Cybersecurity researchers have identified a new scam targeting cryptocurrency users, employing fake anti-money laundering (AML) checking websites to trick individuals into compromising their digital wallets. These fraudulent sites mimic legitimate services, often copying the branding and layout of established platforms like AMLBot, to appear credible.
The scam operates by luring users to seemingly professional websites that promise to verify if a crypto wallet is linked to illicit activities. While legitimate AML checks only require a wallet's public address for a lookup, these fake sites prompt users to "connect" their wallets. Although merely connecting a wallet does not immediately grant access to funds, it allows the scammers to view the user's public address and associated assets.
Once connected, the fraudulent site generates a transaction tailored to the victim's wallet, which is then sent for approval. The sites are designed to manipulate users into authorizing this unexpected transaction. In one observed variant, the process includes a fake progress bar displaying messages such as "Checking wallet history…" and "Verifying compliance…". This is followed by a fabricated error message claiming a small "fee" is required to complete the check. After a user clicks "Retry," the site displays a reassuring "Clean, Low Risk" result and offers a report, regardless of whether a genuine check occurred or a fee was "paid."
The deceptive design, including progress animations, error messages, and a final "clean" result, is intended to make the process appear legitimate and exploit users' desire for security. Researchers note that the same basic design and process have been observed under various names and logos, suggesting a common scam template is being reused.
Users are advised to exercise extreme caution when using any wallet-checking service. Key indicators of a fraudulent site include requests to connect a wallet, approve unexpected token access, confirm a transaction, send cryptocurrency to complete a check, or share a recovery phrase or private key. A legitimate AML screening service will only ever require a public wallet address.
If a user has only connected their wallet to a suspicious site, they should immediately disconnect it. If token permissions were approved, users should check their wallet for unrecognized permissions and revoke them. If a transaction was confirmed or an unknown signature provided, users should review recent wallet activity and consider moving remaining funds to a new wallet. Entering a recovery phrase or private key on such a site means the wallet is compromised, and all assets should be moved to a new wallet with a new recovery phrase. Downloading anything from these sites should be avoided; if a download occurred, the file should be deleted, and a malware scan performed.
Confirmed domains associated with this scam include amlbot-clear[.]com, audittrust[.]shop, bitget-aml[.]com, search-aml[.]net, and swapstoken[.]app. Users are warned that cryptocurrency transactions are generally irreversible, emphasizing the importance of quick action if suspicious activity is detected. Furthermore, individuals who have lost funds should be wary of "recovery scams" that target victims with promises of retrieving stolen crypto for a fee.






