The 10-Second Casino Test That Review Sites Won't Show You

A ten-second MetaMask check flagged a casino that passed every review portal. Here's the test - and three more that take five minutes.

MetaMask phishing-protection warning shown for www.retrobet.com
MetaMask’s phishing-protection warning appeared within seconds of loading www.retrobet.com, citing listings on the SEAL, ChainPatrol, and MetaMask blocklists.

We were vetting a casino for a potential partnership. Ten seconds later, our browser looked like this.

We had typed www.retrobet.com into a browser that happened to have the MetaMask extension installed. Instead of a homepage, we got a full-screen warning: “This website might be harmful.” Underneath, the reason: the site is listed on the blocklists of SEAL, ChainPatrol, or MetaMask. The screenshot above is not a mockup. It’s what came back before we’d read a single word of the site’s actual content.

That’s the test. It takes ten seconds, it costs nothing, and — as far as we can tell — almost nobody runs it before signing an affiliate deal or making a deposit.

The Case of RetroBet

On paper, RetroBet looked fine. Launched in 2024, operated by Stable Tech N.V. under a Curaçao GCB license (OGL/2024/161/0191), the site lists 4,000+ games from roughly 150 providers, accepts 9 cryptocurrencies, and runs a daily cashback program of 3–15% with 5x wagering. Standard due diligence through the usual review channels didn’t raise many flags. Casino.org reported “no widespread issues affecting payouts or fairness.” Worstcasino.com found “no flagged entries” on the blacklists it tracks. AskGamblers showed mostly positive player reviews. The one warning worstcasino.com did surface was buried in the terms: the weekly withdrawal limit of €3,000 drops to €1,000 if weekly turnover falls below €5,000 — a clause that quietly punishes casual players for not betting enough.

That was the picture from the review layer. Then we ran the browser test, and the picture changed.

The MetaMask warning wasn’t a one-off glitch. It’s a signal drawn from third-party security lists — SEAL, ChainPatrol, and MetaMask’s own — none of which have any commercial relationship with RetroBet. So we went to check the one other source that also has no commercial relationship with the casino: the players themselves.

On Trustpilot, where RetroBet has around 405 reviews and the casino replies officially to complaints, the pattern was hard to miss. Multiple players describe withdrawal requests being rejected without explanation — “all my withdrawal requests get rejected without any reason,” as one review put it. Others describe what reads as proof-of-deposit friction used as a stalling tactic: “they do anything they can to deny it.” One player reported winning AUD $900 before what they described as a scam experience; another had a $500 withdrawal sit as “transaction pending” before being declined outright. One reviewer summed up the pattern in blunter terms, calling it a “typical DAMA scam site.” Scattered between these accounts are five-star reviews that read as strikingly generic — the kind of uniform praise that tends to show up when a casino is managing its own review page as much as it is managing its games.

Two independent layers — a security blocklist and player testimony — pointed the same direction. Neither showed up in the standard review-portal check. And as we kept digging, a third layer emerged: the operator’s own corporate history.

Why Review Sites Don’t Show You This

The reason isn’t complicated, and it isn’t a conspiracy: most review portals earn commissions from the casinos they rate. That’s not automatically disqualifying — we run an affiliate model too, and we disclose it on our independence disclosure page — but it does mean a portal’s incentive is to keep a casino listed, not to flag it. A wallet blocklist has no such incentive. Neither does a player who just had a withdrawal declined for the third time. That’s the whole difference: SEAL, ChainPatrol, and MetaMask don’t get paid by the casinos they list. Trustpilot reviewers aren’t paid either — including, notably, the ones giving five stars. The asymmetry in who has skin in the game is exactly why we weight unpaid sources more heavily than paid ones in our own methodology, and why a ten-second browser check outperformed a full review-portal pass on this casino.

The 10-Second Test — and three more that take five minutes

  1. Run the wallet test. This check only works if a wallet extension is actually installed in your browser — the warning comes from the extension, not from the website or the browser itself. If you don’t have one, install MetaMask first (free, from metamask.io, available for Chrome, Brave, Firefox and Edge; you don’t need to create a wallet or hold any crypto for the phishing protection to work). Then open the casino’s domain. If the extension flags the site as listed on the blocklists of SEAL, ChainPatrol, or MetaMask, stop there. Ten seconds, no research skills required. One important caveat: visiting a casino site without a wallet extension installed and seeing no warning proves nothing — no extension, no check.
  2. Read Trustpilot directly — not just casino-focused portals. Look for patterns, not isolated complaints. Repeated “withdrawal rejected” reports are signal one. A cluster of oddly generic five-star reviews sitting next to them is signal two — it usually means the review page is being managed, not just used.
  3. Check the licensing history. Has the operator recently switched licenses or renamed the company? HashLucky moved from a PAGCOR offshore license to an Anjouan license — the weakest tier available — after the Philippines banned POGOs in late 2024. RetroBet’s operator, Stable Tech N.V., is a renamed Dama N.V., rebranded during the 2024 Curaçao licensing reform. A rename by itself proves nothing; a rename that coincides with a regulatory crackdown is worth a second look.
  4. Check the operator’s sister brands. A single casino’s complaint history can be an outlier. A pattern repeated across an operator’s whole portfolio is not. Rabidi N.V.’s NovaJackpot has a documented case in which the same withdrawal request was held for three days and cancelled on the fourth — twelve times in a row — against a €500 daily limit, and the same complaint pattern turns up across other Rabidi-branded casinos, not just that one.

None of these four checks require an account, a deposit, or specialist knowledge. Combined, they take under ten minutes and they caught what a full review-portal pass missed.

What This Means

Stable Tech N.V. is the renamed Dama N.V. — one of the larger multi-brand operators licensed out of Curaçao, running brands that include N1 Bet, King Billy, Playamo, and CoinSlotty, among roughly 13 active labels. The rename landed during the same 2024 licensing reform that pushed other operators to reshuffle their paperwork. Whatever the reasoning behind it, players evidently still recognize the old handwriting — that’s what “typical DAMA scam site” was doing in a Trustpilot review of a casino operating under a different corporate name.

This casino would have paid us commissions. The test decided it never will.

Run the same four checks — the wallet test, the Trustpilot read, the license history, the sister-brand check — on any casino before you send it money or send it players. It takes less time than reading this article did. For the casinos we’ve put through our own provably-fair testing, see our audit reports.