Malwarebytes Warns Fake Crypto AML Checkers Drain Wallets Through Connect-Wallet Prompts
Key Takeaways
- •Genuine ALM wallet screening requires only a public address, so any site asking users to connect a wallet or sign a transaction should be treated as a warning sign.
- •Some fraudulent checkers imitate the legitimate service AMLBot while others use generic names, and one version demands a small fee top-up before displaying a fake 'Clean, Low Risk' result.
- •Approving the targeted transaction sent after a wallet connection is what moves the funds, the same approval mechanism used by commercial drainer kits linked to hundreds of millions of dollars in stolen crypto.
- •Malwarebytes found the same website skeleton operating under different names and logos, indicating the fraud kit is being rebranded and resold.
- •Malwarebytes advises anyone who interacted with a fake checker to disconnect the site, revoke token permissions using tools such as Revoke.cash or Etherscan's token-approval tracker, move exposed funds to a new wallet, and consider any wallet whose recovery phrase was entered as compromised.

Fake anti-money-laundering screening websites are being used to steal from cryptocurrency investors, according to Malwarebytes, which uncovered the attack this week. The fraudulent sites share one tell: they prompt visitors to connect a wallet and sign a transaction — steps that no genuine wallet check ever requires.
Real screening needs only the public address
Under anti-money-laundering rules, banks and regulated firms must verify that their customers have no links to crime. In crypto, that screening takes the form of checking a wallet address’s public transaction history for contact with hacks, thefts, sanctioned parties, or other suspicious activity. Exchanges and banks typically run those checks at scale through blockchain analytics providers such as Chainalysis, Elliptic and TRM Labs, while consumer-facing services like AMLBot offer simplified versions of the same lookup.
The fraudulent sites turn that concept into a weapon, according to Malwarebytes researcher Stefan Dasic. Some copy the branding of AMLBot, a legitimate screening service, while others operate under generic names such as “AML Check.”
A visitor selects a cryptocurrency, clicks to scan it, and is then asked to connect a wallet to see the result. One version examined by Malwarebytes displays a progress bar with messages such as “Checking wallet history…” and “Verifying compliance…” before showing a fake error that requests a small top-up to “cover the fee.” Tapping retry runs the animation again, after which the site returns a soothing “Clean, Low Risk” verdict and an offer to download a report.
A genuine basic screening, by contrast, requires only the wallet’s public address. It is a simple lookup — no signing, no permissions granted, and no wallet connection.
“If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign,” the Malwarebytes team wrote.
Connecting a wallet does not hand over the keys, but it does expose the public address. That allows the operators to see what assets are inside and to build a transaction targeted at that particular wallet, which is then sent to the victim for approval. Approval is the moment the money moves, and researchers advise against confirming an unexpected transaction. That approval mechanic is the same one behind commercial drainer kits, which on-chain investigators have linked to hundreds of millions of dollars in stolen crypto in recent years.
Malwarebytes has discovered the same skeleton being used under different names and logos, a sign that the kit is being rebranded and resold.
A $500 kit phishes recovery phrases behind a 15% bonus
The campaign fits a broader pattern of turnkey crypto fraud tools. This month, Cryptopolitan reported on a $500 kit sold on a cybercrime forum that creates a fake $TSLA presale and scans each visitor’s wallet for valuable assets. The kit then attempts to phish the 12-word recovery phrase by offering a 15% bonus, and its admin panel lets operators inflate fake balances at will so that victims keep paying.
In May, Solana Floor analysts spotted a scheme that flooded Solana wallets with fake “$CJUP” tokens impersonating Jupiter Exchange’s Jupuary airdrop and redirecting recipients to a drainer site, as Cryptopolitan reported at the time.
CoinDCX, for its part, has said it detected more than 1,212 fake websites impersonating its platform between April 2024 and January 2026. Mumbai police have registered an FIR against fraud being perpetrated through a website impersonating CoinDCX.
What to do after interacting with a fake checker
Malwarebytes offered the following advice:
- Anyone who only connected a wallet should disconnect the site.
- Anyone who gave a token permission to access their wallet should check for unfamiliar permissions and revoke them.
- Anyone who signed something they did not understand should review recent activity and, if funds are exposed, move everything to a new wallet.
- Anyone who entered a recovery phrase or private key should assume the wallet is compromised.
For the permission scenario, free tools such as Revoke.cash and Etherscan’s token-approval tracker are widely used to review and undo outstanding token approvals.