SARM Source Red Flags: How to Spot a Scam Vendor

A practical red-flags checklist for vetting a SARM vendor: missing COAs, crypto-only checkout, prices that are too cheap, no recent reviews, and exit-scam patterns.

By LegitShops Research

The research-compound market is one of the easiest places online to lose money. There's no insured checkout, no chargeback safety net once you pay the wrong way, and an endless supply of slick storefronts that exist for a few months and then vanish. This guide isn't about whether any compound is safe, legal, or worth taking — that's a separate question, and not one a trust platform should answer for you. It's narrowly about one thing: how to tell whether the vendor you're looking at is a real, accountable business or a scam set up to take your payment and disappear.

Below is the red-flags checklist we use when independent reviewers and our own team vet a storefront. Run any vendor through it before you trust them with a cent.

Why vetting the vendor matters more here than anywhere else

A landmark analysis published in JAMA tested 44 products sold online as SARMs. The results are the single best argument for treating these storefronts with suspicion: only 52% actually contained the SARM listed on the label, 39% contained a different unapproved drug entirely, 25% contained substances not listed at all, 9% contained no active ingredient whatsoever, and 59% had amounts that differed from what the label claimed (JAMA, via CNN).

Read that again: in a coin-flip's worth of cases, the bottle wasn't what the website said it was. That gap is exactly where scam vendors operate. And it isn't a small-money problem — the FTC logged a record $12.5 billion in reported fraud losses in 2024, with consumers losing more to bank-transfer and cryptocurrency payments than all other methods combined (Federal Trade Commission). Those two payment methods are, not coincidentally, the ones scam storefronts push hardest.

You can't out-research a counterfeit by reading the product page. You vet the seller. Here's how.

Red flag 1: No COAs — or COAs you can't actually verify

A Certificate of Analysis (COA) is a third-party lab report showing what's in a batch and at what purity, ideally by HPLC or LC-MS/MS. A legitimate vendor publishes them and ties each one to a batch or lot number you can match against the product you received.

Watch for the fakes-within-fakes:

  • No COAs at all, or vague "lab tested" claims with nothing to click.
  • COAs with no batch number, or a batch number that doesn't match the bottle.
  • The same COA reused across every product and every batch (run a reverse-image search on the report — duplicates show up).
  • A COA from a lab that doesn't exist or won't confirm it issued the document.

"We test our products" is marketing. A downloadable, batch-matched report from a named independent lab is evidence. If a vendor can't produce the second thing, treat the first as worthless. Our COA-verification directory for SARM vendors flags which sources actually publish verifiable certificates versus which just claim to.

Red flag 2: Crypto-only or "friends & family" payment

Paying by crypto, wire, or peer-to-peer apps in "friends and family" mode is the single biggest tell. These are the rails scammers prefer for one reason: they're irreversible. Once the transaction confirms, there is no bank, no card network, and no chargeback to claw your money back.

That's why FTC and FBI data consistently show crypto and bank transfers driving the largest losses with the lowest recovery rates. A vendor that refuses card payments and steers you toward crypto with a "discount" isn't saving you money — they're removing your only path to recourse if the package never arrives.

This alone doesn't prove fraud (some legitimate sellers in restricted verticals avoid card processors for unrelated reasons), but combined with any other flag on this list, it should stop you cold.

Red flag 3: Prices that are too good to be true

Real third-party testing, real sourcing, and real fulfillment cost money. When a vendor lists a month's supply at a fraction of every competitor's price, the cheapest explanation is usually the correct one: the bottle is underdosed, contains a cheaper undeclared substance, or nothing ships at all.

Lowball pricing is bait. It's engineered to short-circuit your judgment before you check the COA or the reviews. If a deal is dramatically cheaper than the established market, raise your suspicion, don't lower it.

Red flag 4: No recent, verifiable reviews

Scam storefronts have a recency problem. They tend to show either:

  • A wall of five-star reviews all posted in a tight window (bought in bulk to launch the site), or
  • Nothing recent — plenty of praise from a year ago, then silence, which often means the vendor has already stopped shipping and is coasting on old reputation while the exit unfolds.

What you want is a steady stream of recent, independent reviews — ideally ones tied to verified proof of purchase, not anonymous testimonials hosted on the vendor's own site (which they fully control and can fabricate). Reviews a company can edit or delete are not evidence. That's the entire reason we built LegitShops as an independent platform: a vendor cannot pay to remove a verified negative review.

Red flag 5: Name changes, fresh domains, and the exit-scam pattern

This is the pattern that catches even experienced buyers. Exit scams are rarely a sudden smash-and-grab — operators farm trust for months, then plan the disappearance. The tells:

  • A storefront with an established-sounding brand but a domain registered only weeks ago.
  • A vendor that abruptly rebranded — same product photos, same descriptions, same support email, new name and new URL. Operators relaunch under fresh branding to shed accumulated complaints. (One well-documented case saw a service pocket user balances and reappear days later at a new domain with the same operators.)
  • Sudden shipping delays, stalled tickets, and "warehouse issues" — the friction phase right before the lights go out.
  • A scramble of new buyers reporting unfulfilled orders all at once.

When you see a brand-new domain wearing an old brand's clothes, assume it's an exit-and-reappear until proven otherwise. Our evidence-linked scam registry tracks vendors with documented disappearances, FDA warning letters, and DOJ actions — check a name against it before you order.

A 60-second vetting checklist

Before you trust any source, run it through this:

  • COA published, batch-matched, and from a named independent lab (not a reused image)
  • A card or other reversible payment option exists — crypto isn't the only choice
  • Pricing is in the normal market range, not suspiciously cheap
  • Recent, independent, proof-backed reviews — not a one-time wall of five stars
  • Domain age matches the brand's claimed history (check a WHOIS lookup)
  • No recent rebrand quietly carrying over the same photos and contact details
  • The name isn't in any scam registry or under a regulator warning

If a vendor fails two or more of these, walk away. The downside of skipping a legitimate seller is mild inconvenience. The downside of trusting a scam one is irreversible.

How to actually run the check

You don't have to do all of this by hand. LegitShops is an independent, un-bribable trust platform — we verify reviews, check COAs, and maintain a public registry of vendors with documented problems. No vendor can pay to change their score or bury a complaint.

For the wider data picture — how often these vendors mislabel, disappear, and rebrand across the restricted-vertical market — see our State of Restricted-Vertical Vendor Trust 2026 report.

The goal here isn't to tell you what to buy. It's to make sure that whatever you decide, you're dealing with a real business that can be held accountable — not a storefront built to take your crypto and vanish.

More from the LegitShops blog