Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Fake Crypto AML Checkers Target Digital Asset Wallets

Cybersecurity firm Malwarebytes warns that fraudulent anti-money laundering websites are tricking users into connecting their wallets and approving malicious transactions.
1 hour ago 5 views
Fake Crypto AML Checkers Target Digital Asset Wallets

Scammers are targeting cryptocurrency holders with fraudulent anti-money laundering (AML) services designed to trick users into approving transactions that put their digital assets at risk, according to a report published Wednesday by cybersecurity firm Malwarebytes.

The malicious sites impersonate legitimate services that check whether crypto wallets have interacted with stolen or illicit funds. Some websites mimic the legitimate service AMLBot, while others use generic names like “AML Check.”

Legitimate crypto AML services check a wallet's public transaction history for links to hacks, scams, sanctioned entities, and suspicious activity. A standard check requires only a wallet's public address and does not require users to connect their wallet, approve permissions, or sign a transaction.

According to Malwarebytes, the fraudulent sites prompt users to connect their crypto wallets for an AML check and then simulate the process using fake progress messages and results. One analyzed site asked users for a small top-up to cover a supposed fee before displaying a “Clean, Low Risk” result, regardless of whether a genuine check occurred.

Researchers at Malwarebytes noted that the same basic design and process appeared under multiple names and logos, indicating that a single scam template is being reused and rebranded.

How the Attack Works

While connecting a wallet alone does not allow scammers to steal funds, it exposes the wallet's public address, enabling malicious actors to view its assets and craft a transaction for the victim to approve.

Malwarebytes advises users who have approved token access to revoke suspicious permissions immediately. Individuals who have entered a recovery phrase or private key should treat their wallet as compromised and transfer their assets to a new wallet.

“Crypto transactions generally can’t be reversed once they’re confirmed, so acting quickly matters if you’ve approved something suspicious,” researchers stated.

The campaign is part of a broader series of recent phishing efforts targeting digital asset holders. Earlier this month, hardware wallet manufacturers Trezor and Foundation warned users about phishing emails directing them to a cloned Coldcard website. In March, Malwarebytes uncovered a fake version of the Pudgy Penguins Pudgy World game designed to steal wallet passwords, and Indian exchange CoinDCX reported identifying more than 1,200 websites impersonating its platform between April 2024 and January 2026.