Fraudulent cryptocurrency “AML checker” websites are impersonating legitimate wallet screening services and luring users into connecting wallets, approving token access, signing transactions, or sending funds. The scam relies on professional-looking pages, fake progress indicators, fabricated errors, and reassuring results such as “Clean, Low Risk” to make the checks appear credible, while some sites mimic known brands including AMLBot or use generic names such as “AML Check.”
The operation abuses a key difference between real and fake screening: a legitimate AML wallet check only needs a public wallet address and should never require a wallet connection, transaction approval, recovery phrase, or private key. Victims who interacted with these sites are being urged to disconnect the malicious dApps, revoke token approvals, move assets to a new wallet if compromise is suspected, and ignore follow-on “recovery” scams that promise to retrieve stolen funds.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers described a cryptocurrency theft scam using fake AML wallet-checking websites that impersonate legitimate screening services such as AMLBot and trick users into connecting wallets, approving access, signing transactions, or sending funds. The reporting also identified associated domains including amlbot-clear[.]com, audittrust[.]shop, bitget-aml[.]com, search-aml[.]net, and swapstoken[.]app.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.