Policy Regula2026-09-11 09:40:27Fake AML screening sites lure crypto users into wallet approvals that drain fundsA report carried by Foresight and written by Zero Hour Technology warns that a new phishing playbook is exploiting crypto users’ compliance anxiety by posing as anti-money laundering, or AML, screening tools. According to the article, Malwarebytes disclosed on Aug. 19, 2026, that numerous fake AML check sites were actively operating, tricking users into connecting wallets and approving malicious transactions that later emptied their balances. Some pages reportedly impersonated AMLBot, while others used generic branding such as "AML Check," though the report said they were built from the same malicious template. The piece says a legitimate AML screening process is a read-only query that only needs a public wallet address to review on-chain history for links to sanctions, hacks, theft, or suspicious activity. It does not require a wallet connection, a signature, a token approval, or any payment. By contrast, the fake sites simulate a professional workflow with scan progress bars, compliance messages, fake errors, and small "verification fee" prompts before returning a reassuring "Clean, Low Risk" result. The key risk comes after the wallet is connected and the user clicks approve, granting token access that attackers can later use to move funds. The article’s advice is direct: do not connect a wallet for an AML check, do not pay any fee for such a check, and regularly review and revoke unknown token approvals.890
Policy Regula2026-08-20 13:36:19Fake AML check sites impersonate crypto services to trick users into wallet approvalsCybersecurity firm Malwarebytes has identified multiple fake cryptocurrency anti-money laundering, or AML, screening websites that imitate legitimate services such as AMLBot and try to get users to connect their wallets and approve transactions. The company said a real AML screening process only requires a public wallet address and does not require users to connect a wallet, approve permissions, or sign transactions. The fraudulent sites mimic a normal service flow with fake progress bars and fabricated screening results. One of the sites also asks users to deposit a small amount of funds as a supposed screening fee, then shows a result marked “clean, low risk” regardless of whether any actual check has taken place. Malwarebytes said connecting a wallet does not by itself steal funds, but it can expose wallet addresses and asset holdings, giving scammers the information they need to build transactions for users to approve later. Users who have granted suspicious token permissions should revoke them. Anyone who entered a seed phrase or private key should treat the wallet as compromised and move assets to a new wallet, according to the report cited by Decrypt.1760
crypto scams2026-08-20 13:34:04Fake Crypto AML Checkers Try to Trick Users Into Exposing WalletsCybersecurity firm Malwarebytes has warned that scammers are setting up fake anti-money laundering, or AML, checking services aimed at crypto users. The sites claim to assess whether a wallet has touched stolen funds, sanctioned entities, scams, or other suspicious activity, but instead push visitors to connect wallets and approve actions they should never need to authorize for a basic check. Some pages imitate the legitimate service AMLBot, while others use generic branding such as “AML Check.” Malwarebytes said the scam pages often display fabricated progress messages and bogus results to make the process look real, and at least one site asked for a small top-up fee before returning a “Clean, Low Risk” label. The firm stressed that a standard AML wallet screening only requires a public wallet address, not wallet connection, permission approvals, or transaction signatures. Malwarebytes also said the same layout and workflow appeared under multiple names and logos, pointing to a reusable scam kit. The warning comes as crypto phishing campaigns keep surfacing, including cloned sites tied to Coldcard, Pudgy World, and more than 1,200 fake CoinDCX domains identified over a period running from April 2024 to January 2026.510
Malwarebytes2026-08-13 01:41:58Malwarebytes Uncovers $500 Scam Kit That Builds Fake Tesla TSLA Presale SitesMalwarebytes found a cybercrime forum user selling a $500 scam kit that can create fraudulent Tesla $TSLA token presale websites with no technical skills required. The kit fakes personalized invitations by pulling real X avatars and uses countdown timers and price warnings to pressure victims. Depending on the option chosen, victims either hand over their 12-word recovery phrase or send assets to a scam-controlled address, only to see fake balances on a mock dashboard. The panel lets scammers track victims, collect recovery phrases, and check wallet balances before attacking. Malwarebytes spotted the tool on May 16; similar phishing attacks recently hit IRS and Ledger users.1580