Fraudulent AML Checkers Lure Crypto Users Into Wallet Compromises
Malwarebytes researchers uncovered a widespread scheme where scammers impersonate legitimate anti-money laundering services to trick cryptocurrency holders into connecting wallets and approving harmful transactions.
The Scam Mechanics
Cyber threats targeting cryptocurrency holders continue to evolve, with scammers now impersonating legitimate compliance verification services to gain unauthorized access to user wallets. Fraudulent platforms replicate the appearance of genuine AML checkers, including counterfeit versions mimicking AMLBot and generic lookalikes branded as “AML Check.” According to Malwarebytes’ research, these bogus sites exploit how legitimate AML verification actually works—which requires only a wallet’s public address to scan blockchain history for connections to stolen funds, hacks, sanctioned entities, and illicit activity.
The fraudulent versions manipulate users into connecting their entire wallet to the platform. After connection, the scam sites execute fake verification processes with counterfeit progress indicators and fabricated results. Some operators request nominal payments under the guise of processing fees before displaying a “Clean, Low Risk” assessment, regardless of whether any genuine check occurred. Malwarebytes identified the same underlying attack framework duplicated across multiple identities and logos, indicating organized reuse of the scam template.
Why Wallet Connection Creates Risk
While connecting a wallet alone doesn’t grant scammers direct fund access, it exposes the wallet’s public address and asset balance. This intelligence allows attackers to construct customized transactions and present them to the victim for approval—the moment where compromise occurs. Once a user signs off on a blockchain transaction, reversal becomes impossible on most networks, making the approval step critical and time-sensitive.
Legitimate AML services require only public address entry for verification. Any platform requesting wallet connection to perform a basic compliance check signals a warning sign to users evaluating the service’s authenticity.
Widening Impersonation Campaigns Across Crypto
This discovery reflects a broader pattern of phishing and fraud targeting cryptocurrency participants. Earlier this month, hardware wallet makers Trezor and Foundation warned users of phishing emails directing them to fake Coldcard websites. In March, security researchers exposed a counterfeit Pudgy Penguins game created to harvest wallet credentials. Additionally, major exchange CoinDCX identified more than 1,200 fraudulent sites impersonating its platform between April 2024 and January 2026.
Malwarebytes recommends immediate action for affected users: revoke token permissions from any suspicious connections promptly. Those who shared a recovery phrase or private key should consider the wallet completely compromised and transfer assets to a new wallet without delay. The irreversible nature of blockchain transactions underscores the need for swift response when suspicious approvals occur.
Sophisticated impersonation and social engineering schemes like these highlight the critical importance of user education and vigilance as the crypto ecosystem expands.
Source: Malwarebytes, via Decrypt. Not financial advice.