Fake AML Checks for Crypto Wallets: How to Spot the Scam Sites
Fraudulent websites pose as money-laundering screening services for crypto addresses and ask you to connect your wallet. A genuine check needs only the public address, and three of the domains named by Malwarebytes still respond twelve days later.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
A legitimate AML check on a crypto address needs exactly one thing from you: the public address. It needs no access to your wallet, no connection, no signature and certainly no advance payment. Anyone who asks you to connect your wallet for a money-laundering check is not running a check at all. That is exactly what a wave of fraud relies on, described by the security firm Malwarebytes on August 19, 2026, with infrastructure that our own measurement found still running twelve days later.
Fake AML check: what Malwarebytes found in August 2026
Stefan Dasic, a malware researcher at Malwarebytes, has documented a series of websites that pose as screening services for crypto addresses. They imitate the legitimate provider AMLBot or operate under colorless generic names such as "AML Check". The setup is similar in every case: you select a cryptocurrency, click a button labeled "Check Wallet", and are then asked to connect your wallet.
From that point on the site is no longer a screening tool. It is a stage. A progress bar runs, accompanied by status messages such as "Checking wallet history…" and "Verifying compliance…". Then comes an invented error message: the check cannot be completed, the balance is too low, a small top-up is needed to cover the fee. Click "Retry" and you see the same animation once more, followed by a reassuring result, usually a "Clean, Low Risk".
That result is pure invention. There is no check, no database query and no assessment. What there is, is a connection between your wallet and someone else's website, and that connection is the real purpose of the whole arrangement.
AML check explained: why a wallet address gets screened at all
AML stands for anti-money laundering. An AML check for crypto is a report on whether a public blockchain address has been connected in the past to suspicious counterparties, for example a hacked trading venue, a mixing service or a sanctioned address. Providers of such reports evaluate publicly visible transaction data and assign addresses to known actors.
The decisive part of that definition is already in the word "public". Everything such a report needs is lying in the open on the blockchain anyway. The address is the key to the query, and the address is a string of characters that you can copy and paste into a field. Access to your balance is no more necessary for this than a power of attorney over a bank account is necessary to request a public land registry extract.
Why do retail investors care in the first place? Because an address flagged as suspicious can cause trouble. Deposit funds at a regulated trading venue and you may face a query from the compliance department, and in the worst case a withdrawal is delayed until the origin of the funds has been clarified. That worry is real, and it is the lever the scam sites pull.
How to recognize a genuine screening page
A legitimate report requires an input field and nothing else. You paste in the address, you get an assessment, and your wallet software is not opened once during the entire process. If your wallet's connection window appears instead, the check is already over at that moment, and not in your favor. Malwarebytes puts it as a plain rule of thumb: anyone demanding a wallet connection instead of the public address is a warning sign.
Enter an address or connect a wallet: the one difference that decides everything
Two actions that look similar in a browser have fundamentally different consequences. Entering an address is a read operation. You hand over information that every blockchain explorer displays anyway, and the other side can do nothing with it that it could not do without you.
Connecting a wallet is something else. Doing so permits a website to talk to your wallet software. The site then sees your address and your balance, and above all it may present transactions to you for confirmation. It cannot trigger those transactions itself, but it can prepare and label them so that a single click from you is enough. A wallet's security architecture is incorruptible at this point: it executes what you approve.
That is why the documented sites build their staging so carefully. They need no vulnerability in your wallet. They need a moment in which a confirmation window looks to you like a normal step in a security check. Once you grasp that you believe yourself to be in a screening process while you are in fact signing a power of attorney, the trick is seen through.

How the scam site works: from the progress bar to the alleged fee
The order of the steps is no accident, it follows a dramaturgy. First comes the choice of cryptocurrency, a harmless act that builds trust and pulls you into a sequence of clicks. Then follows the connection, which seems plausible in the context of a supposed check. Only after that does the actual manipulation begin.
The progress bar serves two purposes. It makes the site appear to work where nothing is working, and it buys the other side time to look at your address and prepare a suitable transaction. What is then put in front of you is tailored to your balance. The subsequent error message about a missing fee is the pretext meant to justify a payment or an approval. And the closing "Clean, Low Risk" makes sure you leave the site reassured, without checking what you confirmed along the way.
What is remarkable about this scheme is whom it hits. It does not target carelessness, it targets caution. Anyone looking for an AML check has already given thought to how clean their address is. That audience is better informed than average, and it arrives of its own accord, without an attacker having to write to it.
Token approval instead of a password: how the outflow works technically
In an attack of this kind no password and no recovery phrase is lost. The usual route runs through a token approval. An approval is a permission you grant to a third-party address to move a particular kind of token out of your wallet. That permission is necessary in everyday use, every decentralized exchange needs it, and it remains in place until you revoke it.
The danger lies in the amount and in the duration. Many approvals are granted without a limit, because that is convenient and because the confirmation window does not always display the amount in an understandable way. An unlimited approval, once granted, keeps working after you have long closed the site, after a restart of your computer, and even when you disconnect the site in your wallet menu. Disconnecting ends the channel of conversation; it does not withdraw the power of attorney.
What such a confirmation looks like in the window, and which fields you should read before clicking, we described in detail in our article on wallet drainers and signature approvals. If there is a single technical skill to take away from this subject, it should be that one. On a chain such as Ethereum and the networks compatible with it, the approval is the standard mechanism by which balances change hands without any key having to be stolen.
What an approval technically permits
An approval names three things: which token it covers, which third-party address may dispose of it, and up to what amount. If the amount limit is missing, the third-party address may withdraw the entire holding of that token, at any time and without asking you again. Wallets with a good interface show you these three details in plain language. Older or plainly designed confirmation windows show you a string of characters, and that is precisely what the operators of such sites count on.
Our own survey: three of the five named domains still respond twelve days later
This analysis was carried out by cryptoticker.io itself on August 31, 2026. Method: we checked the five domains that Malwarebytes names explicitly in its report once on August 31, 2026 at 03:53 UTC, by HTTP request and by name resolution, and recorded the response code. Five domains from the report were checked, plus the domain of the imitated legitimate provider as a reference value, so six objects in total.
The result: two of the five domains can no longer be resolved, their name entries have vanished. Two more respond with code 200 and therefore serve a page. A fifth responds with code 403 and rejects our automated request, but has an active name entry and a responding server. Sorted by name: amlbot-clear[.]com responds, bitget-aml[.]com responds, swapstoken[.]app rejects, audittrust[.]shop and search-aml[.]net can no longer be resolved. The domain of the genuine provider also responds, as expected.
What these figures mean, and what they do not: we measured reachability only, that is, whether a server responds under the name. We did not open the pages served, did not assess their content and therefore did not establish whether the described scheme is still running there, whether a parking page stands in its place or whether a third party has taken the domain over. Nor can we say how many people visited the sites in that period or what damage was caused. Only one statement is solid: twelve days after the public warning, the infrastructure named there has not been fully cleared away. For you as a reader that is the relevant measure, because a warning whose targets have long been offline would be history. This one is not.
Imitated names: what a domain says about a company
One of the domains named combines the name of a well-known trading platform with the abbreviation AML. That deserves a clear classification, because a domain can be chosen freely, and whoever registers it needs neither the permission nor the knowledge of the name's owner. Nothing about a company itself follows from its name appearing in an address bar. On the contrary: firms whose names are used in this way are victims of the scheme, because trust they built over years is turned into a tool against their own customers. That applies here to the imitated screening platform just as much as to the trading platform whose name appears in one of the domains.
In practice that means this for you: a familiar name in a web address is not a seal of approval. What counts is the complete address line, and what counts above all is how you arrived at the page. A link from a message, from a post on a social network or from a paid search ad deserves more suspicion on principle than a bookmark you set yourself.
Why the scheme falls on prepared ground in Germany
Since the beginning of 2026, German investors have been asked by their providers for documentation in a way that was previously unusual. With the implementation of the EU directive DAC8, crypto service providers have had to identify their customers, record transactions and obtain tax self-declarations since January 1, 2026. Anyone who fails to respond is reminded, then warned, and the provider can restrict accounts.
That creates a habituation worth its weight in gold to fraudsters. Demands for documentation, checks and confirmations currently sound less like an alarm signal than like administrative routine. A site offering a money-laundering check fits that picture, and the thought "I suppose I have to do this" comes more readily than it did a year ago. We observed a similar pattern with the crypto job offers involving your own bank account, where an official-sounding procedure likewise provided the frame for the actual damage.
It helps to make the difference clear to yourself once. When your trading venue wants something from you, you find that request inside your account after logging in. No regulated provider sends you to a third-party website to fulfill an obligation, and none demands a wallet connection for it. Where these obligations are actually laid down, and which providers operate under European supervision, you can read in our overview of regulated crypto exchanges.
Store your wallet safely: hardware wallets comparedChecking and revoking token approvals: how to proceed
The most effective step after an unclear encounter with such a site is to review the approvals you have granted. Every major chain has an area in its blockchain explorer where you enter your address and get a list of all open approvals together with the authorized counterpart address. A revocation is an ordinary transaction and costs the usual network fee.
Work through the list calmly and watch for two things: unlimited amounts, and counterpart addresses you cannot assign to any transaction of yours. An approval whose occasion you no longer remember is a candidate for revocation, even if nothing has happened so far. The effort is small; the possible damage is not.
Where you keep your keys also determines how expensive a mistaken click can become. An overview of the devices and how they are operated can be found in our hardware wallet comparison; anyone working without an additional device will find in the software wallet comparison the differences in how confirmation windows are displayed, and that display is precisely the security-relevant point here.
After a confirmed transaction: why disconnecting alone is not enough
Suppose you have confirmed and notice it shortly afterwards. Then the order of your steps matters more than their speed. Disconnecting in the wallet menu is sensible, but it is the smallest of the steps, because it leaves the granted power of attorney untouched. More important is revoking the approval, and more important still is the question of whether only an approval was granted or a recovery phrase was entered.
If an approval was granted, revoking it is usually enough. If, on the other hand, a recovery phrase or a private key was typed in somewhere, the wallet is permanently lost, and the remaining balance belongs on a freshly created wallet with a new recovery phrase. A recovery phrase knows no revocation; it can only be replaced.
You should be prepared for what comes next: offers of supposed recovery. Anyone approached in forums or by message after an incident, promising to retrieve funds against an advance payment, is running the second stage of the same scheme. Confirmed transactions on a blockchain are final, and nobody can reverse them for a fee.

Separate wallets and small amounts: what limits the damage
No single measure fully protects against a mistaken click, but splitting your holdings helps reliably. Anyone who keeps the largest part of their balance on an address that is never connected to a website can experiment calmly without risking everything. A second address with a manageable amount then handles contact with applications, and any damage stays limited to that amount.
A hardware device strengthens this effect, because it moves the confirmation to a display outside the computer. It is still no free pass: even with a hardware wallet you grant an approval when you confirm it on the device. The gain lies in the fact that the details appear there in a form a manipulated website cannot overwrite. Anyone who reads that display, instead of pressing the same button twice, has done the greater part of the work.
Recurring approval reviews: when a check makes sense
Approvals accumulate without being noticed. Every application you use leaves one behind, and after two years of use an active address easily carries several dozen open powers of attorney. Many of them belong to projects that no longer exist, and an abandoned application is an attractive target for a takeover by third parties.
A review twice a year is a sensible measure, plus one after any unusual event: after visiting a site you reached through someone else's link, after a confirmation whose purpose you cannot recall afterwards, and after every report of a compromised application you have used yourself. The time required is a few minutes, once you know the procedure.
Spotting a fake AML check: what to take away
- Remember the dividing line. A genuine check on a crypto address asks only for the public address in an input field. As soon as a supposed screening service asks you to connect your wallet, confirm a transaction or advance a fee, stop. If you are unsure where such checks are handled by the provider anyway, our overview of regulated crypto exchanges helps.
- Review your open approvals. Open your chain's blockchain explorer, enter your address and revoke every unlimited or unexplained approval. How to read a confirmation window properly beforehand, so that no new ones are added in the first place, is set out in the software wallet comparison and in our article on signature approvals.
- Separate storage from use. Keep the larger part of your holdings on an address that is never connected to a website, and use a second address for applications with an amount whose loss you could cope with. Which devices support this separation and how they are operated is shown in the hardware wallet comparison.
The sources for this article: the report by Malwarebytes of August 19, 2026 and the independent write-up at Decrypt of August 20, 2026. The reachability measurement of the named domains comes from cryptoticker.io.
(As of August 31, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Wallet Drainers: What You Really Approve When You Confirm, and How to Take It Back
- Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
- Crypto Scams: How to Protect Your Cryptos?
- How to Identify Fake TRUMP tokens: A Guide to Staying Safe in the Crypto World
- Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 14, 2026 10:13 AM

Revoke Token Approvals on Ethereum: A Revocation Now Costs 0.52 Cents
Every decentralized exchange, every lending pool and every bridge asks for a token approval, and it keeps running after the swap is done. We counted 5,910 approvals and worked out what a revocation really costs today.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
August 23, 2026 4:36 PM

Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.
April 25, 2024 11:44 AM

Beware of New Ethereum Node Scam: USDT Fraud Exposed
Crypto Scammers exploit Ethereum nodes and USDT to deceive crypto users. How are they pulling it off and what essential tips can help you protect yourself against these crypto scams?
August 25, 2026 10:11 PM

Ledger Closes a Gap in the Ethereum App: When the Display Shows Something Other Than What You Sign
Ledger has closed a flaw in its Ethereum app that let a malicious application swap the reviewed transaction for a different one. Anyone holding Ether or ERC-20 tokens on the device should check the app version and clear out old token approvals.
December 6, 2024 5:10 PM

Magic Eden Airdrop Guide: How to Claim Magic Eden Token
The Magic Eden $ME airdrop checker is now live! Here's everything you need to know about checking your allocation, claiming your rewards, and understanding the value of $ME tokens.
December 26, 2024 1:08 PM

BGB News: Bitget Token Reaches New ATH Amid Market Momentum
Bitget Token (BGB) defies the market downtrend, hitting a new ATH of $7.32. What's driving this 368% surge and what the future holds for this top-performing cryptocurrency?
September 26, 2026 4:21 AM

Operation Herakles disconnects 13,888 phone numbers: what to check on crypto investment calls
Six authorities have disconnected 13,888 phone numbers used by investment fraudsters to call their victims in Operation Herakles, 9,304 of them in the past three months alone. What the Federal Network Agency now requires of telecoms providers and which three checks protect you from the scheme.
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
June 1, 2024 11:00 PM

Bitget Wallet Token (BWB) makes debut on the Bitget Launchpad
Bitget, the world's leading cryptocurrency exchange and Web3 company, has announced the launch of Bitget Wallet's BWB token on its Launchpad.
April 19, 2026 10:29 AM

RAVE Token Crash 95% in $6 Billion Wipeout: Insider Scam or Trader’s Paradise?
RAVE plummets 95% as allegations of insider manipulation surface. While retail investors suffer, professional traders eye a "Dead Cat Bounce" opportunity.
December 31, 2023 8:11 AM

Ultimate Guide To Rainbow Wallet Airdrop
Rainbow has unveiled its Rainbow Points rewards initiative. This article is all about the simple guide on Rainbow wallet airdrop
August 22, 2026 4:16 PM

Stolen Crypto: Where You Actually File a Report and What Counts in the First Hours
After a theft most people google first and preserve the evidence last, when the right order is the other way round. What you have to record in the first hours, where private individuals actually turn, and where the limit of what is possible lies.
September 14, 2026 1:27 PM

Bitcoin Lost to a Scam: What Counts as a Tax Loss in Austria
Lost bitcoin to a scam? Why Austria generally does not recognise the damage as a tax loss for privately held assets, and when compensation payments start to matter.
September 5, 2026 10:24 PM

Fake German Finance Ministry Letters: Why Nobody May Demand 19 Percent VAT on Your Crypto Purchase
Since September 1, 2026, Germany's Federal Ministry of Finance has been warning about forged letters that demand 19 percent VAT on cryptocurrency purchases while citing real transactions. That tax does not exist, and this is how to spot the forgery.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
September 15, 2026 10:14 PM

AI Crypto Crime: How Scams Are Getting More Convincing
AI is sharpening fake support, deepfakes and phishing across the crypto space. Why the data still needs a careful reading and which security routines protect a wallet.
September 25, 2026 1:47 PM

Magic Eden and Limit Break exploit: 530 WETH and thousands of NFTs drained, how to revoke your approvals
A bug in Limit Break's Payment Processor, the protocol behind Magic Eden's former Ethereum marketplace, has been draining NFTs and WETH since Thursday. Our blockchain analysis shows 911 affected wallets. What happened, why hardware wallets do not protect you and which two approvals to revoke now.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
August 26, 2024 7:44 PM
DOGS Token Major 120% Surge Within Hours Of Its Listing: BUY NOW?
The DOGS token experienced a dramatic surge of over 120% on Binance following its listing. How did the Telegram Open Network (TON) drive this surge?
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
January 10, 2025 11:00 PM

Bitget Token Price Surge amid Market Downturn: New 2025 BGB ATH?
In this week's turbulent crypto market taken by downward pressure, BGB made it the top gainer with an impressive price surge. Will it end the week with a new ATH in 2025?
October 3, 2026 4:28 PM

Sweatcoin Token SWEAT: Bitvavo Closes Trading on October 7, and What Matters Now
The Sweat Foundation is ending Sweat Wallet and the SWEAT token in their current form on December 30, 2026. At Bitvavo, one of the two remaining euro markets, trading and withdrawals close as early as October 7, and whatever is left in the account after that is converted into euros automatically by October 15.
October 2, 2026 1:42 PM

Arkham Intelligence: who does this wallet address really belong to?
The analytics platform attaches names to blockchain addresses and has been paying bounties for unmasking wallets since July 2023. What comes out of it, where the assignment goes wrong, and how you keep your own trail shorter.
September 4, 2026 10:32 AM

Crypto Deadlines This Autumn: Nine Cut-Off Dates Checked, and Only Three Leave You Time After Trading Ends
Nine running crypto deadlines, eleven provider pages, one query date: we counted how much time really lies between the end of trading and the withdrawal cut-off. In six of nine cases the stated date is the end of the line.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
More from CryptoTicker

