Wallet Connection Prompts Are a Sign of a Fake AML Check Website

cryptonews.ruPublished on 2026-08-21Last updated on 2026-08-21

Abstract

Fake anti-money laundering (AML) verification sites are stealing from cryptocurrency investors. These websites trick users into connecting their wallets and signing transactions, which is unnecessary for a basic wallet check, as discovered by Malwarebytes. Legitimate wallet verification only requires a public address to analyze transaction history for links to hacks, thefts, or sanctioned entities. The fraudulent sites, some copying brands like AMLBot, mimic this process. After a user initiates a scan, they are prompted to connect their wallet, shown fake progress bars, and sometimes asked to pay a small "fee." Eventually, a false "clean, low risk" verdict is given to download a report. Connecting a wallet reveals the public address and assets, allowing scammers to craft targeted transactions for the victim to approve, which can drain funds. Malwarebytes warns that any AML checker requesting wallet connection instead of just a public address is a major red flag. The report details that the same malicious template is repackaged under different names. It also mentions a $500 scam kit advertised on cybercrime forums that creates fake token presales, scans visitor wallets for valuable assets, and attempts to steal secret recovery phrases by offering a bonus. The article advises users who connected only a wallet to revoke the site's permissions. Those who signed suspicious transactions should check activity and move funds to a new wallet if compromised. Anyone who entered a re...

Fake anti-money laundering check websites are stealing money from crypto investors.

These websites prompt users to connect a wallet and sign a transaction, which is not required for a genuine wallet verification. Malwarebytes discovered this attack this week.

Only the Public Address is Needed for Genuine Wallet Verification

Under anti-money laundering regulations, banks and regulated firms are required to verify that their clients are not linked to criminal activities.

In the cryptocurrency space, such checks involve analyzing the public transaction history of a wallet address for connections to hacks, thefts, sanctioned entities, or other suspicious activity.

According to Malwarebytes researcher Stefan Dasic, fraudulent websites take this concept and weaponize it.

Some copy the branding of AMLBot, a legitimate AML checking service. Others operate under generic names like 'AML Check.'

A visitor selects a cryptocurrency, clicks a scan button, and is then prompted to connect their wallet to see the result.

One version analyzed by Malwarebytes displays a progress bar with messages like 'Checking wallet history...' and 'Checking compliance...', then shows a fake error asking for a small top-up to 'cover the fee.'

Click 'Retry,' and the animation runs again, eventually giving a reassuring verdict of 'Clean, low risk' and offering to download a report.

A genuine basic check requires only the wallet's public address. It is a simple lookup, with no signing, granting permissions, or connecting the wallet.

'If an anti-money laundering checker asks you to connect your wallet rather than just enter its public address, treat it as a red flag,' the Malwarebytes team wrote.

Connecting a wallet does not hand over keys but does reveal the public address. This allows the operators to see what assets are inside and craft transactions targeting that specific wallet.

This transaction is then sent to the victim for approval. Approval is the point at which funds start to move.

Researchers advise not approving unexpected transactions.

Malwarebytes found the same malware kit being used under different names and logos. The kit is being renamed and resold.

$500 Kit Uses Recovery Phrase Phishing, Promises 15% Bonus

This month, Cryptopolitan reported on a $500 ready-made kit available on a cybercrime forum. The kit creates a fake $TSLA presale and scans each visitor's wallet for valuable holdings.

The scammers then attempt to phish the 12-word recovery phrase by offering a 15% bonus. An admin panel automatically inflates balances artificially to keep victims paying.

In May, Solana Floor uncovered a scheme flooding Solana wallets with counterfeit '$CJUP' tokens, mimicking the Jupuary airdrop from Jupiter Exchange and redirecting recipients to a fake website, as Cryptopolitan reported at the time.

CoinDCX reported discovering over 1,212 fake websites impersonating its platform between April 2024 and January 2026. Mumbai police have registered a complaint regarding fraud committed via a website impersonating CoinDCX.

Malwarebytes advised anyone who has only connected a wallet to disconnect the site. Anyone who granted a token permission to their wallet should check for unfamiliar permissions and revoke them.

Anyone who signed something unclear should check recent activity and, if funds are compromised, transfer everything to a new wallet. Anyone who entered a recovery phrase or private key should assume the wallet is compromised.

Trending Cryptos

Related Questions

QAccording to the article, what is a key red flag that a cryptocurrency AML (Anti-Money Laundering) checking website is likely a scam?

AThe key red flag is if the website asks you to connect your wallet, rather than simply enter your wallet's public address. Legitimate AML checks only require a public address.

QHow do the fake AML websites ultimately steal money from victims?

AThey trick victims into connecting their wallets, which allows the operators to see the assets inside. They then send a targeted transaction for the victim to approve. Signing/approving this transaction allows the money to be transferred out.

QWhat did Malwarebytes researchers discover about the malware kits used to create these fake sites?

AThey discovered that the same malware template is being used under different names and logos. The kits are being renamed and resold to various criminals.

QWhat is the purpose of the $500 kit mentioned in the article that was sold on a cybercrime forum?

AThe $500 kit creates a fake $TSLA presale website. It scans each visitor's wallet for valuable assets and then tries to trick them into revealing their 12-word seed phrase by offering a 15% bonus.

QWhat three actions does Malwarebytes recommend for users based on their level of interaction with a suspicious site?

A1. If you only connected a wallet, disconnect the site. 2. If you granted token permissions, review and revoke any unfamiliar approvals. 3. If you signed something unknown, check recent activity. If funds were taken, move remaining assets to a new wallet. 4. If you entered a seed phrase or private key, assume the wallet is compromised.

Related Reads

Just Now, Sam Altman Blasts Dario Amodei as 'Anti-Human', Secret Model Exposed the Same Day

Just now, Sam Altman strongly criticized Dario (Amodei, co-founder of Anthropic), denouncing his "doomsday marketing" as "anti-human dictator rhetoric." This came alongside the accidental exposure of OpenAI's next-generation model, codenamed "gpt-nathree," hinting at the imminent release of GPT-6 Astra. The leak occurred when an OpenAI employee's public GitHub commit mentioned the codename. Combined with previous leaks of "gpt-mewfour," it suggests these are iterative checkpoints for OpenAI's upcoming agent model, Astra. Astra is known for multi-agent collaboration and long-duration task handling, having reportedly solved previously unsolved mathematical problems. Meanwhile, two new Anthropic model codenames, "claude-marshmallow-eap" and "claude-melon-eap," were also exposed but are believed to be iterations of the Claude 5 series, not a new flagship. In a wide-ranging podcast interview, Altman admitted he was wrong about the speed of AI-driven disruption, acknowledging societal inertia slows adoption. He fiercely criticized rivals' marketing that simultaneously promises immense benefits (like curing cancer) and warns of existential risk, calling it a dangerous "benevolent dictator" narrative that seeks to concentrate power. He emphasized that people are the ultimate purpose of AI. Altman also revealed OpenAI's unconventional, consensus-defying path: spending four and a half years in the "dark" without a public product before ChatGPT's breakthrough, driven by scaling laws rather than early customer feedback. He concluded that even with superintelligent AI, genuine human connection will remain irreplaceably valuable.

marsbit36m ago

Just Now, Sam Altman Blasts Dario Amodei as 'Anti-Human', Secret Model Exposed the Same Day

marsbit36m ago

The 'Saving U.S. Treasuries' Baton Pass: Bessent Fumbled Last Week, This Week It's Wash's Turn

"Rescuing US Treasuries" Relay: After Bessent's Miss, All Eyes Are on Walsh Last week, US Treasury Secretary Bessent's announcement to at least double long-term Treasury buybacks failed to sustainably lower yields, which quickly rebounded. The market response saw a drop in the dollar alongside surges in gold and Bitcoin, interpreted as a "pressure release valve" for anxiety. The focus now shifts to Fed Chairman Walsh's upcoming Jackson Hole speech. Markets are highly sensitive to his message, seeking clarity on the Fed's policy response to stubborn inflation and worsening fiscal conditions. Analysts warn that a lack of new guidance could disappoint markets and worsen the sell-off in long-dated bonds. Analysts question the scale of Bessent's operations, noting they are too small relative to the overall debt market and do not constitute quantitative easing. A key issue is the Fed's massive holdings of long-term bonds, which distorts the market. With the Fed holding low-yielding short-term bonds that are losing money relative to its policy rate, discussion is growing around a potential Fed-led "Operation Twist." This would involve selling short-term bonds to buy long-term ones, aiming to lower long-end yields without expanding the balance sheet. The upcoming PCE inflation data will set the stage for Walsh's speech. However, the window for action is narrowing amid political pressures. A critical threshold is the 30-year yield at 5%; holding above it could increase stress on the dollar and leveraged sectors. Overall, the article suggests that without coordinated Fed action to anchor inflation expectations, Treasury interventions may ultimately fail, with investors increasingly looking to assets like gold as hedges.

marsbit1h ago

The 'Saving U.S. Treasuries' Baton Pass: Bessent Fumbled Last Week, This Week It's Wash's Turn

marsbit1h ago

Hyperliquid's Compliance Journey: From Permissionless to Permissioned via HIP-3

Hyperliquid’s Compliance Path: From Permissionless to Permissioned HIP-3 Hyperliquid currently blocks U.S. access because its permissionless, on-chain infrastructure conflicts with U.S. market structure laws, which restrict futures trading to registered exchanges, clearinghouses, and brokers. Through its Hyperliquid Policy Center (HPC), the project is advocating for regulatory modernization, proposing that regulated entities be allowed to build products on HyperCore (its exchange and clearing layer) while fulfilling their compliance obligations. The platform’s modular stack separates roles like a traditional exchange (DCM), clearinghouse (DCO), and broker (FCM), but reconstructs them on-chain with code. This enables permissionless access, self-custody, and 24/7 global trading, but clashes with U.S. rules requiring KYC, specific margin models, and custodial arrangements. To resolve this, HPC is engaging with U.S. regulators (CFTC, SEC) to seek clarity that deploying on-chain software does not itself trigger licensing, and to establish exemptions allowing non-custodial wallets to route users to regulated derivatives. Recent political signals suggest openness to this approach. On the technical side, Hyperliquid Labs has introduced permissioned HIP-3 deployers on testnet. These allow regulated entities to launch markets, perform KYC, and whitelist compliant users. While these create separate order books, whitelisted market makers can bridge liquidity between them, ensuring deep, shared liquidity across the same L1. Features like payload-based “PA” permissions enable DEX-level account controls (e.g., reduce-only orders), mirroring traditional broker authorities. The strategy is not to open the native, permissionless front-end to U.S. users, but to position Hyperliquid as neutral infrastructure that U.S. regulated firms can use while meeting their legal duties. This paves a compliant path for U.S. investor access while preserving the protocol’s core, permissionless nature.

marsbit1h ago

Hyperliquid's Compliance Journey: From Permissionless to Permissioned via HIP-3

marsbit1h ago

Two Funding Rounds in Three Months: The Chinese Version of Palantir is on Fire

Investment Community AI has learned that Beijing Zhongshu Ruizhi Technology Co., Ltd., a domestic industrial-grade causal intelligence and high-reliability decision-making AI company, has recently completed a strategic financing round worth hundreds of millions of RMB. This round saw participation from China Internet Investment Fund, Suzhou Chuangtou National Social Security Fund, Financial Street Capital, ICBC Capital, Kunlun Capital, among others, with existing shareholders also increasing their investment. This follows a Series B funding round in the hundreds of millions completed just three months prior. The rapid succession of two major funding rounds signifies strong market recognition of the company's underlying original technology and scaled commercial implementation. Often referred to as the "Chinese version of Palantir," Zhongshu Ruizhi is entering a new phase of accelerated technological iteration, widespread scenario replication, and scaled performance release, mirroring the explosive growth of China's AI market. Founded in April 2020 by Dr. Han Han, a Tsinghua University Ph.D. and former core drafter of national AI policies, the company is mission-driven to "move AI from the digital world to the physical world." It focuses on the high-reliability, strong-decision industrial AI track and enterprise-grade AI Agent full-stack infrastructure. The team tackles the challenge of applying AI to China's vast and complex industrial and energy systems by developing a new intelligent operating system from scratch. Its core technological breakthrough lies in three proprietary底层 technologies: meta-causal cognitive theory, causal models, and a dynamic ontology engine. These address critical pain points of generative large models in industrial settings—such as AI hallucinations, insufficient reasoning, lack of temporal logic, unverifiable decisions, and multi-source rule conflicts—thereby providing trustworthy, explainable, and executable智能决策 capabilities. Commercially, Zhongshu Ruizhi has achieved scaled deployment, serving over 50 central state-owned enterprises and industrial groups in sectors like power, petroleum, and aerospace, with implementations in more than 800 highly complex production scenarios. The company reported doubled revenue in 2025, demonstrating strong self-sufficiency and a viable business model—a rarity among new-generation AI firms. The latest funds will be allocated towards advancing foundational theoretical research, replicating successful application models to expand market presence (including overseas), and attracting top-tier talent. Lead investor China Internet Investment Fund highlighted that in the current shift from general AI capability contests to deep industrial empowerment, industrial-grade causal intelligence is crucial for building China's modern digital foundation and fostering new quality productive forces. They expressed support for the company's efforts to define decision-making paradigms and trustworthy standards for industrial intelligence, aiming to secure a rule-making voice in the global physical AI arena.

marsbit1h ago

Two Funding Rounds in Three Months: The Chinese Version of Palantir is on Fire

marsbit1h ago

Trading

Spot

Hot Articles

How to Buy CHECK

Welcome to HTX.com! We've made purchasing Checkmate (CHECK) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Checkmate (CHECK) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Checkmate (CHECK)After purchasing your Checkmate (CHECK), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Checkmate (CHECK)Easily trade Checkmate (CHECK) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

5.2k Total ViewsPublished 2026.01.19Updated 2026.06.02

How to Buy CHECK

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of CHECK (CHECK) are presented below.

活动图片