BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Guides

Fake AML Checks for Crypto Wallets: How to Spot the Scam Sites

A legitimate AML check on a crypto address needs exactly one thing from you: the public address. It needs no access to your wallet, no connection, no signature and certainly no advance paymen

AnonymousCryptoCompass newsroom
August 31, 2026
15 min read
NEWS
Fake AML Checks for Crypto Wallets: How to Spot the Scam Sites
CryptoCompass editorial visual for guides coverage.

A legitimate AML check on a crypto address needs exactly one thing from you: the public address. It needs no access to your wallet, no connection, no signature and certainly no advance payment. Anyone who asks you to connect your wallet for a money-laundering check is not running a check at all. That is exactly what a wave of fraud relies on, described by the security firm Malwarebytes on August 19, 2026, with infrastructure that our own measurement found still running twelve days later.

Fake AML check: what Malwarebytes found in August 2026

Stefan Dasic, a malware researcher at Malwarebytes, has documented a series of websites that pose as screening services for crypto addresses. They imitate the legitimate provider AMLBot or operate under colorless generic names such as "AML Check". The setup is similar in every case: you select a cryptocurrency, click a button labeled "Check Wallet", and are then asked to connect your wallet.

From that point on the site is no longer a screening tool. It is a stage. A progress bar runs, accompanied by status messages such as "Checking wallet history…" and "Verifying compliance…". Then comes an invented error message: the check cannot be completed, the balance is too low, a small top-up is needed to cover the fee. Click "Retry" and you see the same animation once more, followed by a reassuring result, usually a "Clean, Low Risk".

That result is pure invention. There is no check, no database query and no assessment. What there is, is a connection between your wallet and someone else's website, and that connection is the real purpose of the whole arrangement.

AML check explained: why a wallet address gets screened at all

AML stands for anti-money laundering. An AML check for crypto is a report on whether a public blockchain address has been connected in the past to suspicious counterparties, for example a hacked trading venue, a mixing service or a sanctioned address. Providers of such reports evaluate publicly visible transaction data and assign addresses to known actors.

The decisive part of that definition is already in the word "public". Everything such a report needs is lying in the open on the blockchain anyway. The address is the key to the query, and the address is a string of characters that you can copy and paste into a field. Access to your balance is no more necessary for this than a power of attorney over a bank account is necessary to request a public land registry extract.

Why do retail investors care in the first place? Because an address flagged as suspicious can cause trouble. Deposit funds at a regulated trading venue and you may face a query from the compliance department, and in the worst case a withdrawal is delayed until the origin of the funds has been clarified. That worry is real, and it is the lever the scam sites pull.

How to recognize a genuine screening page

A legitimate report requires an input field and nothing else. You paste in the address, you get an assessment, and your wallet software is not opened once during the entire process. If your wallet's connection window appears instead, the check is already over at that moment, and not in your favor. Malwarebytes puts it as a plain rule of thumb: anyone demanding a wallet connection instead of the public address is a warning sign.

Enter an address or connect a wallet: the one difference that decides everything

Two actions that look similar in a browser have fundamentally different consequences. Entering an address is a read operation. You hand over information that every blockchain explorer displays anyway, and the other side can do nothing with it that it could not do without you.

Connecting a wallet is something else. Doing so permits a website to talk to your wallet software. The site then sees your address and your balance, and above all it may present transactions to you for confirmation. It cannot trigger those transactions itself, but it can prepare and label them so that a single click from you is enough. A wallet's security architecture is incorruptible at this point: it executes what you approve.

That is why the documented sites build their staging so carefully. They need no vulnerability in your wallet. They need a moment in which a confirmation window looks to you like a normal step in a security check. Once you grasp that you believe yourself to be in a screening process while you are in fact signing a power of attorney, the trick is seen through.

Two service windows in a dark counter: on the left a narrow letter slot for a slip of paper, on the right an open hatch through which a bunch of keys and coins bearing the Bitcoin symbol disappear A typed address fits through the letter slot. A connected wallet opens the whole hatch.

How the scam site works: from the progress bar to the alleged fee

The order of the steps is no accident, it follows a dramaturgy. First comes the choice of cryptocurrency, a harmless act that builds trust and pulls you into a sequence of clicks. Then follows the connection, which seems plausible in the context of a supposed check. Only after that does the actual manipulation begin.

The progress bar serves two purposes. It makes the site appear to work where nothing is working, and it buys the other side time to look at your address and prepare a suitable transaction. What is then put in front of you is tailored to your balance. The subsequent error message about a missing fee is the pretext meant to justify a payment or an approval. And the closing "Clean, Low Risk" makes sure you leave the site reassured, without checking what you confirmed along the way.

What is remarkable about this scheme is whom it hits. It does not target carelessness, it targets caution. Anyone looking for an AML check has already given thought to how clean their address is. That audience is better informed than average, and it arrives of its own accord, without an attacker having to write to it.

Token approval instead of a password: how the outflow works technically

In an attack of this kind no password and no recovery phrase is lost. The usual route runs through a token approval. An approval is a permission you grant to a third-party address to move a particular kind of token out of your wallet. That permission is necessary in everyday use, every decentralized exchange needs it, and it remains in place until you revoke it.

The danger lies in the amount and in the duration. Many approvals are granted without a limit, because that is convenient and because the confirmation window does not always display the amount in an understandable way. An unlimited approval, once granted, keeps working after you have long closed the site, after a restart of your computer, and even when you disconnect the site in your wallet menu. Disconnecting ends the channel of conversation; it does not withdraw the power of attorney.

What such a confirmation looks like in the window, and which fields you should read before clicking, we described in detail in our article on wallet drainers and signature approvals. If there is a single technical skill to take away from this subject, it should be that one. On a chain such as Ethereum and the networks compatible with it, the approval is the standard mechanism by which balances change hands without any key having to be stolen.

What an approval technically permits

An approval names three things: which token it covers, which third-party address may dispose of it, and up to what amount. If the amount limit is missing, the third-party address may withdraw the entire holding of that token, at any time and without asking you again. Wallets with a good interface show you these three details in plain language. Older or plainly designed confirmation windows show you a string of characters, and that is precisely what the operators of such sites count on.

Our own survey: three of the five named domains still respond twelve days later

This analysis was carried out by cryptoticker.io itself on August 31, 2026. Method: we checked the five domains that Malwarebytes names explicitly in its report once on August 31, 2026 at 03:53 UTC, by HTTP request and by name resolution, and recorded the response code. Five domains from the report were checked, plus the domain of the imitated legitimate provider as a reference value, so six objects in total.

The result: two of the five domains can no longer be resolved, their name entries have vanished. Two more respond with code 200 and therefore serve a page. A fifth responds with code 403 and rejects our automated request, but has an active name entry and a responding server. Sorted by name: amlbot-clear[.]com responds, bitget-aml[.]com responds, swapstoken[.]app rejects, audittrust[.]shop and search-aml[.]net can no longer be resolved. The domain of the genuine provider also responds, as expected.

What these figures mean, and what they do not: we measured reachability only, that is, whether a server responds under the name. We did not open the pages served, did not assess their content and therefore did not establish whether the described scheme is still running there, whether a parking page stands in its place or whether a third party has taken the domain over. Nor can we say how many people visited the sites in that period or what damage was caused. Only one statement is solid: twelve days after the public warning, the infrastructure named there has not been fully cleared away. For you as a reader that is the relevant measure, because a warning whose targets have long been offline would be history. This one is not.

Imitated names: what a domain says about a company

One of the domains named combines the name of a well-known trading platform with the abbreviation AML. That deserves a clear classification, because a domain can be chosen freely, and whoever registers it needs neither the permission nor the knowledge of the name's owner. Nothing about a company itself follows from its name appearing in an address bar. On the contrary: firms whose names are used in this way are victims of the scheme, because trust they built over years is turned into a tool against their own customers. That applies here to the imitated screening platform just as much as to the trading platform whose name appears in one of the domains.

In practice that means this for you: a familiar name in a web address is not a seal of approval. What counts is the complete address line, and what counts above all is how you arrived at the page. A link from a message, from a post on a social network or from a paid search ad deserves more suspicion on principle than a bookmark you set yourself.

Why the scheme falls on prepared ground in Germany

Since the beginning of 2026, German investors have been asked by their providers for documentation in a way that was previously unusual. With the implementation of the EU directive DAC8, crypto service providers have had to identify their customers, record transactions and obtain tax self-declarations since January 1, 2026. Anyone who fails to respond is reminded, then warned, and the provider can restrict accounts.

That creates a habituation worth its weight in gold to fraudsters. Demands for documentation, checks and confirmations currently sound less like an alarm signal than like administrative routine. A site offering a money-laundering check fits that picture, and the thought "I suppose I have to do this" comes more readily than it did a year ago. We observed a similar pattern with the crypto job offers involving your own bank account, where an official-sounding procedure likewise provided the frame for the actual damage.

It helps to make the difference clear to yourself once. When your trading venue wants something from you, you find that request inside your account after logging in. No regulated provider sends you to a third-party website to fulfill an obligation, and none demands a wallet connection for it. Where these obligations are actually laid down, and which providers operate under European supervision, you can read in our overview of regulated crypto exchanges.

Checking and revoking token approvals: how to proceed

The most effective step after an unclear encounter with such a site is to review the approvals you have granted. Every major chain has an area in its blockchain explorer where you enter your address and get a list of all open approvals together with the authorized counterpart address. A revocation is an ordinary transaction and costs the usual network fee.

Work through the list calmly and watch for two things: unlimited amounts, and counterpart addresses you cannot assign to any transaction of yours. An approval whose occasion you no longer remember is a candidate for revocation, even if nothing has happened so far. The effort is small; the possible damage is not.

Where you keep your keys also determines how expensive a mistaken click can become. An overview of the devices and how they are operated can be found in our hardware wallet comparison; anyone working without an additional device will find in the software wallet comparison the differences in how confirmation windows are displayed, and that display is precisely the security-relevant point here.

After a confirmed transaction: why disconnecting alone is not enough

Suppose you have confirmed and notice it shortly afterwards. Then the order of your steps matters more than their speed. Disconnecting in the wallet menu is sensible, but it is the smallest of the steps, because it leaves the granted power of attorney untouched. More important is revoking the approval, and more important still is the question of whether only an approval was granted or a recovery phrase was entered.

If an approval was granted, revoking it is usually enough. If, on the other hand, a recovery phrase or a private key was typed in somewhere, the wallet is permanently lost, and the remaining balance belongs on a freshly created wallet with a new recovery phrase. A recovery phrase knows no revocation; it can only be replaced.

You should be prepared for what comes next: offers of supposed recovery. Anyone approached in forums or by message after an incident, promising to retrieve funds against an advance payment, is running the second stage of the same scheme. Confirmed transactions on a blockchain are final, and nobody can reverse them for a fee.

Metal vending machine with a coin slot whose back panel is missing: the coin bearing the Bitcoin symbol falls straight through without reaching a cash box and lands in a bucket on the floor The fee demanded for the supposed check ends up nowhere it could achieve anything.

Separate wallets and small amounts: what limits the damage

No single measure fully protects against a mistaken click, but splitting your holdings helps reliably. Anyone who keeps the largest part of their balance on an address that is never connected to a website can experiment calmly without risking everything. A second address with a manageable amount then handles contact with applications, and any damage stays limited to that amount.

A hardware device strengthens this effect, because it moves the confirmation to a display outside the computer. It is still no free pass: even with a hardware wallet you grant an approval when you confirm it on the device. The gain lies in the fact that the details appear there in a form a manipulated website cannot overwrite. Anyone who reads that display, instead of pressing the same button twice, has done the greater part of the work.

Recurring approval reviews: when a check makes sense

Approvals accumulate without being noticed. Every application you use leaves one behind, and after two years of use an active address easily carries several dozen open powers of attorney. Many of them belong to projects that no longer exist, and an abandoned application is an attractive target for a takeover by third parties.

A review twice a year is a sensible measure, plus one after any unusual event: after visiting a site you reached through someone else's link, after a confirmation whose purpose you cannot recall afterwards, and after every report of a compromised application you have used yourself. The time required is a few minutes, once you know the procedure.

Spotting a fake AML check: what to take away

  1. Remember the dividing line. A genuine check on a crypto address asks only for the public address in an input field. As soon as a supposed screening service asks you to connect your wallet, confirm a transaction or advance a fee, stop. If you are unsure where such checks are handled by the provider anyway, our overview of regulated crypto exchanges helps.
  2. Review your open approvals. Open your chain's blockchain explorer, enter your address and revoke every unlimited or unexplained approval. How to read a confirmation window properly beforehand, so that no new ones are added in the first place, is set out in the software wallet comparison and in our article on signature approvals.
  3. Separate storage from use. Keep the larger part of your holdings on an address that is never connected to a website, and use a second address for applications with an amount whose loss you could cope with. Which devices support this separation and how they are operated is shown in the hardware wallet comparison.

The sources for this article: the report by Malwarebytes of August 19, 2026 and the independent write-up at Decrypt of August 20, 2026. The reachability measurement of the named domains comes from cryptoticker.io.

(As of August 31, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)