LIVE · cybersecurity feed
Live wire
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewCVE-2026-65400 · Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationOver 500 Critical Infrastructure Organizations Hit by Medusa RansomwareMedusa ransomware gang has hit over 500 organizations, CISA warns
security

Scammers are using fake crypto AML checkers to drain your wallet

We found wallet-checking sites impersonating real anti-money laundering services that trick people into approving access to scammers.

zeroday.news ·

Cybersecurity researchers have identified a new scam targeting cryptocurrency users, employing fake anti-money laundering (AML) checking websites to trick individuals into compromising their digital wallets. These fraudulent sites mimic legitimate services, often copying the branding and layout of established platforms like AMLBot, to appear credible.

The scam operates by luring users to seemingly professional websites that promise to verify if a crypto wallet is linked to illicit activities. While legitimate AML checks only require a wallet's public address for a lookup, these fake sites prompt users to "connect" their wallets. Although merely connecting a wallet does not immediately grant access to funds, it allows the scammers to view the user's public address and associated assets.

Once connected, the fraudulent site generates a transaction tailored to the victim's wallet, which is then sent for approval. The sites are designed to manipulate users into authorizing this unexpected transaction. In one observed variant, the process includes a fake progress bar displaying messages such as "Checking wallet history…" and "Verifying compliance…". This is followed by a fabricated error message claiming a small "fee" is required to complete the check. After a user clicks "Retry," the site displays a reassuring "Clean, Low Risk" result and offers a report, regardless of whether a genuine check occurred or a fee was "paid."

The deceptive design, including progress animations, error messages, and a final "clean" result, is intended to make the process appear legitimate and exploit users' desire for security. Researchers note that the same basic design and process have been observed under various names and logos, suggesting a common scam template is being reused.

Users are advised to exercise extreme caution when using any wallet-checking service. Key indicators of a fraudulent site include requests to connect a wallet, approve unexpected token access, confirm a transaction, send cryptocurrency to complete a check, or share a recovery phrase or private key. A legitimate AML screening service will only ever require a public wallet address.

If a user has only connected their wallet to a suspicious site, they should immediately disconnect it. If token permissions were approved, users should check their wallet for unrecognized permissions and revoke them. If a transaction was confirmed or an unknown signature provided, users should review recent wallet activity and consider moving remaining funds to a new wallet. Entering a recovery phrase or private key on such a site means the wallet is compromised, and all assets should be moved to a new wallet with a new recovery phrase. Downloading anything from these sites should be avoided; if a download occurred, the file should be deleted, and a malware scan performed.

Confirmed domains associated with this scam include amlbot-clear[.]com, audittrust[.]shop, bitget-aml[.]com, search-aml[.]net, and swapstoken[.]app. Users are warned that cryptocurrency transactions are generally irreversible, emphasizing the importance of quick action if suspicious activity is detected. Furthermore, individuals who have lost funds should be wary of "recovery scams" that target victims with promises of retrieving stolen crypto for a fee.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OpenAI confirms ChatGPT is down as logins and signups fail

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]