In brief – Malwarebytes identified fake crypto AML checkers that trick users into connecting their wallets and approving transactions. – The sites impersonate legitimate services such as AMLBot and use fake scans and results to appear legitimate. – A basic AML check only…
quires a public wallet address, not a wallet connection or transaction approval. Scammers are targeting crypto holders with fake anti-money laundering services designed to trick users into approving transactions that could put their digital assets at risk, cybersecurity firm Malwarebytes warned
In a report published Wednesday, Malwarebytes said the sites impersonate services that check whether crypto wallets have interacted with stolen or illicit funds. Some mimic the legitimate service AMLBot, while others use generic names such as “AML Check.” Crypto AML services check a wallet’s public transaction history for links to hacks, scams, sanctioned entities, and other suspicious activity. A basic check only requires a wallet’s public address and does not require users to connect their wallet, approve permissions, or sign a transaction.
According to Malwarebytes, the fake sites prompt users to connect their crypto wallets for an AML check, then simulate the process with fake progress messages and results. One site asked users for a small top-up to cover a supposed fee before returning a “Clean, Low Risk” result, regardless of whether a genuine check occurred. “If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign,” Malwarebytes researchers wrote. Connecting a wallet alone does not allow scammers to steal funds, but it reveals the wallet’s public address, which lets them see its assets and create a transaction for the victim to approve.