Summary
- Malwarebytes has discovered fraudulent crypto anti-money laundering (AML) services that deceive users into linking their wallets and authorizing transactions.
- These sites mimic legitimate platforms like AMLBot and employ fake scans to appear credible.
- An authentic AML check requires only a public wallet address, without the need for wallet connection or transaction approval.
Cybersecurity firm Malwarebytes has issued a warning about scammers targeting cryptocurrency holders through counterfeit anti-money laundering services that trick users into authorizing risky transactions.
In a recent report, Malwarebytes explained that these deceptive websites imitate services that verify whether crypto wallets are linked to stolen or illicit funds. Some of these sites pose as the legitimate service AMLBot, while others use generic identifiers like “AML Check.”
Myriad: What’s next for XRP price? Make your prediction here.Legitimate crypto AML services analyze a wallet's public transaction history for connections to hacks, scams, sanctioned entities, and other dubious activities. A standard AML check only requires the public address of a wallet and does not necessitate connecting the wallet or approving any transactions.
Malwarebytes reported that these fraudulent sites encourage users to link their crypto wallets for an AML verification, then fabricate the process with false progress notifications and results. One site even requested a minor fee for a supposed service before providing a “Clean, Low Risk” result, irrespective of any real checks being conducted.
“If an AML checker requests that you connect your wallet instead of merely entering its public address, consider that a red flag,” the researchers at Malwarebytes cautioned.
While simply connecting a wallet does not enable scammers to steal funds, it does disclose the wallet's public address, allowing them to view its assets and create a transaction that the victim may approve.
Malwarebytes observed that the same fundamental design and methodology were apparent across several names and logos, indicating that this scam template is being repurposed and rebranded.
Experienced crypto users are familiar with such tactics, but there has been a recent surge in phishing campaigns targeting cryptocurrency holders through fake websites.
Earlier this month, hardware wallet manufacturers Trezor and Foundation issued warnings about phishing emails leading users to a counterfeit Coldcard website, while in March, Malwarebytes discovered a fraudulent version of the Pudgy Penguins’ Pudgy World game aimed at stealing wallet passwords. During the same month, crypto exchange CoinDCX reported identifying over 1,200 websites impersonating its platform between April 2024 and January 2026.
Malwarebytes recommends that users who have granted token access to revoke any suspicious permissions. Those who have entered a recovery phrase or private key should consider their wallet compromised and transfer their assets to a new wallet immediately.
“Once crypto transactions are confirmed, they generally cannot be reversed, so it is crucial to act swiftly if you have approved any suspicious activity,” Malwarebytes added.