The Cybersecurity company Malwarebytes states that there have recently been several fake encrypted AML search sites, the aim of which is to induce users to connect wallets and approve transactions, thus exposing assets to risk. Such websites are disguised as formal services such as AMLBot and use generic names such as “AML Check” to confuse users.

Just an address, not even a wallet.

Encryption AML services are usually used to check the public transaction records of a wallet to determine whether it has any connection to hacker attacks, fraud, sanctioned entities or other suspicious funds. When the basic query is completed, the user simply enters the address of the public wallet, does not need to connect the wallet or sign or authorize the transaction.

Malwarebytes states that a fake website would require users to connect their wallets and then display a false scan progress and results page to create an image of “ongoing testing”. Some websites also require users to pay a small fee first, on the grounds that they cover the search costs and then give results such as “Clean, Low Risk”, whether or not the test is actually completed.

The risk begins to increase when you connect your wallet.

Researchers caution that if the so-called AML query tool requires a connection to a wallet, rather than simply entering an open address, it is in itself a clear alert. A simple connection to a wallet does not necessarily lead to the immediate theft of funds, but it exposes the wallet address, allows the other party to see the holdup and further constructs the transaction pending approval by the user.

Malwarebytes also found that the web site was highly similar to the page design and operating processes, but only changed its name and logo to show that the same fraud template was being packaged and dropped over and over again.

There has been an increase in recent attacks on fake websites

This is not the only type of fishing that has targeted encrypted users in the recent past. Earlier this month, the hardware wallet manufacturer, Térezor and Foundation, warned users to turn people into counterfeit Coldcard's fishing mail. In March, Malwarebytes also discovered a fake Pudgy Penguins game site for the purpose of stealing wallet passwords.

Also in March, the encryption exchange CoinDCX indicated that during the period from April 2024 to January 2026, the platform identified more than 1,200 sites that had been branded.

Authorized users need to process as soon as possible

Malwarebytes recommends that if a user has granted suspicious token privileges, the authorization should be revoked as soon as possible; if a handwritten or private key has been entered, the wallet should be considered lost and the assets transferred to the new wallet as soon as possible.

The company cautioned that, once the encrypted transaction had been established in the chain, it would normally not be possible to withdraw it, and that the speed of processing was therefore critical when exceptional authorizations were found.