Skip to content

Invest2 publishers3 min readPublished

The compliance-flavoured drainer: fake AML checkers that need your signature, not your address

Malwarebytes says fake crypto AML screening sites are draining wallets. The defence is unglamorous: a real basic check needs only a public address, so a connect prompt is the tell.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying The compliance-flavoured drainer: fake AML checkers that need your signature, not your address
Generated illustration

What happened

  • Malwarebytes said in a report published Wednesday that fake crypto AML checkers trick users into connecting their wallets and approving transactions, putting their digital assets at risk.
  • Some of the fake sites mimic the legitimate screening service AMLBot, while others use generic names such as "AML Check."
  • Crypto AML services check a wallet's public transaction history for links to hacks, scams, sanctioned entities and other suspicious activity.
  • A basic AML check requires only a wallet's public address and does not require users to connect their wallet, approve permissions, or sign a transaction.
  • Malwarebytes researchers wrote: "If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign."

Compiled by The InvestorSomething wrong?How this is made

Why it matters

Malwarebytes said in a report published Wednesday that scammers are running fake crypto anti-money-laundering checkers which prompt visitors to connect a wallet and then approve a transaction that puts their assets at risk [1]. The consequence for anyone holding client or treasury funds is that the bait is no longer a free airdrop or a presale, it is compliance, which is the one category of request that trained users are least likely to refuse.

The mechanics are cheap. A visitor picks a cryptocurrency, clicks to scan it, and is told to connect a wallet to see the result [6]. One version Malwarebytes examined runs a progress bar with messages such as "Checking wallet history..." and "Verifying compliance...", then throws a fake error asking for a small top-up to cover a fee [7]. Retry, and the animation replays before returning a soothing "Clean, Low Risk" verdict and an offer to download a report [8]. Some sites copy the branding of AMLBot, a legitimate screening service; others use generic names such as "AML Check" [2].

The useful part is the tell, and it is binary. A genuine crypto AML check reads a wallet's public transaction history for links to hacks, scams, sanctioned entities and other suspicious activity [3]. A basic check requires only the public address: no connection, no permissions, no signature [4]. As Malwarebytes researchers put it, "If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign" [5].

Connecting does not hand over keys, but it does expose the public address, which lets the operator see what assets are inside and build a transaction aimed at that specific wallet [9]. Approval is the moment the money moves [10]. Malwarebytes says transactions generally cannot be reversed once confirmed, so speed matters after a bad signature [14].

This is a product, not a stunt. Malwarebytes researcher Stefan Dasic found the same skeleton running under several names and logos, indicating the template is being rebranded and resold [11][12]. Cryptopolitan reported this month on a $500 turnkey kit sold on a cybercrime forum that builds a fake $TSLA presale, scans each visitor's wallet for valuable assets, and phishes the 12-word recovery phrase behind a 15% bonus, with an admin panel that inflates fake balances so victims keep paying [15]. In May, Solana Floor analysts flagged fake "$CJUP" tokens airdropped to Solana wallets to impersonate Jupiter Exchange's Jupuary distribution and route recipients to a drainer [16]. CoinDCX said it had detected more than 1,212 sites impersonating its platform between April 2024 and January 2026 [17], roughly 55 a month across that 22-month window [18]. Trezor and Foundation warned this month about phishing emails pointing to a cloned Coldcard site [19].

Triage ladder, in order of damage. Connected only: disconnect the site. Granted token access: audit permissions and revoke anything unfamiliar. Signed something opaque: review recent activity and move funds to a fresh wallet if exposed. Entered a seed phrase or private key: treat the wallet as compromised [13].

What to watch: whether the kit's operators drop the fee-top-up step, which is the weakest part of the script and the one that gives careful users a second chance to leave, and whether any established screening vendor starts publishing address-only checkers with verifiable domains so staff have one bookmark instead of a search result.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories