Fake anti-money laundering check websites are stealing money from crypto investors.
These websites prompt users to connect a wallet and sign a transaction, which is not required for a genuine wallet verification. Malwarebytes discovered this attack this week.
Only the Public Address is Needed for Genuine Wallet Verification
Under anti-money laundering regulations, banks and regulated firms are required to verify that their clients are not linked to criminal activities.
In the cryptocurrency space, such checks involve analyzing the public transaction history of a wallet address for connections to hacks, thefts, sanctioned entities, or other suspicious activity.
According to Malwarebytes researcher Stefan Dasic, fraudulent websites take this concept and weaponize it.
Some copy the branding of AMLBot, a legitimate AML checking service. Others operate under generic names like 'AML Check.'
A visitor selects a cryptocurrency, clicks a scan button, and is then prompted to connect their wallet to see the result.
One version analyzed by Malwarebytes displays a progress bar with messages like 'Checking wallet history...' and 'Checking compliance...', then shows a fake error asking for a small top-up to 'cover the fee.'
Click 'Retry,' and the animation runs again, eventually giving a reassuring verdict of 'Clean, low risk' and offering to download a report.
A genuine basic check requires only the wallet's public address. It is a simple lookup, with no signing, granting permissions, or connecting the wallet.
'If an anti-money laundering checker asks you to connect your wallet rather than just enter its public address, treat it as a red flag,' the Malwarebytes team wrote.
Connecting a wallet does not hand over keys but does reveal the public address. This allows the operators to see what assets are inside and craft transactions targeting that specific wallet.
This transaction is then sent to the victim for approval. Approval is the point at which funds start to move.
Researchers advise not approving unexpected transactions.
Malwarebytes found the same malware kit being used under different names and logos. The kit is being renamed and resold.
$500 Kit Uses Recovery Phrase Phishing, Promises 15% Bonus
This month, Cryptopolitan reported on a $500 ready-made kit available on a cybercrime forum. The kit creates a fake $TSLA presale and scans each visitor's wallet for valuable holdings.
The scammers then attempt to phish the 12-word recovery phrase by offering a 15% bonus. An admin panel automatically inflates balances artificially to keep victims paying.
In May, Solana Floor uncovered a scheme flooding Solana wallets with counterfeit '$CJUP' tokens, mimicking the Jupuary airdrop from Jupiter Exchange and redirecting recipients to a fake website, as Cryptopolitan reported at the time.
CoinDCX reported discovering over 1,212 fake websites impersonating its platform between April 2024 and January 2026. Mumbai police have registered a complaint regarding fraud committed via a website impersonating CoinDCX.
Malwarebytes advised anyone who has only connected a wallet to disconnect the site. Anyone who granted a token permission to their wallet should check for unfamiliar permissions and revoke them.
Anyone who signed something unclear should check recent activity and, if funds are compromised, transfer everything to a new wallet. Anyone who entered a recovery phrase or private key should assume the wallet is compromised.






