Security specialists have discovered that fraudsters are copying the design and logos of the AMLBot service or using similar names like AMLCheck. Such services check a crypto address's transaction history to see if it might be linked to fraud, hacking, violation of international sanctions, or any other illegal activity.
Unlike legitimate Anti-Money Laundering (AML) services, which only require a public wallet address for a check, fake services ask users to connect their actual wallet. This does not give the scammers access to the funds, however, by learning the user's public address, hackers create a custom transaction for them, which they then ask the user to confirm.

The process of checking crypto addresses on fake websites mimics a genuine security check: users see messages like "Checking wallet history" and "Checking compliance." Then the service produces a false error, claiming that to complete the verification, a small top-up to the wallet is needed to pay a fee. After a second attempt to perform the check, a reassuring result appears: the address is clean. The user is then prompted to download a verification report, after which malicious software is launched on the user's device.

Malwarebytes Labs reminded that a real AML check only requires a public address; it does not involve connecting a wallet, approving transactions, or using a seed phrase. If a service requests token access or asks to confirm a transaction—that is a clear sign of fraud. In case of lost funds, users are advised to move remaining assets to a new address and not to trust offers of "recovering cryptoassets" for a separate fee.
Security specialists at CertiK named phishing attacks and deepfakes as the main tools of hackers. In 2025 alone, losses in the crypto industry from malicious actors amounted to $3.3 billion, according to CertiK's calculations.
end-content




