BackAMLBot

AMLBot

Policy Regula
2026-08-20 13:36:19

Fake AML check sites impersonate crypto services to trick users into wallet approvals

Cybersecurity firm Malwarebytes has identified multiple fake cryptocurrency anti-money laundering, or AML, screening websites that imitate legitimate services such as AMLBot and try to get users to connect their wallets and approve transactions. The company said a real AML screening process only requires a public wallet address and does not require users to connect a wallet, approve permissions, or sign transactions. The fraudulent sites mimic a normal service flow with fake progress bars and fabricated screening results. One of the sites also asks users to deposit a small amount of funds as a supposed screening fee, then shows a result marked “clean, low risk” regardless of whether any actual check has taken place. Malwarebytes said connecting a wallet does not by itself steal funds, but it can expose wallet addresses and asset holdings, giving scammers the information they need to build transactions for users to approve later. Users who have granted suspicious token permissions should revoke them. Anyone who entered a seed phrase or private key should treat the wallet as compromised and move assets to a new wallet, according to the report cited by Decrypt.

480
Fake AML check sites impersonate crypto services to trick users into wallet approvals
crypto scams
2026-08-20 13:34:04

Fake Crypto AML Checkers Try to Trick Users Into Exposing Wallets

Cybersecurity firm Malwarebytes has warned that scammers are setting up fake anti-money laundering, or AML, checking services aimed at crypto users. The sites claim to assess whether a wallet has touched stolen funds, sanctioned entities, scams, or other suspicious activity, but instead push visitors to connect wallets and approve actions they should never need to authorize for a basic check. Some pages imitate the legitimate service AMLBot, while others use generic branding such as “AML Check.” Malwarebytes said the scam pages often display fabricated progress messages and bogus results to make the process look real, and at least one site asked for a small top-up fee before returning a “Clean, Low Risk” label. The firm stressed that a standard AML wallet screening only requires a public wallet address, not wallet connection, permission approvals, or transaction signatures. Malwarebytes also said the same layout and workflow appeared under multiple names and logos, pointing to a reusable scam kit. The warning comes as crypto phishing campaigns keep surfacing, including cloned sites tied to Coldcard, Pudgy World, and more than 1,200 fake CoinDCX domains identified over a period running from April 2024 to January 2026.

150
Fake Crypto AML Checkers Try to Trick Users Into Exposing Wallets
Polymarket
2026-06-28 21:31:37

Polymarket Users Lose $3.1M PUSD in Front-End Script Attack; Funds Bridged to Ethereum

区块链情报公司 AMLBot 监测显示,Polymarket 用户在 Polygon 网络上因前端恶意脚本入侵,被盗走约 310 万美元 PUSD。攻击者利用 EIP-7702 委托执行诱导用户签署授权,随后将资金转换为 USDC.e 并桥接至以太坊,最终兑换为 ETH 并集中存储。目前约 1891.9 枚 ETH 分布在三个新钱包中。此次攻击手法与 2024 年 1inch 的 Lottie Player 库入侵事件类似,均源于第三方脚本被攻破。事件再次警示去中心化应用前端的安全性薄弱环节,用户需警惕恶意授权签名。

990
Polymarket Users Lose $3.1M PUSD in Front-End Script Attack; Funds Bridged to Ethereum
2026-06-28 21:01:30

Polymarket Users Lose $3.1M in PUSD via Frontend Script Injection Attack, Mirroring 2024 1inch Incident

Blockchain intelligence firm AMLBot has detected a frontend script injection attack on Polymarket users on the Polygon network, resulting in the theft of approximately $3.1 million worth of PUSD. The attackers exploited a compromised third-party script to trick users into signing EIP-7702 delegation transactions, draining their wallets. The stolen funds were converted to USDC.e via Relay, bridged to Ethereum, and consolidated into three new wallets holding about 1,891.9 ETH. The attack shares striking similarities with the 2024 1inch exploit where the Lottie Player library was compromised, highlighting persistent risks in frontend supply chain security.

1030
Polymarket Users Lose $3.1M in PUSD via Frontend Script Injection Attack, Mirroring 2024 1inch Incident
Polymarket
2026-06-28 20:31:31

Polymarket Users Lose ~$3.1M PUSD in Front-End Malicious Script Attack on Polygon

Blockchain intelligence firm AMLBot has detected a malicious script injection attack targeting Polymarket users on the Polygon network, resulting in the theft of approximately $3.1 million in PUSD stablecoins. Attackers embedded malicious code into the platform's front end, tricking users into signing EIP-7702 delegation transactions that emptied their wallets. The stolen funds were converted to USDC.e via Relay, bridged to Ethereum, swapped for ETH, and consolidated into approximately 1,891.9 ETH across three new wallets. AMLBot draws parallels to the 2024 attack on 1inch, where the Lottie Player library was compromised, leading to front-end contamination.

1040
Polymarket Users Lose ~$3.1M PUSD in Front-End Malicious Script Attack on Polygon