Fake AML screening sites lure crypto users into wallet approvals that drain funds

Fake AML screening sites lure crypto users into wallet approvals that drain funds

N
News Editor
2026-09-11 09:40:27
A report carried by Foresight and written by Zero Hour Technology warns that a new phishing playbook is exploiting crypto users’ compliance anxiety by posing as anti-money laundering, or AML, screening tools. According to the article, Malwarebytes disclosed on Aug. 19, 2026, that numerous fake AML check sites were actively operating, tricking users into connecting wallets and approving malicious transactions that later emptied their balances. Some pages reportedly impersonated AMLBot, while others used generic branding such as "AML Check," though the report said they were built from the same malicious template. The piece says a legitimate AML screening process is a read-only query that only needs a public wallet address to review on-chain history for links to sanctions, hacks, theft, or suspicious activity. It does not require a wallet connection, a signature, a token approval, or any payment. By contrast, the fake sites simulate a professional workflow with scan progress bars, compliance messages, fake errors, and small "verification fee" prompts before returning a reassuring "Clean, Low Risk" result. The key risk comes after the wallet is connected and the user clicks approve, granting token access that attackers can later use to move funds. The article’s advice is direct: do not connect a wallet for an AML check, do not pay any fee for such a check, and regularly review and revoke unknown token approvals.

A phishing scheme built around fake anti-money laundering screening pages is tricking crypto users into handing over wallet access under the guise of compliance checks, according to an article published by Foresight and written by Zero Hour Technology.

Fake AML screening sites lure crypto users into wallet approvals that drain funds 2

The article describes websites that present themselves as official-looking AML review tools and push users to enter wallet details or complete what they call an asset verification step. Once a user follows those prompts, the attackers can use the disguised backend flow to siphon funds away.

It says the setup often looks polished. A user searching whether a wallet address has a problematic history may find an "AML checker" with a professional interface, progress bars, compliance badges, and even references to FATF oversight. After the wallet is connected, the site may ask for a small verification fee and then display a green "Clean, Low Risk" result. The user leaves reassured. Months later, the wallet balance may be gone.

Malwarebytes says fake AML sites are actively operating

The article cites Malwarebytes as saying on Aug. 19, 2026, that a large number of fake AML screening websites were active and luring users into connecting wallets and signing malicious transactions that could empty their accounts.

Some of the sites reportedly copied the branding of compliance service AMLBot. Others used generic names such as "AML Check." The article says the sites were essentially the same malicious template wrapped in different branding.

Its core warning is blunt: people thought they were running a security and compliance review, but ended up handing their wallets to hackers themselves.

Fake AML screening sites lure crypto users into wallet approvals that drain funds 3

Compliance anxiety is being turned into bait

The article argues that the scam works because it dresses fraud up as a security procedure. AML screening is already familiar in crypto. Exchanges, custodians, and DeFi platforms use it to check whether wallet addresses are linked to hacks, theft, sanctions, or other suspicious activity. As those tools have become more visible to retail users, scammers have moved in.

It breaks the social engineering behind the scam into three parts. The first is compliance anxiety. Under the DAC8 directive and the broader MiCA compliance push, users have become conditioned to treat compliance checks as normal procedure, the article says. Fake sites exploit that reflex.

The second is the safety disguise. A tool that claims to check whether funds are legitimate sounds far more credible than a high-yield pitch. Malwarebytes researchers wrote, "People use AML checkers with the intention of protecting themselves. Scammers exploit that cautious mindset and package each step so it looks like a normal security check."

The third is process simulation. These pages use progress bars, compliance messages, and fake error prompts that ask for a small top-up before presenting a reassuring "Clean, Low Risk" conclusion. The article says the full sequence can look convincing enough that many users will not spot the trap immediately.

The piece also notes that the image above compares real and fake AMLBot sites that push users to "connect wallet" for a supposed security check. A legitimate AML screening only needs a public wallet address. Any tool that asks for a wallet connection should be treated with extreme caution.

Fake AML screening sites lure crypto users into wallet approvals that drain funds 4

What separates a real AML check from a fake one

The article says a real crypto AML screening is a read-only lookup. It checks on-chain transaction history tied to a wallet address to see whether the address is linked to sanctioned entities, hacks, scams, or other flagged activity. That process only requires a public receiving address. It does not require connecting a wallet, granting approvals, signing messages, or paying a fee.

Fake sites do the opposite. Malwarebytes researchers said, "If an AML checker asks you to connect your wallet rather than simply entering its public address, treat it as a warning sign."

The article adds an important distinction. Connecting a wallet does not by itself hand over a private key, but it does expose wallet asset information. Attackers can use that information to construct a transaction and push it to the user for approval. Once the user clicks approve, the attacker obtains permission to transfer the relevant token and can then drain funds.

The five-step trap described in the report

The article outlines a five-step attack flow recorded by Malwarebytes.

  1. The hook. A user lands on a fake website, sees prompts such as selecting a cryptocurrency and scanning it, and is asked to connect a wallet to view the result. The interface is designed to resemble a real service.
  2. The fake scan. Progress messages appear, including lines such as checking wallet history and verifying compliance, creating the impression that the system is doing real work.
  3. The false error. A fabricated error message appears and asks the user to deposit a small amount to cover a detection fee. The point is to make the payment request look routine.
  4. The reassuring result. Whether or not the fee is actually paid, the page eventually returns a "safe" or "low risk" result and may offer a report download, lowering the victim’s guard.
  5. The drain. After the approval step, the attacker already has token access. The victim may not notice for weeks or even months that the wallet has been emptied.

The article stresses that the real danger is not the moment of wallet connection itself. It comes after the user clicks approve. Malwarebytes said what the victim approves is token access. Once that authorization is signed, the attacker can keep moving assets without asking again.

Fake AML screening sites lure crypto users into wallet approvals that drain funds 5

Three rules the article says users should follow

The first rule is simple: never connect a wallet just to perform a check. The article says a legitimate AML review is a read-only query based on public data, so entering the wallet address is enough. If a service says a wallet must be connected before it can check anything, close it.

The second rule is to be wary of any small fee request. The article describes a common pattern: a fake error, a prompt for a small payment, a detection fee, and then a fabricated safe result. It says a real AML check does not require any payment.

The third rule is to review and revoke approvals regularly. If a user suspects they visited a questionable site, the article says they should inspect the wallet’s approval management page and revoke any unfamiliar permissions even if no direct loss is visible yet. If a suspicious transaction has already been approved, the article advises moving the remaining assets to a brand-new wallet immediately and treating the original wallet as no longer safe.

Two figures cited at the end of the article

The article says that from April 2024 to January 2026, CoinDCX alone identified more than 1,200 phishing websites impersonating platforms. It also cites CertiK data showing that malicious attacks caused $3.3 billion in losses across the crypto sector in 2025.

The closing warning is direct. A real AML check does not require a wallet connection, any fee, or any transaction approval. If an AML tool asks a user to connect a wallet, the article says the safest response is to close it immediately.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.