Fake AML check sites impersonate crypto services to trick users into wallet approvals

Fake AML check sites impersonate crypto services to trick users into wallet approvals

N
News Editor
2026-08-20 13:36:19
Cybersecurity firm Malwarebytes has identified multiple fake cryptocurrency anti-money laundering, or AML, screening websites that imitate legitimate services such as AMLBot and try to get users to connect their wallets and approve transactions. The company said a real AML screening process only requires a public wallet address and does not require users to connect a wallet, approve permissions, or sign transactions. The fraudulent sites mimic a normal service flow with fake progress bars and fabricated screening results. One of the sites also asks users to deposit a small amount of funds as a supposed screening fee, then shows a result marked “clean, low risk” regardless of whether any actual check has taken place. Malwarebytes said connecting a wallet does not by itself steal funds, but it can expose wallet addresses and asset holdings, giving scammers the information they need to build transactions for users to approve later. Users who have granted suspicious token permissions should revoke them. Anyone who entered a seed phrase or private key should treat the wallet as compromised and move assets to a new wallet, according to the report cited by Decrypt.

Malwarebytes has found several fake cryptocurrency anti-money laundering, or AML, screening websites that pose as legitimate services including AMLBot and attempt to trick users into connecting wallets and approving transactions.

Fraudulent sites copy the look of AML screening services

According to Malwarebytes, a normal AML check only requires a public wallet address. It does not require users to connect a wallet, approve permissions, or sign a transaction. These fake sites imitate the service process with fabricated progress prompts and screening results.

One of the websites also asks users to deposit a small amount of funds to pay a supposed screening fee. It then displays a “clean, low risk” result regardless of whether any real screening has been completed.

Wallet connection alone does not directly drain funds

Malwarebytes said connecting a wallet by itself does not directly cause funds to be stolen, but it does expose wallet addresses and asset information. That can help scammers prepare transactions for users to approve later.

The company added that similar scams use the same design and workflow, changing only the name and branding. Users who have already approved suspicious token permissions should revoke them. Anyone who entered a seed phrase or private key should treat the wallet as compromised and move assets to a new wallet. The report was cited by Decrypt.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
480

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.