Fake Crypto “AML Checkers” Drain Wallets

Malwarebytes · Medium sophistication
Last updated August 20, 2026

Scammers are running professional-looking “AML checker” websites that pretend to screen crypto wallets for suspicious activity, but are designed to trick people into connecting their wallet and approving a malicious transaction. Many impersonate a legitimate service (AMLBot) and use fake progress bars, errors, and “Clean, Low Risk” results to look trustworthy. The scam ultimately relies on the victim approving something they didn’t expect or understand.

How the Attack Worked

Scammers built professional looking websites that pose as AML (anti-money laundering) checkers for crypto wallets. Many of these sites copy the branding, layout, and language of AMLBot, a legitimate screening service, to appear trustworthy. Visitors are invited to choose their cryptocurrency, click a Check Wallet button, and connect their wallet to see results. Rather than performing a genuine compliance check, the site is built to get the victim to approve a transaction that the scammers have crafted, which can drain funds once approved.

The Fake Compliance Theater

To make the process feel legitimate, these sites use progress bar animations with messages like Checking wallet history and Verifying compliance. Regardless of what happens during the process, the sites return a reassuring Clean, Low Risk result and often offer a downloadable report. Some variants add a fake error partway through, claiming the wallet needs a small top-up to cover a fee before the check can finish, pressuring the victim into sending crypto or approving further access.

Why It Succeeds

This scam works because it borrows the visual and procedural trust signals of real compliance tools: familiar branding, progress indicators, and official sounding language. Users who are accustomed to legitimate KYC or AML checks may not question a request to connect a wallet, especially when the workflow looks polished. The reassuring Clean, Low Risk outcome regardless of input reduces suspicion at the exact moment users should be most cautious.

What to Watch For

  • A checker site asking you to connect your wallet instead of simply entering a public address
  • Any prompt to approve a transaction you did not expect or do not fully understand
  • A sudden claim that a small fee or top-up is required to finish a check
  • Overly polished progress bars or animations paired with a guaranteed positive result

Building Resistance

Teams that use crypto wallets, including finance, treasury, and payments staff, should treat wallet-connection requests from screening tools as a hard stop. A real basic wallet check only requires a public address, not a connected wallet or a signed transaction. Employees should be trained to never approve a transaction they do not understand, and to know the recovery steps if they do interact with a suspicious site: disconnect the site, revoke token permissions, or move assets to a new wallet if a recovery phrase or private key was ever shared.

Key findings

  • Fake sites impersonate legitimate AML screening services (notably AMLBot) by copying branding, layout, and language.
  • The sites push users to connect their wallet and then approve a transaction crafted by scammers to steal funds.
  • Some variants show a fake “fee/top-up required” error mid-check to pressure users into sending crypto or approving actions.
  • They display fake progress messages (e.g., “Checking wallet history…”, “Verifying compliance…”) and return a reassuring “Clean, Low Risk” outcome regardless of any real checks.
  • Article provides multiple IOC domains linked to the scam.

Who’s being targeted

  • Commonly targeted roles: Finance, Executives, Employees who use crypto wallets, Treasury/Payments teams, General staff security awareness.
  • Affected industries: Cryptocurrency users/investors, Fintech / crypto services, Consumers.
  • Attack channels: website.
  • Impersonated: AMLBot (or a generic “AML Check” service), “AML Check” (rebranded template).

Red flags to watch for

  • The site requires connecting a wallet instead of just entering a public address
  • Pressure to approve an unexpected transaction you “weren’t expecting”
  • A sudden claim that you must pay a small fee/top-up to finish a ‘check’
  • Overly polished ‘security check’ UX (progress bars/results) that doesn’t match normal wallet screening
  • Reassuring result regardless of inputs (“Clean, Low Risk” every time)
  • Downloadable “report” offered by an untrusted site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do fake AML checker sites steal crypto?

They mimic legitimate AML screening services and push victims to connect their wallet, then trick them into approving a transaction crafted by the scammers rather than performing a real check.

What is a red flag that an AML checker site is fake?

If the site asks you to connect your wallet or approve a transaction instead of simply entering a public address, treat that as a warning sign since a basic wallet check only needs the public address.

What should I do if I connected my wallet to a suspicious site?

Disconnect the site from your wallet and revoke any token permissions it may have obtained; if you shared a recovery phrase or private key, treat the wallet as compromised and move assets to a new one.

Why do these fake checkers show a fee or top-up error?

Some variants display a fake error claiming the wallet needs a small top-up to cover a fee, which is a pressure tactic designed to get victims to send funds or approve unauthorized access.

Read the video transcript

You land on an AMLBot look‑alike site that says: “Choose your cryptocurrency, click Check Wallet, and connect your wallet to get your results.” Looks legit, right? But this fake AML checker is built to drain your wallet. The moment you connect, it pushes a transaction you weren’t expecting, then shows a slick progress bar: “Checking wallet history… Verifying compliance…” before flashing a comforting “Clean, Low Risk” result. Here’s the tell: a real basic check only needs your public address. It never needs you to connect your wallet, approve anything, or pay a little 'top‑up fee' after some fake error to finish the scan or download a report. If any 'AML checker' asks you to connect your wallet or approve a transaction, stop right there, close the tab, and don’t approve anything you don’t fully understand.

Similar attacks

Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
Revolut Smishing Uses Fake Identity Check

Revolut Smishing Uses Fake Identity Check

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be…

September 21, 2026
RatHat Smishing Lure Pushes Android Sideloading

RatHat Smishing Lure Pushes Android Sideloading

Researchers described an Android Trojan (“RatHat”) that starts with scam texts or malicious ads and tricks people into installing a fake app from a bogus download page. After installation, it pressures victims to grant Accessibility permissions using fake excuses or incentives, then uses those…

September 18, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Brevo Breach Fuels Crypto Newsletter Phishing

Brevo Breach Fuels Crypto Newsletter Phishing

Attackers abused access to Brevo (an email marketing platform) to send highly convincing phishing emails from legitimate cryptocurrency company domains to newsletter subscribers. The lures claimed urgent security issues (hardware vulnerability or data breach) and pushed victims to click links,…

September 11, 2026