Cybersecurity company Malwarebytes has alerted crypto holders to a surge in fraudulent anti-money laundering (AML) websites posing as legitimate services. These fake sites are designed to dec
Cybersecurity company Malwarebytes has alerted crypto holders to a surge in fraudulent anti-money laundering (AML) websites posing as legitimate services. These fake sites are designed to deceive users into connecting their wallets and approving transactions that compromise the safety of their digital assets.
Malwarebytes reported that scammers have been setting up sites that closely mimic well-known crypto AML services, including platforms such as AMLBot. Other fake sites operate under generic titles such as “AML Check.” The goal is to convince users that they are interacting with reputable services capable of verifying whether their accounts have been exposed to stolen or illicit funds.
A genuine AML service typically only requires the entry of a wallet’s public address to scan its transaction history for links to hacks, sanctions, or suspicious activity. Malwarebytes clarified that legitimate checks never require wallet connections, approval of permissions, or transaction signatures from the user.
The cybersecurity firm said false AML sites trick users into connecting their crypto wallets under the pretense of conducting a scan. The sites present fake progress indicators and fabricated results, sometimes displaying a “Clean, Low Risk” status regardless of any actual investigation. In several cases, users are prompted to make a small payment to cover an alleged fee before being shown reassuring but meaningless results.
“If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign,” Malwarebytes researchers advised.
While connecting a wallet does not permit the scammers to immediately drain funds, it enables them to view the wallet’s assets and initiate a transaction which the victim might then approve. The report noted that the same website template, with minor branding alterations, has been reused across multiple fake platforms—a sign of coordinated activity targeting the crypto community.
Mini dictionary: Malwarebytes, a cybersecurity firm known for its malware detection and protection software, often publishes research exposing new online threats and scams targeting internet users.
Rise in phishing campaigns targeting crypto users
Experienced crypto holders have seen similar scams before, but Malwarebytes stated that a wave of recent phishing campaigns and fake websites is targeting both new and existing users. Earlier this month, hardware wallet companies Trezor and Foundation issued warnings after phishing emails led users to a cloned Coldcard site. In March, Malwarebytes also identified a fraudulent version of the Pudgy Penguins’ Pudgy World game, created to steal wallet passwords.
Data from crypto exchange CoinDCX indicated more than 1,200 fake websites impersonating its platform were identified between April 2024 and January 2026, underlining the scale of the threat facing crypto users.
IncidentFake Websites DetectedPeriodCoinDCX phishing clones1,200+Apr 2024 – Jan 2026
Malwarebytes advised users who have mistakenly approved token access on suspicious sites to promptly revoke those permissions. However, if someone has entered a recovery phrase or private key, they should consider the security of their wallet compromised and move their assets to new accounts immediately.
Crypto transactions cannot be reversed once confirmed, meaning swift action is essential for those who suspect they’ve approved a malicious transaction, according to Malwarebytes.
The persistence of these coordinated scams underscores the growing sophistication of phishing tactics in the crypto space. Users are urged to remain vigilant, only use trusted verification platforms, and closely scrutinize requests for wallet access or additional payments.
The post Malwarebytes warns of fake AML crypto sites targeting wallet permissions appeared first on COINTURK NEWS.