Scammers are disguising wallet-draining schemes as cryptocurrency anti-money laundering services, according to a new warning from cybersecurity firm Malwarebytes.
In a report published Wednesday, Malwarebytes said fraudulent websites are posing as services designed to determine whether a crypto wallet has interacted with stolen funds, scams, hacks or sanctioned entities.
Some of the websites imitate the legitimate AML service AMLBot, while others operate under generic names such as “AML Check.”
The scam takes advantage of a legitimate concern among crypto users: whether their wallet's transaction history could be connected to suspicious funds. However, a genuine basic AML check only requires a public wallet address. Users normally do not need to connect their wallet, approve permissions or sign transactions.
Scammers Fake the Entire AML Check
The fraudulent websites instead instruct visitors to connect their crypto wallets before beginning the supposed compliance scan.
Once connected, the sites display fake progress screens designed to make the process appear legitimate. Some then generate fabricated risk assessments regardless of whether an actual blockchain analysis has taken place.
Malwarebytes found one service that requested a small top-up supposedly needed to cover the AML-checking fee before eventually returning a “Clean, Low Risk” result.
Malwarebytes also discovered similar websites operating under different brands and logos but using essentially the same interface and workflow, suggesting scammers are repeatedly rebranding the same template.
Connecting a Wallet Can Set Up the Attack
Simply connecting a cryptocurrency wallet does not automatically give attackers permission to steal its funds.
However, doing so exposes the wallet's public address to the website. Attackers can then inspect the assets held by that address and potentially prepare malicious transactions or token approvals for the victim to sign.
The critical moment comes when users approve those requests without understanding what they authorize.
A malicious approval could potentially provide access to tokens, while signing an attacker-prepared transaction could put assets directly at risk.
The scam therefore relies heavily on social engineering rather than exploiting a technical vulnerability in the wallet itself. By presenting the request as part of a routine compliance procedure, attackers hope users will approve actions they would normally reject.
Crypto Phishing Campaigns Continue to Grow
The fake AML services are the latest example of phishing websites targeting cryptocurrency holders through trusted brands and familiar services.
Earlier this month, hardware wallet companies Trezor and Foundation warned users about phishing emails directing victims toward a cloned Coldcard website.
In March, Malwarebytes uncovered a fraudulent version of Pudgy Penguins' Pudgy World game designed to steal wallet credentials.
Crypto exchange CoinDCX also previously reported identifying more than 1,200 websites impersonating its platform between April 2024 and January 2026.
The campaigns differ in appearance, but the strategy remains similar: attackers create convincing copies of services that users already recognize and then attempt to steal credentials, obtain dangerous permissions or convince victims to sign malicious transactions.
What Users Should Do After a Suspicious AML Check
Malwarebytes recommends that anyone who has granted suspicious token access revoke those permissions as quickly as possible.
The situation becomes substantially more serious if a user has entered a wallet recovery phrase or private key into one of the fraudulent websites. In that case, the wallet should be considered compromised and the assets should be transferred to a newly created secure wallet.
Users should also remember that a standard AML check can generally be performed using only a public blockchain address, without giving the service control over the wallet.
Because confirmed blockchain transactions are generally irreversible, recognizing suspicious requests before approving them remains critical.



