Wallet Connection Prompts Are a Sign of a Fake AML Check Website

cryptonews.ru發佈於 2026-08-21更新於 2026-08-21

文章摘要

Fake anti-money laundering (AML) verification sites are stealing from cryptocurrency investors. These websites trick users into connecting their wallets and signing transactions, which is unnecessary for a basic wallet check, as discovered by Malwarebytes. Legitimate wallet verification only requires a public address to analyze transaction history for links to hacks, thefts, or sanctioned entities. The fraudulent sites, some copying brands like AMLBot, mimic this process. After a user initiates a scan, they are prompted to connect their wallet, shown fake progress bars, and sometimes asked to pay a small "fee." Eventually, a false "clean, low risk" verdict is given to download a report. Connecting a wallet reveals the public address and assets, allowing scammers to craft targeted transactions for the victim to approve, which can drain funds. Malwarebytes warns that any AML checker requesting wallet connection instead of just a public address is a major red flag. The report details that the same malicious template is repackaged under different names. It also mentions a $500 scam kit advertised on cybercrime forums that creates fake token presales, scans visitor wallets for valuable assets, and attempts to steal secret recovery phrases by offering a bonus. The article advises users who connected only a wallet to revoke the site's permissions. Those who signed suspicious transactions should check activity and move funds to a new wallet if compromised. Anyone who entered a re...

Fake anti-money laundering check websites are stealing money from crypto investors.

These websites prompt users to connect a wallet and sign a transaction, which is not required for a genuine wallet verification. Malwarebytes discovered this attack this week.

Only the Public Address is Needed for Genuine Wallet Verification

Under anti-money laundering regulations, banks and regulated firms are required to verify that their clients are not linked to criminal activities.

In the cryptocurrency space, such checks involve analyzing the public transaction history of a wallet address for connections to hacks, thefts, sanctioned entities, or other suspicious activity.

According to Malwarebytes researcher Stefan Dasic, fraudulent websites take this concept and weaponize it.

Some copy the branding of AMLBot, a legitimate AML checking service. Others operate under generic names like 'AML Check.'

A visitor selects a cryptocurrency, clicks a scan button, and is then prompted to connect their wallet to see the result.

One version analyzed by Malwarebytes displays a progress bar with messages like 'Checking wallet history...' and 'Checking compliance...', then shows a fake error asking for a small top-up to 'cover the fee.'

Click 'Retry,' and the animation runs again, eventually giving a reassuring verdict of 'Clean, low risk' and offering to download a report.

A genuine basic check requires only the wallet's public address. It is a simple lookup, with no signing, granting permissions, or connecting the wallet.

'If an anti-money laundering checker asks you to connect your wallet rather than just enter its public address, treat it as a red flag,' the Malwarebytes team wrote.

Connecting a wallet does not hand over keys but does reveal the public address. This allows the operators to see what assets are inside and craft transactions targeting that specific wallet.

This transaction is then sent to the victim for approval. Approval is the point at which funds start to move.

Researchers advise not approving unexpected transactions.

Malwarebytes found the same malware kit being used under different names and logos. The kit is being renamed and resold.

$500 Kit Uses Recovery Phrase Phishing, Promises 15% Bonus

This month, Cryptopolitan reported on a $500 ready-made kit available on a cybercrime forum. The kit creates a fake $TSLA presale and scans each visitor's wallet for valuable holdings.

The scammers then attempt to phish the 12-word recovery phrase by offering a 15% bonus. An admin panel automatically inflates balances artificially to keep victims paying.

In May, Solana Floor uncovered a scheme flooding Solana wallets with counterfeit '$CJUP' tokens, mimicking the Jupuary airdrop from Jupiter Exchange and redirecting recipients to a fake website, as Cryptopolitan reported at the time.

CoinDCX reported discovering over 1,212 fake websites impersonating its platform between April 2024 and January 2026. Mumbai police have registered a complaint regarding fraud committed via a website impersonating CoinDCX.

Malwarebytes advised anyone who has only connected a wallet to disconnect the site. Anyone who granted a token permission to their wallet should check for unfamiliar permissions and revoke them.

Anyone who signed something unclear should check recent activity and, if funds are compromised, transfer everything to a new wallet. Anyone who entered a recovery phrase or private key should assume the wallet is compromised.

熱門幣種推薦

相關問答

QAccording to the article, what is a key red flag that a cryptocurrency AML (Anti-Money Laundering) checking website is likely a scam?

AThe key red flag is if the website asks you to connect your wallet, rather than simply enter your wallet's public address. Legitimate AML checks only require a public address.

QHow do the fake AML websites ultimately steal money from victims?

AThey trick victims into connecting their wallets, which allows the operators to see the assets inside. They then send a targeted transaction for the victim to approve. Signing/approving this transaction allows the money to be transferred out.

QWhat did Malwarebytes researchers discover about the malware kits used to create these fake sites?

AThey discovered that the same malware template is being used under different names and logos. The kits are being renamed and resold to various criminals.

QWhat is the purpose of the $500 kit mentioned in the article that was sold on a cybercrime forum?

AThe $500 kit creates a fake $TSLA presale website. It scans each visitor's wallet for valuable assets and then tries to trick them into revealing their 12-word seed phrase by offering a 15% bonus.

QWhat three actions does Malwarebytes recommend for users based on their level of interaction with a suspicious site?

A1. If you only connected a wallet, disconnect the site. 2. If you granted token permissions, review and revoke any unfamiliar approvals. 3. If you signed something unknown, check recent activity. If funds were taken, move remaining assets to a new wallet. 4. If you entered a seed phrase or private key, assume the wallet is compromised.

你可能也喜歡

Hyperliquid的合规之路:从无需许可到许可制HIP-3

Hyperliquid(基于HyperCore的去中心化交易基础设施)因其无需许可、用户自托管的特点,与美国针对期货交易的严格市场结构法律(涉及注册交易平台DCM、清算所DCO和经纪商FCM)存在根本冲突,因此一直对美国市场进行地理封锁。 为了解决此困境,Hyperliquid成立了政策中心(HPC),积极游说美国监管机构(CFTC、SEC),主张将Hyperliquid视为“中立基础设施”。其核心提议是:允许已受监管的实体(如经纪商、交易平台)在履行其原有KYC、市场监控等合规义务的前提下,利用Hyperliquid的底层技术(如HyperCore)来构建和运营产品,而非要求协议本身改变其无需许可的特性。 作为这一合规路径的实例,Hyperliquid已在测试网推出具备许可权限的HIP-3部署者功能。此类部署允许受监管实体创建仅对白名单用户(即已完成KYC的合规用户)开放的市场,并拥有对用户账户执行特定操作(如强制平仓)的权限,从而模仿传统金融中FCM的职责。尽管这些合规市场会形成独立的订单簿,但通过白名单做市商的桥梁作用,它们仍能共享Hyperliquid主市场的流动性。 总之,Hyperliquid的战略目标并非直接向美国用户开放其原生免KYC前端,而是通过提供工具,让合规机构能在其底层上构建符合美国法规的产品,从而为美国投资者提供间接参与其生态的合规通道,同时保持协议本身的中立性与开放性。

marsbit1 小時前

Hyperliquid的合规之路:从无需许可到许可制HIP-3

marsbit1 小時前

交易

現貨

熱門文章

如何購買CHECK

歡迎來到HTX.com!在這裡,購買Checkmate (CHECK)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買Checkmate (CHECK)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的Checkmate (CHECK)購買Checkmate (CHECK)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易Checkmate (CHECK)在HTX的現貨市場輕鬆交易Checkmate (CHECK)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

1.0k 人學過發佈於 2026.01.19更新於 2026.06.02

如何購買CHECK

相關討論

歡迎來到 HTX 社群。在這裡,您可以了解最新的平台發展動態並獲得專業的市場意見。 以下是用戶對 CHECK (CHECK)幣價的意見。

活动图片