Fake Crypto AML Checkers Are Trying to Drain Users’ Wallets
Key Takeaways
- •Fake AML checker websites are impersonating legitimate crypto screening services, including AMLBot, to target wallet holders.
- •Malwarebytes said a genuine AML check requires only a public wallet address and should not ask users to connect a wallet or sign a transaction.
- •Some of the fraudulent sites simulate scans with fake progress messages and may request a small payment before showing a false low-risk result.
- •Granting token approval can allow a smart contract to spend assets in a wallet, which is the key risk behind wallet-drainer scams.
- •Users who approved suspicious access should revoke permissions quickly, and anyone who entered a recovery phrase or private key should treat the wallet as compromised.

Malwarebytes has identified fake crypto AML checkers that trick users into connecting their wallets and approving transactions.
The sites impersonate legitimate services such as AMLBot and use fake scans and results to appear authentic.
A basic AML check only requires a public wallet address, not a wallet connection or transaction approval.
Cybersecurity firm Malwarebytes warned that scammers are targeting crypto holders with fake anti-money laundering services designed to lure users into approving transactions that could put their digital assets at risk.
In a report published Wednesday, Malwarebytes said the sites impersonate services that check whether crypto wallets have interacted with stolen or illicit funds. Some mimic the legitimate service AMLBot, while others use generic names such as “AML Check.”
Crypto AML services examine a wallet’s public transaction history for links to hacks, scams, sanctioned entities, and other suspicious activity. A basic check requires only a wallet’s public address and does not require users to connect their wallet, approve permissions, or sign a transaction. Exchanges and other crypto services run similar screening against sanctions lists and illicit-finance databases, and funds traced to tainted addresses can be flagged or frozen — which is why many users check an address before sending or receiving funds.
According to Malwarebytes, the fake sites prompt users to connect their crypto wallets for an AML check, then simulate the process with fake progress messages and results. One site asked users for a small top-up to cover a supposed fee before returning a “Clean, Low Risk” result, regardless of whether a genuine check had taken place.
“If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign,” Malwarebytes researchers wrote.
Connecting a wallet alone does not allow scammers to steal funds, but it does reveal the wallet’s public address, which lets them see its assets and create a transaction for the victim to approve. That approval step is where the real risk sits: on networks such as Ethereum, signing an approval grants a smart contract permission to spend tokens held in the wallet, commonly with no time limit — the mechanism behind “wallet drainer” phishing schemes in which victims unknowingly authorize transfers that empty their funds.
Malwarebytes found the same basic design and process used under several names and logos, suggesting the scam template is being reused and rebranded.
Seasoned crypto users are no strangers to these kinds of schemes, but recent weeks have brought a series of phishing campaigns using fake websites to target crypto holders.
Earlier this month, hardware wallet makers Trezor and Foundation warned of phishing emails directing users to a cloned Coldcard website. In March, Malwarebytes uncovered a fake version of Pudgy Penguins’ Pudgy World game designed to steal wallet passwords. That same month, crypto exchange CoinDCX said it had identified more than 1,200 websites impersonating its platform between April 2024 and January 2026.
Malwarebytes advised users who approved token access to revoke suspicious permissions, which can be done through token-approval revocation tools that let wallet owners cancel spending permissions they previously granted. Users who entered a recovery phrase or private key should consider the wallet compromised and move their assets to a new wallet.
“Crypto transactions generally can’t be reversed once they’re confirmed, so acting quickly matters if you’ve approved something suspicious,” Malwarebytes said.