Fake anti money laundering screening websites are stealing from crypto investors.

These websites prompt users to connect a wallet and sign a transaction, which is not required for any genuine wallet check. Malwarebytes discovered the attack this week.

Real wallet screening needs only the public address

Banks and regulated firms have to check under anti-money laundering rules that their customers have no links to crime.

In crypto, that screening means looking at a wallet address’s public transaction history for contact with hacks, thefts, sanctioned parties, or other suspicious activity.

The fraudulent sites take that idea and turn it into a weapon, according to Malwarebytes researcher Stefan Dasic.

Some copy the branding of AMLBot, a legitimate screening service. Others run under generic names like “AML Check.”

A visitor picks a cryptocurrency, clicks to scan it, and is asked to connect a wallet to see the result.

One version that Malwarebytes examined displays a progress bar with messages like “Checking wallet history…” and “Verifying compliance…” before displaying a fake error that asks for a small top-up to “cover the fee.”

Tap retry, and the animation runs again before handing back a soothing “Clean, Low Risk” verdict and an offer to download a report.

A genuine basic screening requires only the wallet’s public address. It’s a lookup, and there’s no signing, permissions granted, or wallet connecting.

“If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign,” the Malwarebytes team wrote.

Connecting a wallet does not hand over the keys, but it does expose the public address. This allows the operators to see what assets are inside and build a transaction targeted at that particular wallet.

That transaction is then sent to the victim to approve. Approval is the moment the money moves.

Researchers advise against confirming an unexpected transaction.

Malwarebytes has discovered the same skeleton being used under different names and logos. The kit is being rebranded and resold.

A $500 kit phishes recovery phrases behind a 15% bonus

This month, Cryptopolitan reported on a $500 turnkey kit available on a cybercrime forum. This kit creates a fake $TSLA presale and scans each visitor’s wallet for valuable assets.

It then attempts to phish for the 12-word recovery phrase by offering a 15% bonus. Its admin panel inflates fake balances at will so that the victims keep paying.

In May, Solana Floor analysts spotted a scheme that flooded Solana wallets with fake “$CJUP” tokens impersonating Jupiter Exchange’s Jupuary airdrop and redirecting recipients to a drainer site, as Cryptopolitan reported at the time.

CoinDCX said it has detected more than 1,212 fake websites impersonating its platform between April 2024 and January 2026. Mumbai police have registered an FIR against fraud being perpetrated through a website impersonating CoinDCX.

Malwarebytes advised that anyone who only connected a wallet should disconnect the site. Anyone who gave a token permission to access their wallet should check for unfamiliar permissions and revoke them.

Anyone who signed something they didn’t understand should review recent activity and, if funds are exposed, move everything to a new wallet. Anyone who entered a recovery phrase or private key should assume the wallet is compromised.