Crypto Scammers Pose as Address AML Checking Services

cryptonews.ruPublished on 2026-08-19Last updated on 2026-08-19

Abstract

Cybersecurity experts have uncovered a cryptocurrency scam where fraudsters impersonate legitimate AML (Anti-Money Laundering) address-checking services like AMLBot by copying their design, logos, or using similar names such as AMLCheck. These fake services, which normally verify if a crypto address has been linked to illegal activities, trick users by asking them to connect their wallet—unlike genuine services that only require a public address. Once a user connects, scammers obtain their public address and create a transaction for them to approve, often claiming a "security check" or "compliance verification." The fake service then displays a false error, prompting the user to deposit a small amount for a "fee" to complete the check. After the user complies, the site shows a "clean address" result and offers a downloadable verification report, which installs malware. Malwarebytes Labs and security firm CertiK warn that legitimate AML checks never require wallet connections, transaction approvals, or seed phrases. If a service requests these, it is a scam. In cases of theft, users are advised to move remaining funds to a new address and avoid "asset recovery" offers for a fee. CertiK noted that phishing and deepfakes are primary hacker tools, with crypto industry losses reaching $3.3 billion in 2025 alone.

Security specialists have discovered that fraudsters are copying the design and logos of the AMLBot service or using similar names like AMLCheck. Such services check a crypto address's transaction history to see if it might be linked to fraud, hacking, violation of international sanctions, or any other illegal activity.

Unlike legitimate Anti-Money Laundering (AML) services, which only require a public wallet address for a check, fake services ask users to connect their actual wallet. This does not give the scammers access to the funds, however, by learning the user's public address, hackers create a custom transaction for them, which they then ask the user to confirm.

The process of checking crypto addresses on fake websites mimics a genuine security check: users see messages like "Checking wallet history" and "Checking compliance." Then the service produces a false error, claiming that to complete the verification, a small top-up to the wallet is needed to pay a fee. After a second attempt to perform the check, a reassuring result appears: the address is clean. The user is then prompted to download a verification report, after which malicious software is launched on the user's device.

Malwarebytes Labs reminded that a real AML check only requires a public address; it does not involve connecting a wallet, approving transactions, or using a seed phrase. If a service requests token access or asks to confirm a transaction—that is a clear sign of fraud. In case of lost funds, users are advised to move remaining assets to a new address and not to trust offers of "recovering cryptoassets" for a separate fee.

Security specialists at CertiK named phishing attacks and deepfakes as the main tools of hackers. In 2025 alone, losses in the crypto industry from malicious actors amounted to $3.3 billion, according to CertiK's calculations.

end-content

Related Questions

QWhat are cryptocurrency scammers impersonating, according to the article?

ACryptocurrency scammers are impersonating Anti-Money Laundering (AML) address checking services by copying the design and logos of legitimate services like AMLBot or using similar names like AMLCheck.

QWhat is the key difference between a legitimate AML check service and a fake one described in the text?

AA legitimate AML check service only requires the user's public wallet address, while a fake service asks the user to connect their actual wallet, which can allow scammers to create targeted transactions for the user to approve.

QWhat false error do the fake websites display during their 'check' process, and what do they ask the user to do?

AThe fake websites display a false error stating that to complete the 'check,' the user needs to top up their wallet with a small amount to pay a fee.

QAccording to Malwarebytes Labs, what are clear signs that an AML check service is fraudulent?

AClear signs of fraud are if the service requests access to tokens, asks the user to approve a transaction, or requires the use of a seed phrase. A legitimate check only needs a public address.

QWhat did security company CertiK report as the main tools of hackers, and what were the estimated losses for 2025?

ACertiK reported that phishing attacks and deepfakes are the main tools of hackers. They estimated that losses in the crypto industry from malicious activities amounted to $3.3 billion in 2025 alone.

Related Reads

Latest: Korean QFI Has Bought Changxin Technology

Latest Data Shows Korean QFI Has Purchased Changxin Technology According to data from SEIBro (under Korea Securities Depository, KSD), Korean investors, acting as Qualified Foreign Investors (QFI), have been actively purchasing shares of Changxin Technology (stock code 688825), a company recently listed on China's Sci-Tech Innovation Board (STAR Market). Over the past month until August 18, they made a net purchase of this stock worth approximately $45.32 million (around CNY 307 million), making it the top A-share by net purchase volume for Korean investors during that period. This activity has significantly boosted overall Korean net buying in A-shares. As Changxin Technology is not yet included in the Stock Connect schemes, QFI is currently the only channel for overseas investors like these Koreans to access its shares. SEIBro data indicates Korean buying began as early as July 28, the stock's second trading day. The stock appeared in Korean investor purchase lists using a temporary virtual ISIN code in settlement instructions, as its official international code had not yet been assigned. The listing has garnered significant international attention. On its first trading day (July 27), the actively managed U.S. ETF Tema Memory ETF (DISK) swiftly added Changxin Technology to its portfolio, giving it a substantial 10.56% weighting. Another active ETF, Roundhill Memory ETF (DRAM), also quickly included the stock. Furthermore, global index provider MSCI has added Changxin Technology to its MSCI China All Shares Index, prompting passive fund inflows. Analysts highlight Changxin Technology's unique position to serve China's rapidly growing AI ecosystem amid a global semiconductor memory supply shortage driven by AI demand. Besides Changxin Technology, other A-shares heavily bought by Korean investors recently include Weichai Power, Demingli, Changdian Technology, and CSOP China STAR Chip ETF.

marsbit46m ago

Latest: Korean QFI Has Bought Changxin Technology

marsbit46m ago

China Pinches the Vital Point of CPO

The article "China Grips the Achilles' Heel of CPO" details how China holds a strategic position in the global indium phosphide (InP) supply chain, a critical material for high-speed optical modules and CPO (Co-Packaged Optics) technology used in AI data centers. China controls over 70% of global indium reserves and produces more than half of the world's primary indium, primarily as a by-product of zinc/tin smelting. It further refines 70-80% of the globe's refined indium. This upstream dominance is compounded by the fact that key InP wafer producer AXT operates its primary production through its Chinese subsidiary, Beijing Tongmei. Adding to this leverage are China's export controls, first on InP products and later extending to high-purity indium (6N+ grade). These restrictions have created supply bottlenecks and uncertainty, straining foreign manufacturers like Japan's Sumitomo and Dowa, who rely heavily on Chinese materials. The resulting shortage has led to intense demand, with industry figures like Lumentum's CEO warning of severe constraints and companies like Coherent seeking direct assurances from China. This situation benefits Chinese InP supply chain companies. Firms like Yunnan Chihong Zinc & Germanium (a leading domestic InP wafer producer) and Zhuzhou Keneng (high-purity indium) report surging domestic revenues and orders. They are also making progress in high-end product validation and capacity expansion. However, challenges remain, including lengthy customer qualification cycles and a significant capacity gap compared to foreign leaders. The article frames the current AI-driven demand surge as a pivotal moment for China's InP industry. It references a historical lesson where China, despite controlling indium resources, once ceded value-add and pricing power to Japanese processors. The current scenario is seen as an opportunity to leverage upstream resource control to develop advanced manufacturing capabilities and secure greater influence in the global semiconductor materials market.

marsbit56m ago

China Pinches the Vital Point of CPO

marsbit56m ago

Russian Suspected of Stealing Cryptocurrency from Cold Wallet Worth Almost 10 Million Rubles

Russian authorities are investigating a suspect accused of stealing nearly 10 million rubles worth of cryptocurrency from a cold wallet. According to investigators, the wallet belonged to an unnamed commercial company executive's assistant. In March, the suspect allegedly gained access to the victim's wallet by "an unidentified method" and transferred the digital assets to another address. During a search of the suspect's home, police seized three computers and three mobile phones for forensic examination, as they may contain important digital evidence. The case is being investigated as grand larceny under the Russian Criminal Code, carrying a potential sentence of up to ten years in prison. Police are also checking the suspect's possible involvement in other cryptocurrency thefts and identifying potential accomplices. The article notes that while cold wallets (hardware wallets storing private keys offline) are considered more secure against remote hacking, they remain vulnerable if a perpetrator gains physical or direct access to the keys. In a related case earlier in June, a court in Tomsk sentenced two men to 8 and 9.5 years in a strict-regime colony for a robbery and cryptocurrency theft. They forced an acquaintance at knifepoint to log into a crypto exchange account and transfer over 85 bitcoins, valued at approximately $5.1 million at the time.

cryptonews.ru1h ago

Russian Suspected of Stealing Cryptocurrency from Cold Wallet Worth Almost 10 Million Rubles

cryptonews.ru1h ago

Trading

Spot
活动图片