Fake Crypto AML Checkers Drain Wallets as Scammers Use Trust to Their Advantage
Scammers are creating convincing fake anti-money laundering (AML) screening sites to trick cryptocurrency users into draining their wallets. These fake sites impersonate legitimate crypto compliance services, making it hard for users to distinguish them from real ones.
The scammers use the logos, layouts, and language of their legitimate counterparts like AMLBot or AML Check to make their fake sites look real. They convince users to connect their wallets or approve malicious token permissions, which allows attackers to transfer assets. According to Malwarebytes researchers, simply revealing a public wallet address doesn't give an attacker control of the funds, but signing or approving a malicious transaction does.
Patrick Harr, CEO at DataVisor, notes that scammers can weaponize trust effectively, and Robert Coles, senior manager of threat intelligence security at Black Duck, agrees that this is a 'trust problem' rather than a technical issue. Jason Soroko, senior fellow at Sectigo, explains that no legitimate AML screening service needs a private key, recovery phrase, or permission to spend tokens.
Malwarebytes researchers have found that the same scam template is being reused and rebranded under different names and logos, making it harder for users to identify fake sites. As AI enables fraudsters to create convincing fake websites in minutes, financial institutions need real-time, cross-channel intelligence to identify coordinated social-engineering scams.