Wallet Connection Prompts Are a Sign of a Fake AML Check Website

cryptonews.ru发布于2026-08-21更新于2026-08-21

文章摘要

Fake anti-money laundering (AML) verification sites are stealing from cryptocurrency investors. These websites trick users into connecting their wallets and signing transactions, which is unnecessary for a basic wallet check, as discovered by Malwarebytes. Legitimate wallet verification only requires a public address to analyze transaction history for links to hacks, thefts, or sanctioned entities. The fraudulent sites, some copying brands like AMLBot, mimic this process. After a user initiates a scan, they are prompted to connect their wallet, shown fake progress bars, and sometimes asked to pay a small "fee." Eventually, a false "clean, low risk" verdict is given to download a report. Connecting a wallet reveals the public address and assets, allowing scammers to craft targeted transactions for the victim to approve, which can drain funds. Malwarebytes warns that any AML checker requesting wallet connection instead of just a public address is a major red flag. The report details that the same malicious template is repackaged under different names. It also mentions a $500 scam kit advertised on cybercrime forums that creates fake token presales, scans visitor wallets for valuable assets, and attempts to steal secret recovery phrases by offering a bonus. The article advises users who connected only a wallet to revoke the site's permissions. Those who signed suspicious transactions should check activity and move funds to a new wallet if compromised. Anyone who entered a re...

Fake anti-money laundering check websites are stealing money from crypto investors.

These websites prompt users to connect a wallet and sign a transaction, which is not required for a genuine wallet verification. Malwarebytes discovered this attack this week.

Only the Public Address is Needed for Genuine Wallet Verification

Under anti-money laundering regulations, banks and regulated firms are required to verify that their clients are not linked to criminal activities.

In the cryptocurrency space, such checks involve analyzing the public transaction history of a wallet address for connections to hacks, thefts, sanctioned entities, or other suspicious activity.

According to Malwarebytes researcher Stefan Dasic, fraudulent websites take this concept and weaponize it.

Some copy the branding of AMLBot, a legitimate AML checking service. Others operate under generic names like 'AML Check.'

A visitor selects a cryptocurrency, clicks a scan button, and is then prompted to connect their wallet to see the result.

One version analyzed by Malwarebytes displays a progress bar with messages like 'Checking wallet history...' and 'Checking compliance...', then shows a fake error asking for a small top-up to 'cover the fee.'

Click 'Retry,' and the animation runs again, eventually giving a reassuring verdict of 'Clean, low risk' and offering to download a report.

A genuine basic check requires only the wallet's public address. It is a simple lookup, with no signing, granting permissions, or connecting the wallet.

'If an anti-money laundering checker asks you to connect your wallet rather than just enter its public address, treat it as a red flag,' the Malwarebytes team wrote.

Connecting a wallet does not hand over keys but does reveal the public address. This allows the operators to see what assets are inside and craft transactions targeting that specific wallet.

This transaction is then sent to the victim for approval. Approval is the point at which funds start to move.

Researchers advise not approving unexpected transactions.

Malwarebytes found the same malware kit being used under different names and logos. The kit is being renamed and resold.

$500 Kit Uses Recovery Phrase Phishing, Promises 15% Bonus

This month, Cryptopolitan reported on a $500 ready-made kit available on a cybercrime forum. The kit creates a fake $TSLA presale and scans each visitor's wallet for valuable holdings.

The scammers then attempt to phish the 12-word recovery phrase by offering a 15% bonus. An admin panel automatically inflates balances artificially to keep victims paying.

In May, Solana Floor uncovered a scheme flooding Solana wallets with counterfeit '$CJUP' tokens, mimicking the Jupuary airdrop from Jupiter Exchange and redirecting recipients to a fake website, as Cryptopolitan reported at the time.

CoinDCX reported discovering over 1,212 fake websites impersonating its platform between April 2024 and January 2026. Mumbai police have registered a complaint regarding fraud committed via a website impersonating CoinDCX.

Malwarebytes advised anyone who has only connected a wallet to disconnect the site. Anyone who granted a token permission to their wallet should check for unfamiliar permissions and revoke them.

Anyone who signed something unclear should check recent activity and, if funds are compromised, transfer everything to a new wallet. Anyone who entered a recovery phrase or private key should assume the wallet is compromised.

热门币种推荐

相关问答

QAccording to the article, what is a key red flag that a cryptocurrency AML (Anti-Money Laundering) checking website is likely a scam?

AThe key red flag is if the website asks you to connect your wallet, rather than simply enter your wallet's public address. Legitimate AML checks only require a public address.

QHow do the fake AML websites ultimately steal money from victims?

AThey trick victims into connecting their wallets, which allows the operators to see the assets inside. They then send a targeted transaction for the victim to approve. Signing/approving this transaction allows the money to be transferred out.

QWhat did Malwarebytes researchers discover about the malware kits used to create these fake sites?

AThey discovered that the same malware template is being used under different names and logos. The kits are being renamed and resold to various criminals.

QWhat is the purpose of the $500 kit mentioned in the article that was sold on a cybercrime forum?

AThe $500 kit creates a fake $TSLA presale website. It scans each visitor's wallet for valuable assets and then tries to trick them into revealing their 12-word seed phrase by offering a 15% bonus.

QWhat three actions does Malwarebytes recommend for users based on their level of interaction with a suspicious site?

A1. If you only connected a wallet, disconnect the site. 2. If you granted token permissions, review and revoke any unfamiliar approvals. 3. If you signed something unknown, check recent activity. If funds were taken, move remaining assets to a new wallet. 4. If you entered a seed phrase or private key, assume the wallet is compromised.

你可能也喜欢

Hyperliquid的合规之路:从无需许可到许可制HIP-3

Hyperliquid(基于HyperCore的去中心化交易基础设施)因其无需许可、用户自托管的特点,与美国针对期货交易的严格市场结构法律(涉及注册交易平台DCM、清算所DCO和经纪商FCM)存在根本冲突,因此一直对美国市场进行地理封锁。 为了解决此困境,Hyperliquid成立了政策中心(HPC),积极游说美国监管机构(CFTC、SEC),主张将Hyperliquid视为“中立基础设施”。其核心提议是:允许已受监管的实体(如经纪商、交易平台)在履行其原有KYC、市场监控等合规义务的前提下,利用Hyperliquid的底层技术(如HyperCore)来构建和运营产品,而非要求协议本身改变其无需许可的特性。 作为这一合规路径的实例,Hyperliquid已在测试网推出具备许可权限的HIP-3部署者功能。此类部署允许受监管实体创建仅对白名单用户(即已完成KYC的合规用户)开放的市场,并拥有对用户账户执行特定操作(如强制平仓)的权限,从而模仿传统金融中FCM的职责。尽管这些合规市场会形成独立的订单簿,但通过白名单做市商的桥梁作用,它们仍能共享Hyperliquid主市场的流动性。 总之,Hyperliquid的战略目标并非直接向美国用户开放其原生免KYC前端,而是通过提供工具,让合规机构能在其底层上构建符合美国法规的产品,从而为美国投资者提供间接参与其生态的合规通道,同时保持协议本身的中立性与开放性。

marsbit1小时前

Hyperliquid的合规之路:从无需许可到许可制HIP-3

marsbit1小时前

交易

现货

热门文章

如何购买CHECK

欢迎来到HTX.com!我们已经让购买Checkmate(CHECK)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Checkmate(CHECK)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Checkmate(CHECK)购买完您的Checkmate(CHECK)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Checkmate(CHECK)在HTX的现货市场轻松交易Checkmate(CHECK)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

2.0k人学过发布于 2026.01.19更新于 2026.06.02

如何购买CHECK

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对CHECK(CHECK)币价的意见。

活动图片