Scammers are targeting crypto holders with fake anti-money laundering screening services that try to trick users into approving actions that could put their digital assets at risk, according to a Wednesday report from cybersecurity firm Malwarebytes.

The firm said the sites pose as services that check whether a wallet has interacted with stolen or illicit funds. Some copy the legitimate AMLBot brand, while others use broad labels such as “AML Check.”
What a real AML wallet check requires
Crypto AML services examine a wallet’s public transaction history for links to hacks, scams, sanctioned entities, and other suspicious activity. Malwarebytes said a basic check only needs a wallet’s public address. It does not require a user to connect a wallet, approve permissions, or sign a transaction.
Instead, the fake sites ask users to connect their wallets for an AML check, then imitate a screening process with fabricated status updates and results. Malwarebytes said one of the sites asked for a small top-up to cover an alleged fee before returning a “Clean, Low Risk” result, regardless of whether any legitimate check had actually taken place.
“If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign,” Malwarebytes researchers wrote.
Why wallet connection still matters
Malwarebytes said connecting a wallet by itself does not let scammers immediately steal funds. It does, however, reveal the wallet’s public address, allowing them to inspect the assets inside and prepare a transaction for the victim to approve.
The company said it found the same underlying design and workflow across several names and logos, suggesting the scam infrastructure is being reused and rebranded.
A broader wave of phishing sites
Malwarebytes noted that experienced crypto users are familiar with these tactics, but said there has recently been a string of phishing campaigns built around fake websites targeting crypto holders.
Earlier this month, hardware wallet makers Trezor and Foundation warned about phishing emails that directed users to a cloned Coldcard website. In March, Malwarebytes uncovered a fake version of Pudgy Penguins’ Pudgy World game that was designed to steal wallet passwords. Also in March, crypto exchange CoinDCX said it had identified more than 1,200 websites impersonating its platform between April 2024 and January 2026.
What users should do next
Malwarebytes advised anyone who approved token access to revoke suspicious permissions. Users who entered a recovery phrase or private key should treat that wallet as compromised and move their assets to a new wallet.
“Crypto transactions generally can’t be reversed once they’re confirmed, so acting quickly matters if you’ve approved something suspicious,” the firm said.

