Fake AML websites steal crypto assets by luring users to connect their wallets.

icon MarsBit
Share
AI summary iconSummary
Crypto compliance tools are under threat as fake AML websites deceive users into connecting their wallets and signing malicious transactions, according to Malwarebytes. These scams imitate services like AMLBot, using fake progress bars and claims of being “FATF-regulated” to appear legitimate. Users are prompted to pay a “verification fee” and later see a “Clean, Low Risk” result—only to lose their funds months later. Genuine AML checks require only a public address, not wallet access. Malwarebytes warns that any AML tool demanding wallet connectivity is a red flag. Recent developments in real-world assets (RWA) underscore the growing need for secure crypto compliance practices.

Article by ZeroTime Technology

Foreword

Have you ever encountered this situation: you wanted to check if your wallet address has any "black history," found an "AML checker" with a professional-looking interface featuring a progress bar, compliance verification badges, and even the words "FATF regulated"? You connected your wallet, clicked scan, and the system prompted you to pay a "verification fee." You did so, then saw the green "Clean, Low Risk" result and breathed a sigh of relief.

Months later, you discover that the assets in your wallet have been reduced to zero.

This is not alarmist. On August 19, 2026, cybersecurity firm Malwarebytes revealed that numerous counterfeit anti-money laundering (AML) verification websites are actively operating, tricking users into connecting their wallets and signing malicious transactions that directly drain their account assets. Some sites impersonate the brand of well-known compliance services like AMLBot, while others use generic names such as “AML Check”—but all are essentially the same malicious template repackaged repeatedly.

AML

The real irony is: you thought you were performing a security and compliance check, but you ended up handing your wallet over to the hacker.

Part 01 - Compliance anxiety is being weaponized

Scammers exploit your anxiety about regulatory compliance by disguising fraud as a "security check."

Anti-Money Laundering (AML) screening is no longer a foreign concept in the cryptocurrency space. Exchanges, custodians, and DeFi platforms commonly use it to identify whether wallet addresses are linked to hacks, thefts, sanctions, or other suspicious activities. As compliance tools become more widely known among everyday users, scammers are seizing new opportunities.

The sophistication of this type of scam lies in three psychological tactics:

1. Create compliance anxiety

Scammers make you believe that "not checking might be non-compliant." Under the DAC8 directive and the MiCA compliance wave, users have developed a conditioned response to comply with "compliance checks." Fraudulent websites exploit this mindset, making you think, "This must be a normal process."

2. Impersonating security tools

A tool that claims to “check if your money is legitimate” sounds far more trustworthy than “high-yield investments.” “When people use AML checkers, their intention is to protect themselves. Scammers exploit this cautious mindset by framing every step as a routine security check,” wrote researchers at Malwarebytes.

3. Simulate real-world processes

A progress bar, compliance verification messages, and forged error prompts requesting small deposits, culminating in a reassuring "Clean, Low Risk" conclusion. The entire process appears highly professional, making it difficult for average users to detect immediately.

AML

AML

The images above show the legitimate and fraudulent AMLBot websites, both tricking users into "connecting their wallet" for a so-called "security check." Legitimate AML screening only requires entering a public wallet address—any tool requesting you to "connect your wallet" should be treated with extreme caution.

Part 02 - The Key Differences Between Genuine and Fake AML Checks

Real requests only need your public address; fake ones demand you “connect your wallet.”

Cryptocurrency AML screening is essentially a read-only query: it checks on-chain transaction records using a wallet address to determine if there are any connections to sanctioned addresses, hacking incidents, or fraudulent funds. This operation requires only the public receiving address; no wallet connection, authorization, signature, or fees are needed.

Fake websites are the opposite.

Malwarebytes researchers explicitly state: "If an AML checker asks you to connect your wallet rather than simply entering its public address, treat it as a warning sign."

The key differences are clear at a glance:

AML

Connecting your wallet does not expose your private key, but it does reveal the assets in your wallet. Attackers can use this information to construct a transaction and send it to you, waiting for you to click approve. Once you click "approve," the attacker gains permission to transfer the corresponding tokens from your wallet, and your assets are immediately drained.

Part 03 - The Five-Step Trap of Fake AML Websites

It’s not when you connect your wallet that something goes wrong—it’s after you click “Approve” that your funds are transferred.

One of the attack sequences recorded by Malwarebytes is as follows:

Step 1: Induce connection

The user visits a fake website and sees a prompt saying "Select a cryptocurrency and scan," with a request to "Connect your wallet to view results." The interface appears identical to the real one.

Step 2: Simulate Scan

The progress bar displays "Checking wallet history..." and "Verifying compliance..." to create the illusion that the system is actively working.

Step 3: Fabricate an error

Display a fake error message requesting a small deposit to "pay a verification fee." This design makes users perceive it as part of the standard process rather than a suspicious action.

Step 4: Return the "Secure" result

Regardless of whether the fee was actually paid, the system will ultimately display a "Secure, Low-Risk" conclusion and offer an option to "Download Report." The victim departs feeling reassured, while the attacker has already gained transfer permissions to the wallet through the approval action.

Step 5: Assets have been cleared

Victims may not discover that their wallet has been emptied for weeks or even months—or worse, they may never know.

The core of the entire process is not connecting the wallet itself, but clicking the “Approve” button after connecting. Malwarebytes notes that what is being approved is “token access permissions”—once signed and authorized, it’s equivalent to giving the other party the keys to your wallet, allowing them to continuously transfer assets without further confirmation.

Part 04 - Three Golden Rules to Protect Your Wallet

Remember three golden rules: don't lower your guard just because the interface looks professional.

Rule One: Never connect your wallet for "checking."

Legitimate AML screening is essentially a read-only query of public data—simply entering a wallet address is sufficient. This is the most basic criterion and the core basis for distinguishing genuine from fraudulent services. Any service that requires you to “connect your wallet” to perform a check, no matter how professional its interface or how realistic its logo, should be closed immediately.

Rule Two: Be wary of requests to pay small fees.

False error messages →诱导 small deposits → demands payment → returns forged "secure" results—this is the standard scam procedure. Genuine AML checks incur no fees. Any "security check" requiring payment is a clear red flag.

Rule Three: Regularly review and revoke approvals.

If you suspect you’ve visited a suspicious website, even without noticing any direct asset loss, check and revoke all unfamiliar authorizations in your wallet’s authorization management interface. This simple step, taking just minutes, could prevent a potential asset drain.

If you have accidentally approved a suspicious transaction, immediately transfer any remaining assets to a brand-new wallet, as the original wallet is no longer considered secure. This is your final line of defense to limit losses.

Core Logic: Attackers exploit not a technical vulnerability, but users’ habitual trust in “compliance checks.” By adhering to three basic rules—never connect your wallet, never pay fees, and regularly review your authorizations—you can avoid the vast majority of these scams.

Conclusion

A fake AML website attack is the latest example of trust being weaponized—scammers no longer promise high returns; instead, they exploit your anxiety about compliance and security to set traps. In your effort to protect yourself, you hand your wallet directly to hackers.

Remember the three golden rules:

• AML checks do not require connecting a wallet—only the public address is needed.

• No fees required

• No approval or authorization required for any transaction

From April 2024 to January 2026, CoinDCX alone identified over 1,200 phishing websites targeting counterfeit platforms. According to CertiK data, the cryptocurrency industry suffered losses of up to $3.3 billion due to malicious attacks throughout 2025.

Compliance anxiety has become a new tool for scammers, and the way to spot it is simple: any AML tool that asks you to “connect your wallet” — shut it down immediately.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.