Cybercriminals are operating fake cryptocurrency wallet-checking websites that masquerade as anti-money laundering (AML) compliance tools to drain victims' digital assets. The scam sites impersonate legitimate services such as AMLBot, copying their logos, layouts, and professional appearance to deceive users seeking to verify whether their wallets have links to suspicious activity. Unlike authentic AML checkers that only require a public wallet address for lookup, these fraudulent sites prompt users to connect their wallets directly.
The attack unfolds in multiple stages designed to exploit users' security awareness. After victims connect their wallets, the malicious sites gain access to public addresses and can view associated assets. The scammers then generate tailored transactions sent to victims' wallets for approval. Some variants display fake progress bars with messages like "Checking wallet history" and "Verifying compliance" before showing fabricated errors claiming a small fee is needed to complete the check. The process concludes with a false "Clean, Low Risk" result and downloadable report, regardless of whether any genuine verification occurred.
The technical mechanism relies on wallet connection permissions and transaction approval rather than direct theft. Simply connecting a wallet reveals the public address but does not automatically grant access to funds. However, when victims approve the subsequent transaction requests, thinking they are part of a legitimate security check, they unknowingly authorize the transfer of their cryptocurrency to scammer-controlled addresses. The same scam template appears across multiple domains with different branding, indicating organized distribution of this attack method.
Users who have interacted with these sites face varying levels of risk depending on their actions. Those who only connected wallets should immediately disconnect the suspicious site. Victims who approved token access must check and revoke unrecognized permissions through their wallet's approval checker. Anyone who confirmed transactions, signed unknown requests, or entered recovery phrases should treat their wallets as compromised and immediately transfer remaining assets to new wallets with fresh recovery phrases.
Security professionals recommend several protective measures for cryptocurrency users. Legitimate AML checks require only public wallet addresses and never request wallet connections, transaction approvals, fee payments, or private key disclosure. Users should carefully verify website addresses before interacting with any wallet-checking service, particularly when arriving through advertisements, social media, or search results. Organizations can deploy browser security extensions that block known phishing and scam domains. Given that cryptocurrency transactions cannot be reversed once confirmed, rapid response to suspicious approvals remains critical for asset protection.
Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet


