Scammers Impersonate Crypto AML Checkers to Drain Wallets
Cybercriminals are deploying fake Anti-Money Laundering (AML) checking websites that trick cryptocurrency users into connecting their wallets and approving malicious transactions, leading to asset theft.

Scammers are increasingly targeting cryptocurrency users by creating sophisticated fake websites that impersonate legitimate Anti-Money Laundering (AML) checking services. These fraudulent sites aim to trick unsuspecting individuals into connecting their crypto wallets, ultimately leading to the theft of their digital assets. The scam preys on users' desire to ensure the legitimacy of crypto transactions and wallet addresses.
Legitimate AML checking services typically only require a wallet's public address to analyze its transaction history for links to illicit activities such as hacks, scams, or sanctioned entities. Users do not need to connect their wallets, approve any transactions, or sign anything to receive a basic check. Any service that demands wallet connection or further interaction beyond providing a public address should be considered a significant red flag.
The fake websites often mimic the appearance of well-known services like AMLBot, complete with copied logos, layouts, and language. After prompting users to select their cryptocurrency and click a "Check Wallet" button, they instruct the user to connect their wallet. While simply connecting a wallet may only reveal the public address, it provides scammers with the necessary information to craft a malicious transaction tailored to the victim's wallet.
Once the victim's wallet is connected and their public address is known, the scam website generates a fake transaction. This transaction is then presented to the user for approval, often disguised as a necessary security check, a fee payment, or a part of the AML verification process. The scam's success hinges on the user approving this unexpected transaction without fully understanding its implications.
Some versions of the scam employ deceptive progress bars and messages, such as "Checking wallet history..." and "Verifying compliance..." to create a sense of legitimacy. If a user hesitates or if the initial fake transaction fails, the site might present a fake error message, claiming a small top-up is needed to "cover the fee." Upon "successful" completion, regardless of whether any genuine check occurred, the user is presented with a "Clean, Low Risk" result and an option to download a report, reinforcing the illusion of a completed and successful verification.
The effectiveness of this scam lies in its exploitation of users' existing security consciousness. Individuals seeking to use AML checkers are already in a security-minded mindset, making them more susceptible to steps that appear to be part of a standard security protocol. The fake progress indicators, plausible error messages, and reassuring final results are all designed to lower the user's guard and encourage the approval of the malicious transaction.
If a user has connected their wallet, it is crucial to immediately disconnect the suspicious site from their wallet. If any tokens or permissions were granted, these should be revoked using the wallet provider's approval checker. In cases where a transaction was confirmed or signed without understanding, users should review their recent wallet activity and consider moving remaining funds to a new, secure wallet. If a recovery phrase or private key was compromised, the wallet must be considered entirely compromised, and all assets should be transferred immediately.
To avoid falling victim, users should meticulously verify website addresses, especially when arriving from ads or social media. Be extremely cautious of any AML checker that requests wallet connections, unexpected token access, transaction confirmations, or the sharing of recovery phrases. A legitimate basic wallet screening should only ever require the public wallet address.