Malwarebytes warns fake crypto AML checkers seek wallet transaction approvals

Cybersecurity firm Malwarebytes has warned that fake crypto AML (anti-money-laundering) checkers are targeting investors by asking them to connect wallets and approve transactions. Genuine screening requires only a wallet’s public address and reviews its transaction history for links to hacks, thefts, sanctioned parties or other suspicious activity. The fraudulent sites imitate services such as AMLBot or use generic names including AML Check, then display fake verification steps, request a small top-up to cover a supposed fee and may return a reassuring Clean, Low Risk result. Malwarebytes researcher Stefan Dasic said the same scam kit is being rebranded and resold under different names and logos. A $500 kit reported by Cryptopolitan creates a fake $TSLA presale, identifies valuable wallet assets and phishes for 12-word recovery phrases by offering a 15% bonus, while a separate Solana scheme used fake $CJUP tokens to redirect users to a drainer site. CoinDCX said it detected 1,212 websites impersonating its platform between April 2024 and January 2026, and Mumbai police registered an FIR over fraud involving an impersonating website. Users who only connected a wallet should disconnect it; those who granted token permissions should revoke unfamiliar approvals, while anyone who signed an unexplained transaction, or entered a recovery phrase or private key, should review activity and move exposed funds to a new wallet.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.