Fraudulent cryptocurrency anti-money laundering screening websites are posing as services such as AMLBot and leading visitors into wallet-draining transactions, according to researchers cited in the source report. The sites present themselves as compliance tools, but instead of checking a wallet address, they push users toward actions that legitimate screening services do not require.

The core warning is straightforward: real wallet screening needs only a public address. A request to connect a wallet, sign a transaction, grant permissions, or pay a small fee to reveal a result is a major warning sign, the researchers said.

How the scam flow works

The fake sites imitate the look and purpose of AML checking platforms. A visitor is typically asked to choose a cryptocurrency and start a scan, creating the impression that the service is reviewing a wallet for risk or compliance issues.

After that, the site asks the user to connect a wallet in order to view the result. Some versions add a staged loading sequence with messages such as checks of wallet history and compliance verification, making the process appear legitimate.

The screening then ends with a fabricated obstacle. In some cases, the page shows an error and asks for a small top-up to cover an alleged fee. If the user retries, the animation may run again before displaying a reassuring result such as a low-risk verdict and an option to download a report.

Why the wallet prompt matters

Researchers said the connect-wallet step is the key sign that the service is not genuine. Legitimate AML screening of a crypto wallet only requires the wallet’s public address and does not involve signing messages, approving transactions, or connecting a wallet interface.

Connecting a wallet by itself does not give the operator access to private keys. However, it does expose the public address, which can let the scammers inspect the wallet’s holdings and prepare a transaction tailored to that specific target.

The theft happens when the victim is persuaded to approve the unexpected transaction. Once that approval is given, the funds can be moved. The researchers’ guidance was to avoid confirming transactions that appear unexpectedly during this kind of screening process.

Rebranded kits appear across multiple sites

The report said investigators found the same underlying scam framework appearing under different brand names and visual identities. Rather than a single fake site, the operation appears to rely on a reusable kit that can be repackaged with new logos and names.

That rebranding makes the scheme harder to spot by appearance alone. A site may look different from another one flagged earlier while still using the same page flow, the same wallet prompt, and the same sequence of fake scanning messages and fee requests.

Researchers said the kit is being rebranded and resold, suggesting the tactic can spread through multiple operators using the same basic setup.

What is confirmed and what to watch for next

The confirmed pattern in the report is that fake AML checker pages are trying to turn a simple address lookup into a wallet interaction that leads to approval of a malicious transaction. The specific warning signs are consistent across the examples described: requests to connect a wallet, sign something, approve permissions, or pay to see a result.

For now, the practical next step is caution around any AML or wallet-risk checker that asks for more than a public address. Based on the researchers’ findings, any such prompt should be treated as suspicious, particularly when paired with staged progress bars, compliance language, or a small fee demand before a supposed final report is shown.

Source: Cryptopolitan