Invest2 publishers3 min readPublished
The compliance-flavoured drainer: fake AML checkers that need your signature, not your address
Malwarebytes says fake crypto AML screening sites are draining wallets. The defence is unglamorous: a real basic check needs only a public address, so a connect prompt is the tell.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Malwarebytes said in a report published Wednesday that fake crypto AML checkers trick users into connecting their wallets and approving transactions, putting their digital assets at risk.
- Some of the fake sites mimic the legitimate screening service AMLBot, while others use generic names such as "AML Check."
- Crypto AML services check a wallet's public transaction history for links to hacks, scams, sanctioned entities and other suspicious activity.
- A basic AML check requires only a wallet's public address and does not require users to connect their wallet, approve permissions, or sign a transaction.
- Malwarebytes researchers wrote: "If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign."
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Malwarebytes said in a report published Wednesday that scammers are running fake crypto anti-money-laundering checkers which prompt visitors to connect a wallet and then approve a transaction that puts their assets at risk [1]. The consequence for anyone holding client or treasury funds is that the bait is no longer a free airdrop or a presale, it is compliance, which is the one category of request that trained users are least likely to refuse.
The mechanics are cheap. A visitor picks a cryptocurrency, clicks to scan it, and is told to connect a wallet to see the result [6]. One version Malwarebytes examined runs a progress bar with messages such as "Checking wallet history..." and "Verifying compliance...", then throws a fake error asking for a small top-up to cover a fee [7]. Retry, and the animation replays before returning a soothing "Clean, Low Risk" verdict and an offer to download a report [8]. Some sites copy the branding of AMLBot, a legitimate screening service; others use generic names such as "AML Check" [2].
The useful part is the tell, and it is binary. A genuine crypto AML check reads a wallet's public transaction history for links to hacks, scams, sanctioned entities and other suspicious activity [3]. A basic check requires only the public address: no connection, no permissions, no signature [4]. As Malwarebytes researchers put it, "If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign" [5].
Connecting does not hand over keys, but it does expose the public address, which lets the operator see what assets are inside and build a transaction aimed at that specific wallet [9]. Approval is the moment the money moves [10]. Malwarebytes says transactions generally cannot be reversed once confirmed, so speed matters after a bad signature [14].
This is a product, not a stunt. Malwarebytes researcher Stefan Dasic found the same skeleton running under several names and logos, indicating the template is being rebranded and resold [11][12]. Cryptopolitan reported this month on a $500 turnkey kit sold on a cybercrime forum that builds a fake $TSLA presale, scans each visitor's wallet for valuable assets, and phishes the 12-word recovery phrase behind a 15% bonus, with an admin panel that inflates fake balances so victims keep paying [15]. In May, Solana Floor analysts flagged fake "$CJUP" tokens airdropped to Solana wallets to impersonate Jupiter Exchange's Jupuary distribution and route recipients to a drainer [16]. CoinDCX said it had detected more than 1,212 sites impersonating its platform between April 2024 and January 2026 [17], roughly 55 a month across that 22-month window [18]. Trezor and Foundation warned this month about phishing emails pointing to a cloned Coldcard site [19].
Triage ladder, in order of damage. Connected only: disconnect the site. Granted token access: audit permissions and revoke anything unfamiliar. Signed something opaque: review recent activity and move funds to a fresh wallet if exposed. Entered a seed phrase or private key: treat the wallet as compromised [13].
What to watch: whether the kit's operators drop the fee-top-up step, which is the weakest part of the script and the one that gives careful users a second chance to leave, and whether any established screening vendor starts publishing address-only checkers with verifiable domains so staff have one bookmark instead of a search result.