Invest2 distinct publishers3 min readUpdated
Malwarebytes says fake crypto AML screening sites are draining wallets. The defence is unglamorous: a real basic check needs only a public address, so a connect prompt is the tell.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Malwarebytes says fake crypto AML screening sites are draining wallets. The defence is unglamorous: a real basic check needs only a public address, so a connect prompt is the tell.
Malwarebytes said in a report published Wednesday that scammers are running fake crypto anti-money-laundering checkers which prompt visitors to connect a wallet and then approve a transaction that puts their assets at risk [1]. The consequence for anyone holding client or treasury funds is that the bait is no longer a free airdrop or a presale, it is compliance, which is the one category of request that trained users are least likely to refuse.
The mechanics are cheap. A visitor picks a cryptocurrency, clicks to scan it, and is told to connect a wallet to see the result [6]. One version Malwarebytes examined runs a progress bar with messages such as "Checking wallet history..." and "Verifying compliance...", then throws a fake error asking for a small top-up to cover a fee [7]. Retry, and the animation replays before returning a soothing "Clean, Low Risk" verdict and an offer to download a report [8]. Some sites copy the branding of AMLBot, a legitimate screening service; others use generic names such as "AML Check" [2].
The useful part is the tell, and it is binary. A genuine crypto AML check reads a wallet's public transaction history for links to hacks, scams, sanctioned entities and other suspicious activity [3]. A basic check requires only the public address: no connection, no permissions, no signature [4]. As Malwarebytes researchers put it, "If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign" [5].
Connecting does not hand over keys, but it does expose the public address, which lets the operator see what assets are inside and build a transaction aimed at that specific wallet [9]. Approval is the moment the money moves [10]. Malwarebytes says transactions generally cannot be reversed once confirmed, so speed matters after a bad signature [14].
This is a product, not a stunt. Malwarebytes researcher Stefan Dasic found the same skeleton running under several names and logos, indicating the template is being rebranded and resold [11][12]. Cryptopolitan reported this month on a $500 turnkey kit sold on a cybercrime forum that builds a fake $TSLA presale, scans each visitor's wallet for valuable assets, and phishes the 12-word recovery phrase behind a 15% bonus, with an admin panel that inflates fake balances so victims keep paying [15]. In May, Solana Floor analysts flagged fake "$CJUP" tokens airdropped to Solana wallets to impersonate Jupiter Exchange's Jupuary distribution and route recipients to a drainer [16]. CoinDCX said it had detected more than 1,212 sites impersonating its platform between April 2024 and January 2026 [17], roughly 55 a month across that 22-month window [18]. Trezor and Foundation warned this month about phishing emails pointing to a cloned Coldcard site [19].
Triage ladder, in order of damage. Connected only: disconnect the site. Granted token access: audit permissions and revoke anything unfamiliar. Signed something opaque: review recent activity and move funds to a fresh wallet if exposed. Entered a seed phrase or private key: treat the wallet as compromised [13].
What to watch: whether the kit's operators drop the fee-top-up step, which is the weakest part of the script and the one that gives careful users a second chance to leave, and whether any established screening vendor starts publishing address-only checkers with verifiable domains so staff have one bookmark instead of a search result.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Malwarebytes said in a report published Wednesday that fake crypto AML checkers trick users into connecting their wallets and approving transactions, putting their digital assets at risk.
Some of the fake sites mimic the legitimate screening service AMLBot, while others use generic names such as "AML Check."
Crypto AML services check a wallet's public transaction history for links to hacks, scams, sanctioned entities and other suspicious activity.
A basic AML check requires only a wallet's public address and does not require users to connect their wallet, approve permissions, or sign a transaction.
Malwarebytes researchers wrote: "If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign."
On the fake sites, a visitor picks a cryptocurrency, clicks to scan it, and is asked to connect a wallet to see the result.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor research, two-outlet corroboration, no artefacts
The mechanism is specified precisely and consistently across both outlets — impersonated AMLBot branding, simulated progress strings, a fee-top-up error, and a connect-then-approve drain path — and one outlet names the researcher. But every primary fact traces to a single Malwarebytes report; neither publisher supplies domains, wallet addresses, transaction hashes, victim counts or loss totals, and no independent confirmation or takedown record is offered.
Template reuse evident, campaign scale unquantified
There is real evidence the pattern is spreading rather than isolated: the same skeleton appears under multiple names and logos, and the surrounding kit economy is documented via a $500 forum-sold drainer kit, the fake $CJUP airdrop scheme and CoinDCX's 1,212 impersonation domains (about 55 per month). What is missing is any count of fake AML sites, victims or funds drained, so prevalence of this specific lure cannot be sized.
Slightly ahead of the evidence on scale and resale
Headlines assert wallets are being drained and that the websites are 'stealing from crypto investors' while no confirmed theft, victim or loss figure is published, and Cryptopolitan's 'resold' framing goes beyond the reuse pattern Decrypt reports. Against that, both pieces are technically restrained, correctly note that connection alone does not surrender keys, and lead with a concrete defensive test rather than alarm, so the overstatement is modest.
Vendor threat research amplified by crypto trade press
The sole primary source is a commercial security vendor whose research output markets its detection products, and both stories are near-total restatements of that report. Cryptopolitan compounds this by sourcing its supporting context largely from its own prior articles and appending newsletter promotion and an investment disclaimer; a legitimate screening brand, AMLBot, also has a reputational interest in publicising impersonation. No party with an interest in downplaying the campaign is quoted.
Mechanism solid, scale and independence weak
Confidence is high on the actionable core — how the lure works and why an address-only check makes the connect prompt diagnostic — because two outlets describe it consistently and quote the same researcher guidance. It is materially lower on breadth: one vendor source, no indicators, no loss or victim data, one single-sourced resale claim and a minor numeric discrepancy on the CoinDCX figure (1,200 versus 1,212).
security
The connect-wallet tell: fake AML checkers turn a compliance ritual into a drain1 distinct publisher
invest
The card networks just picked the referee for agent checkout, and it looks like EMVCo2 distinct publishers
invest
Pump.fun's $12m week puts token issuance above every lending market in crypto1 distinct publisher
security
A staging password went into a Google Doc, and Google's autocomplete found it first1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026
1 article · August 20, 2026