
Scammers are impersonating crypto AML checkers to trick users into approving wallet-draining transactions. Malwarebytes says the fake sites ask for wallet connections instead of just a public address.
Alpha Score of 72 reflects strong overall profile with strong momentum, moderate value, strong quality, moderate sentiment.
Scammers are impersonating crypto compliance services to trick users into approving transactions that drain their wallets. Cybersecurity firm Malwarebytes detailed the scheme in a report published this week, warning that fake anti-money laundering (AML) checker websites are designed to request wallet connections under the guise of legitimate analysis.
Some of the spoofed sites replicate the aesthetics of AMLBot, a real service that scans blockchain addresses for risk. Others operate under generic names like "AML Check." The mechanism is straightforward, Malwarebytes said. The platforms simulate a verification process with fake progress bars and return results such as "Clean, Low Risk" without performing any real analysis. In some cases, they also ask for a small payment as a supposed fee.
The core issue is that a legitimate AML check only requires entering the wallet's public address. It does not require connecting the wallet or signing any transaction. Connecting the wallet does not let scammers steal funds directly, Malwarebytes said. It does expose the user's asset balances and allows scammers to generate transactions for the victim to approve. Once the user signs a malicious transaction, the attacker can drain the wallet.
Malwarebytes identified the same basic design replicated under different names and logos. The firm said the scam template is systematically reused and rebranded, making it hard for users to spot the pattern. For anyone who has already approved suspicious permissions, Malwarebytes recommends revoking them immediately. If a user entered their recovery phrase or private key on any of these sites, the wallet should be considered fully compromised.
The report comes amid a broader wave of phishing attacks targeting crypto users. A Hyperliquid user recently lost about $550,000 in USDC after clicking a malicious Google search ad that impersonated the trading platform. SafePal disclosed a plugin flaw that exposed personal data of nearly 40,000 customers. The SafePal incident raised fears of physical attacks because the leaked data included shipping addresses.
For users who move between centralized exchanges and self-custody wallets, the safest practice is to never connect a wallet to a site that claims to perform an AML check. Malwarebytes said the only legitimate way to check an address is to paste the public address into a trusted blockchain explorer or a verified compliance service. Any site that asks to connect a wallet or sign a transaction to run a compliance check is a scam.
The firm also urged users to double-check URLs and avoid clicking ads that appear on search engines for terms like "crypto AML check" or "wallet safety scanner." The fake sites often use lookalike domains that differ from the real service by one or two characters. Malwarebytes said the scammers rely on users acting quickly without verifying the request's legitimacy.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.