Security1 distinct publisher3 min readUpdated
Malwarebytes describes counterfeit crypto screening sites that ask visitors to connect a wallet. Real screening needs only a public address, which makes the prompt itself the attack.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Malwarebytes describes counterfeit crypto screening sites that ask visitors to connect a wallet. Real screening needs only a public address, which makes the prompt itself the attack.
A crop of counterfeit crypto wallet-screening sites is promising to tell visitors whether an address is linked to suspicious activity, and then trying to trick them into handing over access to their funds, according to Malwarebytes [1]. That matters because the victims are self-selecting for caution: the people who go looking for an anti-money-laundering check are the people trying to protect themselves, and the scam dresses each step up as part of a normal security review [14].
The useful part of this write-up is that the tell is mechanical, not aesthetic. AML screening in crypto means checking whether an address has links to hacks, scams, sanctioned entities or other suspicious activity, based on its transaction history [3]. For a basic check, the service needs the public address and nothing else: no wallet connection, no approval, no signature [4]. Malwarebytes puts it plainly: if a checker asks you to connect your wallet rather than enter the public address, treat that as a warning sign [5]. That is a one-line rule an awareness programme can ship this week, because it does not depend on spotting a good forgery. And the forgeries are decent, with many sites impersonating the legitimate service AMLBot or trading under names such as "AML Check", copying the logo, layout and language [6].
The flow is short: pick your cryptocurrency, click Check Wallet, connect [7]. Connecting on its own does not move funds; what it does is reveal the public address, which the operators use to build a transaction aimed at that specific wallet and push it back for approval [8]. Knowing the address also lets them see the assets held there and size the request accordingly [10]. The objective throughout is a victim-signed transaction the victim does not understand and was not expecting [9].
Then comes the theatre. One version Malwarebytes reviewed runs a progress bar with lines such as "Checking wallet history..." and "Verifying compliance...", stalls on a fake error saying the wallet needs a small top-up to cover a fee, and on Retry replays the same animation before returning a reassuring "Clean, Low Risk" verdict and a downloadable report, whether or not any check happened [11][12].
Triage depends on how far someone got. Connected only: disconnect the site [15]. Approved token access: review token permissions and revoke the ones you do not recognise, using your wallet provider's approval checker if it has one [16]. Signed or confirmed something: check recent activity and move remaining funds to a new wallet [17]. Entered a recovery phrase or private key: treat the wallet as compromised and move assets to a new wallet with a new phrase [18]. Downloaded a file: do not open it, delete it, scan [19]. Speed matters because confirmed crypto transactions generally cannot be reversed [20].
Two things to watch. First, reuse: the same basic design and process has surfaced under several names and logos, which points to a shared template being rebranded rather than a single site to block [13]. Second, the second wave. Anyone who has already lost money should expect contact from people offering recovery for a fee, since recovery scams routinely target prior victims [21]. In the meantime, check the address bar carefully, particularly if you arrived via an ad, a social post, a message or a search result [22].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Scammers are creating fake crypto wallet-checking sites that promise to tell you whether a wallet is linked to suspicious activity, and instead try to trick you into giving them access to your crypto.
In crypto, AML checking usually means checking whether a wallet address has links to hacks, scams, sanctioned entities, or other suspicious activity based on its transaction history.
For a basic wallet check, the service only needs the wallet's public address; you do not need to connect your wallet, approve anything, or sign a transaction. It is just a lookup.
Malwarebytes: if an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign.
Many of the fake sites pretend to be the legitimate service AMLBot, or use names such as "AML Check", copying the logo, layout, and language of legitimate wallet-screening services.
On the fake sites you are invited to choose your cryptocurrency, click Check Wallet, and connect your wallet to get your results.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-party sample review with named indicators, single publisher
Malwarebytes reports hands-on review of at least one live site, with specific UI strings, a described fee-error and clean-verdict flow, an identified impersonation target, and five checkable indicator domains. That is concrete and falsifiable. It is nonetheless one vendor's account with no screenshots-of-record cited by third parties, no observation window and no corroborating publisher in the cluster.
Confirmed in the wild, scale unquantified
Adoption here means attacker uptake of the technique. There is evidence of real deployment - five live indicator domains and the same template rebranded under several names and logos - but the source gives no counts of sites, victims, funds lost, traffic sources or duration, so breadth cannot be graded above 'present and recurring'.
Mechanism claims restrained, scale language outruns disclosed data
The body is unusually careful - it explicitly says connecting a wallet alone cannot steal funds and locates the theft at user approval - which pulls the piece toward alignment. The mild overstatement comes from a 'drain your wallet' framing and 'many pretend to be AMLBot' phrasing that imply prevalence the article never quantifies, plus a closing product pitch.
Security vendor advisory that closes on its own product
The publisher sells consumer security software and the post recommends Malwarebytes Browser Guard as mitigation, with an install call to action. That is a direct commercial interest in the threat being seen as urgent, though the technical content is specific and the indicator list is useful independent of the product.
Credible single-source threat intel, unverified breadth
The mechanism and remediation guidance are consistent with well-understood wallet-drainer behaviour and are supported by first-party review plus verifiable domains, so the core of the story is reliable. Confidence is capped by having only one publisher, no independent confirmation, no response from the impersonated service, and no quantification of the campaign.
invest
The compliance-flavoured drainer: fake AML checkers that need your signature, not your address2 distinct publishers
security
A staging password went into a Google Doc, and Google's autocomplete found it first1 distinct publisher
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
product
The criminal AI market is a reseller business, and Grok's abuse desk is the chokepoint1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026