All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to Crypto & Digital Assets

Fake Crypto AML Checkers Target Users to Drain Wallets

Created at 20 Aug · 1:41 PM1 source↑ Market-relevant
IN SHORT

Cybersecurity firm Malwarebytes has identified fake anti-money laundering services impersonating legitimate platforms. These sites trick crypto holders into connecting their wallets and approving transactions, potentially leading to the theft of digital assets.

Key Numbers

1,200+impersonating websites identified by CoinDCX

Who's Involved

Malwarebytes
cybersecurity firm that identified fake crypto AML checkers
AMLBot
legitimate service impersonated by scammers
Fake Crypto AML Checkers Target Users to Drain Wallets

↳ Why This Matters

These fake AML checkers pose a significant risk to crypto holders by exploiting trust in security services to facilitate theft. Users can lose their entire digital asset holdings if they fall victim to these scams.

Key facts

  • Fake crypto AML checker websites have been identified by Malwarebytes.
  • These sites impersonate legitimate services to trick users into connecting their wallets.
  • Users are prompted to approve transactions, which can lead to asset theft.
  • A genuine AML check only requires a public wallet address, not wallet connection.
  • Malwarebytes advises revoking suspicious permissions and moving assets if a wallet is compromised.

Cybersecurity firm Malwarebytes has identified a new scam targeting cryptocurrency holders through fake anti-money laundering (AML) checker websites. These fraudulent sites impersonate legitimate services, such as AMLBot, and use deceptive tactics to trick users into connecting their crypto wallets and approving malicious transactions. The ultimate goal is to drain users' digital assets.

According to Malwarebytes, these fake websites simulate AML checks by displaying fake progress messages and results. Users are often prompted to connect their wallets, a step that, while not immediately compromising, allows scammers to view the wallet's public address and its associated assets. This information is then used to craft transaction requests for the victim to approve. In some instances, scammers have even requested a small top-up fee to supposedly cover a fee before returning a false 'Clean, Low Risk' result.

Researchers emphasize that legitimate AML checks typically only require a wallet's public address and do not necessitate connecting the wallet or signing any transactions. Malwarebytes noted that the same scam template appears to be reused and rebranded under various names and logos. The firm advises users to be wary if an AML checker asks for wallet connection instead of just a public address. If users have approved suspicious token access, they should revoke those permissions. In cases where a recovery phrase or private key has been entered, the wallet should be considered compromised, and all assets should be moved to a new, secure wallet.

Frequently asked questions

Crypto AML services check a wallet's public transaction history for links to illicit activities such as hacks, scams, or sanctioned entities.

They impersonate legitimate services, prompt users to connect their wallets, and simulate checks with fake results, often asking for a small fee before users approve malicious transactions.

If an AML checker asks you to connect your wallet rather than simply enter its public address, it should be treated as a warning sign.

If you entered a recovery phrase or private key, consider the wallet compromised and move your assets to a new wallet immediately. Revoke any suspicious token access.

What Happens Next

01Users should revoke suspicious token access from their wallets.
02Users who entered recovery phrases or private keys should move assets to a new wallet.
CME Headlines
  • Product Modification Summary: Add Offset Eligibility to Bitcoin Futures, Micro Bitcoin Futures, Ether Futures and Micro Ether Futures Contracts — Effective September 14, 2026
    19 Aug · 9:15 PM
  • Amendments to CME Rule 855. (“Offsetting Positions for Different-Sized Contracts”) – Contracts Eligible for Offset Table to Include Bitcoin Futures, Micro Bitcoin Futures, Ether Futures and Micro Ether Futures Contracts
    19 Aug · 7:45 PM

How It Developed

Malwarebytes identified fake crypto AML checker websites.
These sites impersonate legitimate services like AMLBot.
Scammers prompt users to connect wallets and approve transactions.
Fake progress messages and results are used to appear legitimate.
A small top-up fee was requested by one fake service.
Connecting a wallet reveals its public address and allows transaction approval requests.
Malwarebytes advises revoking suspicious token access and moving assets if a wallet is compromised.
Users who entered recovery phrases or private keys should consider their wallet compromised.

Sources

T1
Fake Crypto AML Checkers Are Trying to Drain Users' WalletsDecrypt

Related Stories

Cybersecurity firm Rapid7 uncovers crypto phishing campaign targeting 885,000 phone numbers
20 Aug · 12:41 PM
Binance launches AI trading platform, placing user oversight at its core
20 Aug · 9:46 AM
150+ Polymarket Wallets May Have Traded on US Military Secrets, Research Finds
20 Aug · 10:08 AM
BitGo Korea secures VASP registration for institutional crypto custody
20 Aug · 8:06 AM
Coinbase's Base Bets on AI Agents With $100K Startup Accelerator
19 Aug · 4:36 PM