XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Learn
● Learn

Fraudulent AML Checkers Lure Crypto Users Into Wallet Compromises

Malwarebytes researchers uncovered a widespread scheme where scammers impersonate legitimate anti-money laundering services to trick cryptocurrency holders into connecting wallets and approving harmful transactions.

JM
by Jacob Marquez · Learn Desk
Published August 20, 2026 · 3 min read

The Scam Mechanics

Cyber threats targeting cryptocurrency holders continue to evolve, with scammers now impersonating legitimate compliance verification services to gain unauthorized access to user wallets. Fraudulent platforms replicate the appearance of genuine AML checkers, including counterfeit versions mimicking AMLBot and generic lookalikes branded as “AML Check.” According to Malwarebytes’ research, these bogus sites exploit how legitimate AML verification actually works—which requires only a wallet’s public address to scan blockchain history for connections to stolen funds, hacks, sanctioned entities, and illicit activity.

The fraudulent versions manipulate users into connecting their entire wallet to the platform. After connection, the scam sites execute fake verification processes with counterfeit progress indicators and fabricated results. Some operators request nominal payments under the guise of processing fees before displaying a “Clean, Low Risk” assessment, regardless of whether any genuine check occurred. Malwarebytes identified the same underlying attack framework duplicated across multiple identities and logos, indicating organized reuse of the scam template.

Why Wallet Connection Creates Risk

While connecting a wallet alone doesn’t grant scammers direct fund access, it exposes the wallet’s public address and asset balance. This intelligence allows attackers to construct customized transactions and present them to the victim for approval—the moment where compromise occurs. Once a user signs off on a blockchain transaction, reversal becomes impossible on most networks, making the approval step critical and time-sensitive.

Legitimate AML services require only public address entry for verification. Any platform requesting wallet connection to perform a basic compliance check signals a warning sign to users evaluating the service’s authenticity.

Widening Impersonation Campaigns Across Crypto

This discovery reflects a broader pattern of phishing and fraud targeting cryptocurrency participants. Earlier this month, hardware wallet makers Trezor and Foundation warned users of phishing emails directing them to fake Coldcard websites. In March, security researchers exposed a counterfeit Pudgy Penguins game created to harvest wallet credentials. Additionally, major exchange CoinDCX identified more than 1,200 fraudulent sites impersonating its platform between April 2024 and January 2026.

Malwarebytes recommends immediate action for affected users: revoke token permissions from any suspicious connections promptly. Those who shared a recovery phrase or private key should consider the wallet completely compromised and transfer assets to a new wallet without delay. The irreversible nature of blockchain transactions underscores the need for swift response when suspicious approvals occur.

Sophisticated impersonation and social engineering schemes like these highlight the critical importance of user education and vigilance as the crypto ecosystem expands.

Source: Malwarebytes, via Decrypt. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Learn Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.