Fake AML Sites Trick Crypto Users Into Approving Malicious Transactions

Fake AML Sites Trick Crypto Users Into Approving Malicious Transactions

Researchers warn of fake anti-money laundering (AML) wallet-checking sites that impersonate legitimate services and trick crypto users into approving malicious transactions or token permissions.

Listen to this article

0:00

Press play to start listening

Cybercriminals are using fake crypto wallet-checking sites to target users looking for signs of suspicious activity, according to security firm Malwarebytes. The sites pose as Anti-money laundering (AML) screening services but are designed to trick users into connecting their wallets and approving transactions or permissions that could put their funds at risk.

How the Fake AML Check Works

AML involves screening financial activity to spot ties to crime, scams, sanctioned entities, or other suspicious activity. In crypto, a basic wallet check only needs the wallet’s public address to review its transaction history.

However, Malwarebytes researchers found that malicious operators are building copies of trusted platforms like AMLBot, along with fake checkers using similar names. These fake sites ask visitors to connect their crypto wallets directly.

Connecting a wallet by itself does not give scammers control of the funds. Instead, it reveals the wallet’s public address, which scammers can use to see associated assets and create a transaction specifically for the user. That transaction is then sent to the wallet for approval.

To keep up appearances, the websites display realistic loading screens with messages like “Checking wallet history” and fake fee prompts. One version reviewed by Malwarebytes showed an error claiming the wallet needed a small top-up to cover a fee.

After the user clicked Retry, the site eventually displayed a reassuring “Clean, Low Risk” result and offered a report to download, regardless of whether any genuine check had taken place.

Researchers also found the same basic scam design and process appearing under different names and logos, suggesting that the template is being reused and rebranded.

Steps to Take After Visiting Malicious Sites

Steps to take depend on what happened after interacting with the fraudulent site. Users who only connected their wallet should disconnect the site from their wallet settings, as connecting alone does not permit attackers to move funds.

Those who granted token approvals need to use an approval checker tool to identify unknown permissions and revoke them immediately. If an unexpected transaction was approved, users should review recent wallet activity and move remaining assets if they appear at risk. Anyone who entered a recovery phrase or private key should treat the wallet as compromised and transfer funds to a new wallet created with a new recovery phrase.

Downloaded files should be deleted without opening and followed by a full malware scan. Users who have already lost funds must avoid anyone offering to recover stolen money for a fee, because recovery scams frequently target people who were already cheated.

Security researchers identified several web domains linked to this campaign, including amlbot-clear(.)com, audittrust(.)shop, bitget-aml(.)com, search-aml(.)net, and swapstoken(.)app.

A basic AML check only needs a public wallet address. If a service asks users to connect a wallet, approve token access, sign a transaction, send crypto, or provide a recovery phrase or private key, they should leave the site.

Security Experts React

Security experts who shared their comments with Hackread.com stated that the scam works by exploiting users’ trust in security and compliance services. “Malwarebytes’ findings demonstrate how effectively scammers can weaponize trust,” said Patrick Harr, Chief Executive Officer at DataVisor.

“As AI enables fraudsters to create polished, convincing fake websites in minutes, and rapidly reuse them at scale, financial institutions need real-time, cross-channel intelligence that connects device, behavioral, account, and transaction signals to identify coordinated social-engineering scams and intervene before a customer authorizes an irreversible transfer,” Patrick explained.

Robert Coles, Senior Manager of Threat Intelligence Security at Black Duck, stated that “This isn’t a technology problem — it’s a trust problem. OAuth consent phishing, device code phishing, fake software updates, crypto wallet drainers… they all work the same way: get the victim to click ‘approve’ themselves. No exploit needed if the person hands over the keys voluntarily.”

“That’s what makes these scams so effective, and why they’re getting harder to spot. Before you connect an account, approve a permission, or sign a transaction, take the extra ten seconds to check exactly what you’re agreeing to,” Robert advised.

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts