
  • jurisdiction;
  • applicable regulation;
  • internal risk appetite;
  • the asset involved;
  • the detected risk category.

Wallet screening should be treated as one component of a broader compliance process.

What to Do If a TON Wallet Has High Risk

A high-risk result should not be ignored.

Possible next steps include:

  • reviewing the detected categories;
  • checking whether exposure is direct or indirect;
  • confirming which asset is involved;
  • reviewing the amount and percentage involved;
  • analyzing related messages and transaction paths;
  • identifying the relevant entity, contract, or service;
  • requesting an explanation from the counterparty;
  • requesting source-of-funds documentation;
  • checking the specific transaction;
  • escalating the case to compliance;
  • delaying or rejecting the transaction where appropriate;
  • documenting the final decision.

The appropriate response depends on the transaction context and applicable obligations.

The score alone should not be treated as automatic proof of illegal activity.

Example: Low-Risk TON Wallet

Imagine a TON wallet that mainly interacts with identified exchanges and ordinary services and has no significant exposure to high-risk categories.

The report may show:

  • a low overall risk score;
  • no sanctions exposure;
  • no direct stolen-funds exposure;
  • ordinary Gram and jetton activity;
  • limited unidentified counterparties.

This result may support proceeding with the transaction, but the address, asset, memo, and counterparty should still be confirmed.

Example: Medium-Risk TON Wallet

Imagine a wallet with mostly ordinary activity but some indirect exposure to a high-risk service through several intermediary contracts or accounts.

The report may show:

  • a medium overall risk score;
  • indirect exposure;
  • a limited amount involved;
  • no direct sanctions exposure;
  • an older message and transaction path.

This result may require additional review rather than automatic rejection.

The amount, timing, asset, transaction purpose, and explanation from the counterparty should be considered.

Example: High-Risk TON Wallet

Imagine a wallet that recently received a substantial amount directly from an identified cluster associated with stolen assets or fraud.

The report may show:

  • a high overall risk score;
  • direct stolen-funds or scam exposure;
  • recent activity;
  • a significant percentage of wallet activity involved;
  • an identified high-risk counterparty.

This result may require escalation, additional documents, or a decision not to proceed, depending on the applicable compliance process.

Do You Need to Connect Your TON Wallet?

No.

A public TON address can be analyzed without connecting the wallet.

You do not need to provide:

  • a private key;
  • a seed phrase;
  • a wallet password;
  • access to the wallet application;
  • authorization through TON Connect.

Never share private credentials with an AML screening service or counterparty.

The public address is sufficient for blockchain risk analysis.

TON Wallet Check vs General Crypto Wallet Check

A TON-specific guide focuses on the addresses, assets, jettons, smart contracts, messages, and transactions of The Open Network.

A general crypto wallet AML check explains broader principles that apply across multiple blockchains.

These include:

  • risk scores;
  • risk categories;
  • direct and indirect exposure;
  • sanctions screening;
  • transaction context;
  • wallet and transaction checks;
  • business compliance workflows.

Learn how to perform a general AML check on a crypto wallet

AML Wallet Check Guides

Use the relevant guide for the wallet or network you want to analyze:

All planned network-specific AML wallet guides are now available.

Check a TON Wallet Before Sending or Accepting Assets

TON wallet risk is not visible from the address alone.

An AML check can help identify exposure to sanctions, scams, stolen funds, mixers, high-risk services, suspicious P2P activity, and other risky connections.

Review the risk score together with the detected categories, message and transaction paths, assets, amounts, timing, entity information, and counterparty context.

Check a TON wallet now

Frequently Asked Questions

Is Gram the same as Toncoin?

Yes.

Gram is the current official name of the native cryptocurrency previously known as Toncoin.

The blockchain itself continues to be called The Open Network, or TON.

Can I check any TON wallet?

You can check a valid public TON address supported by the service.

You do not need the private key or seed phrase.

Does a TON address always begin with EQ or UQ?

No.

EQ and UQ are common prefixes for user-friendly Mainnet address representations.

The same underlying account may also be represented in another valid format.

What is the difference between an EQ and UQ address?

An EQ address is normally represented as bounceable, while a UQ address is represented as non-bounceable.

Both can refer to the same underlying account.

Can the same TON wallet receive Gram and USDT?

A TON owner address can hold Gram and control the jetton wallet contracts used for USDT and other jettons.

Gram and USDT remain separate assets.

Is USDT on TON the same as USDT TRC20?

No.

USDT on TON is implemented on The Open Network.

USDT TRC20 is issued on the TRON blockchain.

Always confirm the correct network before transferring assets.

What is a jetton?

A jetton is a fungible token on TON.

Jettons serve a role similar to ERC-20 tokens on Ethereum and can represent stablecoins, payment tokens, utility tokens, and other assets.

Is a low-risk TON wallet automatically safe?

No.

Low risk only means that no significant high-risk exposure was detected in the available data at the time of the check.

Does indirect exposure prove illegal activity?

No.

Indirect exposure is a risk indicator. It does not prove that the wallet owner knowingly interacted with the final high-risk entity or controls every account in the transaction path.

Can a TON wallet risk score change?

Yes.

The score may change because of new transactions, new entity attribution, sanctions updates, scam reports, law-enforcement information, or newly traced stolen assets.

Can an AML report guarantee that an exchange will accept my assets?

No.

Each exchange, payment provider, and financial institution uses its own compliance policies, data sources, and risk thresholds.

Should I check the wallet or the transaction?

They provide different information.

A wallet check reviews broader account history, while a transaction check focuses on a particular on-chain operation.

Because TON is message-based, related messages and transactions may also need to be reviewed.

Do I need to include a memo or comment?

It depends on the recipient.

Some exchanges, custodial services, merchants, or payment processors require a specific memo, comment, or payment identifier.

Always follow the destination service’s instructions exactly.

Should I check the wallet before or after receiving funds?

Whenever possible, check it before completing the transaction.

A post-transaction check may still help investigate the origin or destination of the assets and document a compliance decision.


AML Verifier provides blockchain risk information for screening, compliance, and research purposes. Results do not guarantee that a TON wallet is safe or unsafe and should not be treated as legal or financial advice. Decisions should consider the full transaction context and, where appropriate, be reviewed by a qualified compliance professional.