Scammers are using fake “AML check” websites to trick crypto users into approving transactions that can drain their wallets, cybersecurity firm Malwarebytes warns. What’s happening Malwarebytes’ report describes a wave of fraudulent sites posing as anti-money-laundering (AML) services — some mimicking the real AMLBot brand, others hiding behind generic names like “AML Check.” Legitimate AML tools only need a public wallet address to scan on-chain history for links to hacks, scams, sanctioned entities and other red flags. They do not require wallet connections, permission approvals, or transaction signatures. The scam The fake pages ask victims to connect their wallets and then fake a verification process with progress bars and bogus results. One site even requested a small “top-up” fee before returning a “Clean, Low Risk” result — regardless of whether any real check happened. Connecting a wallet by itself doesn’t immediately let attackers remove funds, but it exposes the public address and the wallet’s holdings. With that info, scammers can generate malicious transactions that the user is then prompted to approve — and a signed transaction can move assets out permanently. Signs of a template operation Malwarebytes notes the same basic layout and flow appearing under multiple names and logos, suggesting the scammers are reusing and rebranding a single scam template. Context: other recent phishing waves This isn’t an isolated trick. In recent months, hardware wallet makers Trezor and Foundation warned about phishing emails directing users to a cloned Coldcard website; Malwarebytes uncovered a fake version of Pudgy Penguins’ Pudgy World game designed to steal wallet credentials; and crypto exchange CoinDCX reported more than 1,200 impersonating websites between April 2024 and January 2026. What to do if you encounter or fall for one - Treat any AML checker that asks you to connect your wallet rather than accept a public address as a red flag, Malwarebytes advises. - If you approved token access or other permissions on a suspicious site, revoke those approvals immediately using an on-chain explorer or approval-revocation tool. - If you entered your recovery phrase or private key, assume the wallet is compromised: move funds to a new wallet created on a secure device and transfer assets quickly — blockchain transactions are generally irreversible. - As a rule: never enter your seed phrase into a website, double-check URLs and bookmarks, use official links from trusted sources, and avoid signing transactions unless you understand exactly what they authorize. Bottom line Scammers are increasingly clever at cloning trusted services and luring users with what looks like legitimate security checks. A simple rule — prefer read-only checks that accept public addresses, and never connect or sign unless absolutely necessary — can help keep your crypto safe. Read more AI-generated news on: undefined/news