A phishing scheme built around fake anti-money laundering screening pages is tricking crypto users into handing over wallet access under the guise of compliance checks, according to an article published by Foresight and written by Zero Hour Technology.

The article describes websites that present themselves as official-looking AML review tools and push users to enter wallet details or complete what they call an asset verification step. Once a user follows those prompts, the attackers can use the disguised backend flow to siphon funds away.
It says the setup often looks polished. A user searching whether a wallet address has a problematic history may find an "AML checker" with a professional interface, progress bars, compliance badges, and even references to FATF oversight. After the wallet is connected, the site may ask for a small verification fee and then display a green "Clean, Low Risk" result. The user leaves reassured. Months later, the wallet balance may be gone.
Malwarebytes says fake AML sites are actively operating
The article cites Malwarebytes as saying on Aug. 19, 2026, that a large number of fake AML screening websites were active and luring users into connecting wallets and signing malicious transactions that could empty their accounts.
Some of the sites reportedly copied the branding of compliance service AMLBot. Others used generic names such as "AML Check." The article says the sites were essentially the same malicious template wrapped in different branding.
Its core warning is blunt: people thought they were running a security and compliance review, but ended up handing their wallets to hackers themselves.

Compliance anxiety is being turned into bait
The article argues that the scam works because it dresses fraud up as a security procedure. AML screening is already familiar in crypto. Exchanges, custodians, and DeFi platforms use it to check whether wallet addresses are linked to hacks, theft, sanctions, or other suspicious activity. As those tools have become more visible to retail users, scammers have moved in.
It breaks the social engineering behind the scam into three parts. The first is compliance anxiety. Under the DAC8 directive and the broader MiCA compliance push, users have become conditioned to treat compliance checks as normal procedure, the article says. Fake sites exploit that reflex.
The second is the safety disguise. A tool that claims to check whether funds are legitimate sounds far more credible than a high-yield pitch. Malwarebytes researchers wrote, "People use AML checkers with the intention of protecting themselves. Scammers exploit that cautious mindset and package each step so it looks like a normal security check."
The third is process simulation. These pages use progress bars, compliance messages, and fake error prompts that ask for a small top-up before presenting a reassuring "Clean, Low Risk" conclusion. The article says the full sequence can look convincing enough that many users will not spot the trap immediately.
The piece also notes that the image above compares real and fake AMLBot sites that push users to "connect wallet" for a supposed security check. A legitimate AML screening only needs a public wallet address. Any tool that asks for a wallet connection should be treated with extreme caution.

What separates a real AML check from a fake one
The article says a real crypto AML screening is a read-only lookup. It checks on-chain transaction history tied to a wallet address to see whether the address is linked to sanctioned entities, hacks, scams, or other flagged activity. That process only requires a public receiving address. It does not require connecting a wallet, granting approvals, signing messages, or paying a fee.
Fake sites do the opposite. Malwarebytes researchers said, "If an AML checker asks you to connect your wallet rather than simply entering its public address, treat it as a warning sign."
The article adds an important distinction. Connecting a wallet does not by itself hand over a private key, but it does expose wallet asset information. Attackers can use that information to construct a transaction and push it to the user for approval. Once the user clicks approve, the attacker obtains permission to transfer the relevant token and can then drain funds.
The five-step trap described in the report
The article outlines a five-step attack flow recorded by Malwarebytes.
- The hook. A user lands on a fake website, sees prompts such as selecting a cryptocurrency and scanning it, and is asked to connect a wallet to view the result. The interface is designed to resemble a real service.
- The fake scan. Progress messages appear, including lines such as checking wallet history and verifying compliance, creating the impression that the system is doing real work.
- The false error. A fabricated error message appears and asks the user to deposit a small amount to cover a detection fee. The point is to make the payment request look routine.
- The reassuring result. Whether or not the fee is actually paid, the page eventually returns a "safe" or "low risk" result and may offer a report download, lowering the victim’s guard.
- The drain. After the approval step, the attacker already has token access. The victim may not notice for weeks or even months that the wallet has been emptied.
The article stresses that the real danger is not the moment of wallet connection itself. It comes after the user clicks approve. Malwarebytes said what the victim approves is token access. Once that authorization is signed, the attacker can keep moving assets without asking again.

Three rules the article says users should follow
The first rule is simple: never connect a wallet just to perform a check. The article says a legitimate AML review is a read-only query based on public data, so entering the wallet address is enough. If a service says a wallet must be connected before it can check anything, close it.
The second rule is to be wary of any small fee request. The article describes a common pattern: a fake error, a prompt for a small payment, a detection fee, and then a fabricated safe result. It says a real AML check does not require any payment.
The third rule is to review and revoke approvals regularly. If a user suspects they visited a questionable site, the article says they should inspect the wallet’s approval management page and revoke any unfamiliar permissions even if no direct loss is visible yet. If a suspicious transaction has already been approved, the article advises moving the remaining assets to a brand-new wallet immediately and treating the original wallet as no longer safe.
Two figures cited at the end of the article
The article says that from April 2024 to January 2026, CoinDCX alone identified more than 1,200 phishing websites impersonating platforms. It also cites CertiK data showing that malicious attacks caused $3.3 billion in losses across the crypto sector in 2025.
The closing warning is direct. A real AML check does not require a wallet connection, any fee, or any transaction approval. If an AML tool asks a user to connect a wallet, the article says the safest response is to close it immediately.


