Fake AML checkers are tricking crypto users into signing wallet-draining approvals, security researchers warn, by disguising a malicious transaction prompt as a routine compliance or risk scan.
Fake AML checkers are tricking crypto users into signing wallet-draining approvals, security researchers warn, by disguising a malicious transaction prompt as a routine compliance or risk scan.
Fake AML checkers are tricking crypto users into signing wallet-draining approvals, security researchers warn, by disguising a malicious transaction prompt as a routine compliance or risk scan. The tools promise a quick anti-money-laundering lookup, then push victims to connect a wallet and approve a request that hands attackers a path to drain their funds.
The warning comes from Malwarebytes, which documented a wave of counterfeit AML sites that impersonate the compliance brand AMLBot or lean on generic “AML Check” branding to look legitimate, according to the firm’s threat intelligence team. The mechanics echo the phishing playbook seen in other recent campaigns, including a phishing alert issued to 14,000 Trezor users after a data breach.
A wallet approval, or token allowance, is a permission that lets a smart contract move a specific token from your wallet on your behalf. Grant it broadly, and the holder of that permission can transfer eligible assets without asking again. For related coverage, see Bitcoin Miner Signs $350M AI Deal, Needs $185M More.
The scam works because the pitch sounds like due diligence. A user worried about tainted funds or a flagged deposit is told to run an AML check, a request that borrows the language of legitimate compliance and sanctions screening. To a less technical user, connecting a wallet to “verify” it feels like a reasonable step. For related coverage, see CFTC Prepares Crypto Rules if Congress Stalls on Clarity Act.
The problem is the gap between the front-end promise and the on-chain reality. The page displays a benign scan, but the transaction it asks you to sign is an approval that grants spending access. Malwarebytes said a basic AML wallet screening only needs the public wallet address and does not require a wallet connection, approval, or signature.
Stefan Dasic of Malwarebytes put the standard plainly.
“For a basic wallet check, the service only needs the wallet’s public address.”
Stefan Dasic, Malwarebytes
AMLBot, the brand most often impersonated, issued its own warning that connecting a Web3 wallet is never required for its checks, and that once such an approval is signed it can drain the wallet, the company said in an advisory.
Compliance framing is a potent lever. Security-themed prompts invoking regulators create urgency and lower skepticism, the same behavioral pressure that makes brand-impersonation phishing so productive. AMLBot noted that scammers even cite bodies such as FATF, ESMA, or the FCA to manufacture credibility.
It helps that most users do not inspect the details. Signing a message to prove wallet ownership is harmless, but approving a transaction that sets a token allowance is not, and the two prompts can look similar in a rushed moment. Few victims scrutinize the spender address or the scope of the permission before clicking approve.
Independent evidence shows how directly these pages map to drainer infrastructure. PhishDestroy classified usdt-verif.net, a domain titled “Web3 AML Checker,” as a confirmed crypto drainer using a WalletConnect abuse kit, assigning it a 95/100 threat verdict alongside 12 of 91 flagged detections on VirusTotal.
The losses rarely stop at one token. Because attackers can obtain multiple approvals in a single session, they may drain several assets, and MetaMask warns that transactions cannot be reversed and lists granting a dapp or smart contract unlimited access as a common cause of wallet compromise, in its recovery guidance.
The tactic fits a wider surge in trust-based deception. Chainalysis reported that impersonation scams grew more than 1400% year over year in 2025, a backdrop that explains why attackers increasingly borrow compliance and brand-trust language.
The same brand-abuse logic drives adjacent frauds, from fake software downloads seeded with wallet-stealing malware to outright investment cons such as the fake FXRP scheme that led to $8.6 million in XRP losses and arrests in South Korea.
Malwarebytes flagged a list of indicator domains tied to the campaign, including amlbot-clear[.]com, audittrust[.]shop, bitget-aml[.]com, search-aml[.]net, and swapstoken[.]app, none of which are legitimate screening services.
What to know:
Bitcoin traded at $73,170 at press time, up 5.5% on the day, while the market’s Fear & Greed Index sat at 62, in “Greed” territory, a risk-on mood that scammers count on to keep users moving quickly through prompts.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Quick access to the site tools and map-driven utility pages.
Follow the core desks readers use most across Bitcoin, altcoins, mining, events, and sponsored coverage.
© 2026 BitcoinInfoNews.com. All rights reserved.
Independent Bitcoin and crypto coverage with public trust, policy, and newsroom pages available sitewide.