Fake AML Checkers: Why Can a “Wallet Check” Become a Wallet Drainer?
How scammers disguise approval phishing as AML screening, and which warning signs should stop users.
A fake AML checker is a phishing site that promises to screen a wallet, but instead of checking a public address, it asks users to connect a wallet, approve a transaction, or grant permission. The scam abuses a user’s attempt to be cautious. A basic address check does not need a seed phrase, private key, or token approval.
Why does this scam look convincing?
AML and compliance have become familiar terms in crypto. A user wants to check whether an address is risky, so an interface that looks like a security service can feel trustworthy. Scammers copy the language, progress bars, reports, and visual style of legitimate tools.
Malwarebytes’ warning on fake crypto AML checkers highlights the key point: a basic check needs a public address, not a wallet connection.
How does the attack work?
The site first learns the public address, then builds a transaction or approval tailored to the user’s assets. The interface may say “check,” “report,” “small fee,” or “retry,” but the wallet shows an action that needs signing. If the user confirms, a contract may receive permission to spend tokens.
Chainalysis’ article on approval phishing describes this as deception where the victim thinks they are performing a minor task but actually grants access to funds.
Which red flags are visible early?
Requests to connect a wallet for a simple check, approve tokens, sign an unclear message, top up for a report, download a file, or enter a seed phrase are dangerous. Links from ads, Telegram, comments, direct messages, or lookalike domains also deserve extra caution.
A public address can be checked without spending rights. If a service asks for more, it should explain why, and the user should be able to refuse.
What should be done after suspicious interaction?
If the wallet was only connected, disconnect the site in wallet settings. If an approval was granted, check permissions and revoke unknown ones. If a transaction was signed or a seed phrase was entered, treat the wallet as compromised and move remaining funds to a new address with a new phrase.
Be wary of “recovery experts” who promise to recover funds for an upfront fee. That is often a second scam.
What limits and risks remain?
Even careful users can land on polished clones. Transaction simulators and security extensions help, but they do not catch every new site. Domain blocking can also lag.
The core rule is simple: an AML address check does not require wallet access. Any request to sign, approve, or reveal keys should be treated as high risk.
Sources
- AML checker scams
- Approval phishing
This article is for information only and is not individual investment advice. Trading crypto carries the risk of losing your funds; results on historical data do not guarantee future results.
Check the strategy against your own data
ACARO is a terminal that executes a strategy on your own exchange account. Parameter search and backtesting on history are part of the subscription.
See pricing