Risk gauge with a needle in the green zone next to a downward arrow
Security·7 min read

Fake AML Checkers Are Emptying Wallets: How to Recognise One

There is a category of crypto scam that works precisely because the victim is being careful. Researchers at Malwarebytes Labs have documented a wave of cloned compliance sites: fake services that promise to screen a wallet for links to sanctions, theft or darknet activity, and drain it instead.

The impersonation is not subtle. Some copy the design of an established screening provider outright; others operate under adjacent names built from the same vocabulary. Both rely on the same assumption - that a user worried about dirty coins will follow instructions rather than question them.

What a real crypto AML check does

A crypto AML check reads public data. Every transaction on a public blockchain is visible, and screening services maintain databases that map addresses to known entities: exchanges, mixers, sanctioned wallets, ransomware payments, darknet markets.

Give the service an address and it traces the flow of funds backwards, showing what share of the balance can be linked to those categories and producing a risk score.

That is the entire operation. It requires one input: the public address. Nothing else. No connection, no signature, no access of any kind, because everything being analysed is already public.

How the fake version works

The fake crypto AML check is deliberately paced to look like software rather than a robbery.

You land on the page, usually through a search advertisement or a link posted in a support chat. The interface asks you to connect your wallet to begin screening, which is the first and most important lie.

The connection alone does not move funds. What it does is reveal your address and your token balances, letting the operator build a transaction shaped specifically for what you hold - a token approval that grants unlimited spending rights, or a transfer disguised as a verification step.

Then comes the theatre. Progress messages scroll past about scanning transaction history and checking compliance status. An error appears: the scan cannot complete until a small network fee is topped up. That step exists to pull a second, smaller payment from users who are still suspicious of the first one.

Retry, and the result is reassuring - the address is clean. All that remains is to download the report. The report is an executable, and running it installs an information stealer that goes looking for wallet files, seed phrases stored in notes, and browser session cookies.

Notice how many chances the design creates to take something. Signature, fee, malware. A user who declines the first two often accepts the third, because by then the site has behaved like a legitimate tool for several minutes.

The one rule that ends the conversation

A legitimate crypto AML check never asks you to connect a wallet, approve a transaction, or reveal a seed phrase. There is no version of blockchain analysis that requires any of those, because the data being analysed is public by definition.

If a screening site asks for a signature, it is not screening anything. Read the request carefully when a wallet prompt appears: an unlimited allowance to an unknown contract is not a login step, whatever the page says.

The commercial model is a second tell. Real providers charge per report, by card or by an ordinary crypto payment to a stated address, and they explain what their scoring means. A free unlimited service that only wants your connection is monetising something other than the report.

If you already connected

Move quickly and in this order.

Revoke the approvals granted from that address. Any token allowance issued to an unknown contract stays live until you revoke it, and drainers frequently wait days before using one so the victim connects the loss to something else.

Move the remaining balance to a wallet created on a different, clean device. Do not import the exposed seed phrase on the machine you used - if the "report" ran, that device is the compromise.

Scan the computer if you downloaded anything. Then change the passwords for exchange accounts from a clean device and terminate active sessions, because stolen session cookies survive a password change.

Finally, expect the follow-up. Victims of drainer campaigns are contacted within days by "recovery specialists" asking for an upfront fee or, more brazenly, for the seed phrase they claim to be rescuing. That is the same industry working its own customer list.

When screening is genuinely worth doing

None of this means compliance screening is pointless. The opposite is true, and that is exactly why the scam works.

Exchanges freeze deposits that arrive with a risk flag, and the resulting review takes weeks of paperwork proving where the funds came from. Checking an address before you receive a large payment, or before depositing coins bought from a peer-to-peer counterparty, is a reasonable habit.

Do it through a provider you reached directly rather than through an advertisement, and do it with the address alone. A crypto AML check that stays read-only cannot cost you anything except its fee.

For anyone trading regularly, the more durable answer is structural: buy through a platform that screens deposits on its own side, so the compliance question is answered before the coins are ever yours.

FAQ
Can a wallet connection by itself steal my funds?

Not on its own. Connecting exposes your address and balances; the theft requires a signature. The danger is that the connection lets the attacker craft exactly the signature request most likely to succeed against your specific holdings.

How do I recognise a dangerous signature request?

Look for approval or allowance requests with no spending limit, and for transfers where the destination is an address you do not recognise. Any wallet request that appears during what is supposed to be a read-only check is by definition wrong.

Are paid screening services safer than free ones?

Not automatically, but a clear commercial model is a good sign, because it explains how the operator makes money. A free service with no explanation is being paid by someone, and the question is who.

What happens if my deposit gets flagged by an exchange?

The platform freezes it and asks for documentation of the source of funds. Some balances are released after review, others are held indefinitely, and the process routinely takes weeks - which is the entire reason screening exists.

Is a hardware wallet protection against this?

Against the malware step, largely yes, since keys never touch the computer. Against the signature step, no - if you approve a malicious transaction on the device screen, the hardware wallet will sign it exactly as instructed.

Should I run a crypto AML check on every incoming payment?

For small amounts it is overkill. For large transfers, for funds from counterparties you do not know, and before depositing to an exchange, the check costs a few dollars and prevents a review that could last a month.

About the author
Crypto Markets Expert & Head of Content and Marketing

Crypto markets expert and head of content and marketing at EIDEX. Covers market structure, exchange infrastructure and cross-chain trading — turning on-chain data and market shifts into clear, actionable research for traders.

Share this articleTelegramX