BTCETHBNBSOLXRPUSDCTRXADADOGE
Data by CoinGecko
Scam WatchBearish

Phishing Sites Disguised as Security Tools Drain Wallets

Scammers are launching fake anti-money laundering (AML) detection websites to trick cryptocurrency users into authorizing malicious transactions. The campaign relies heavily on the fear of holding tainted funds, prompting victims to unnecessarily connect their Web3 wallets to fraudulent platforms under the guise of routine compliance checks.

Cybersecurity firm Malwarebytes identified a network of these phishing pages masquerading as legitimate compliance tools. The malicious sites impersonate known services like AMLBot, while others operate under generic brands such as "AML Check." The attackers use simulated progress bars, fabricated error codes, and fake diagnostic messages to convince users that a real on-chain scan is taking place in the background.

Exploiting Compliance Fears

In a report published Wednesday, Malwarebytes detailed how one fraudulent site prompted users to deposit a small upfront fee before displaying a fabricated “Clean, Low Risk” status, regardless of the wallet's actual history. The threat intelligence platform Mallory highlighted that the ongoing campaign utilized at least five specific malicious domains, including amlbot-clear.com and bitget-aml.com, to deceive unsuspecting victims.

The environment is highly susceptible to such exploits, as digital asset holders are already on high alert regarding stolen funds and smart contract vulnerabilities. According to data from DeFiLlama, decentralized finance protocols lost more than $840 million to hacks in the first five months of 2026 alone. Furthermore, blockchain analytics firm Whale Alert recently confirmed a separate incident where a single Ethereum user lost 810 ETH to a phishing frontend. These massive losses underscore the devastating financial impact of social engineering tactics in the broader decentralized ecosystem.

Phishing Sites Disguised as Security Tools Drain Wallets
If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign,

Technical Caveats and Red Flags

The core deception of the AML checker scam relies on a fundamental misunderstanding of how blockchain analysis actually works. Legitimate services do not need direct access to a user's private keys or signature permissions to read public ledger data.

"If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign," Malwarebytes researchers wrote in their latest advisory.

Jason Nelson, a reporter at Decrypt, offered an important technical caveat regarding the exact attack vector. He noted that connecting a wallet alone does not automatically allow scammers to steal funds. Instead, the initial connection merely exposes the wallet's public address and total assets. This visibility enables the attackers to craft a custom, malicious smart contract transaction, which they then present for the victim to unknowingly approve.

According to a report from crypto news outlet Odaily, a legitimate AML check never requires a user to sign transactions, approve token spending permissions, or interface their wallet software directly with a third-party application. Security analysts strongly advise anyone who has interacted with these counterfeit checkers to immediately revoke all active token permissions and transfer their remaining assets to a newly generated wallet to prevent total asset loss.

← All stories