Crypto

Fake Crypto Compliance Sites Target Wallet Holders in Escalating Phishing Schemes

Security researchers warn fraudulent compliance portals are asking users to connect wallets and approve malicious spending permissions.

Public wallet addresses are all that authentic compliance tools require, yet bad actors are leveraging fraudulent anti-money laundering inspection portals to trick digital asset holders into authorizing malicious transactions, cybersecurity firm Malwarebytes warned.

The security company detailed in a Wednesday report how these spoofed domains copy legitimate tools that track wallet exposure to stolen funds and illicit transactions. While several clones directly replicate the genuine platform AMLBot, others operate under generic branding including “AML Check.”

Legitimate crypto compliance utilities scan on-chain transaction histories to flag connections with security breaches, scams, sanctioned entities, or fraudulent activity. Performing a standard evaluation only necessitates entering a public wallet address, with zero requirement to connect a Web3 wallet, sign a transaction, or approve smart contract permissions.

Investigators at Malwarebytes observed that the deceptive sites force visitors to link their Web3 wallets under the guise of starting an evaluation, generating fabricated loading screens and synthetic risk scores. In one instance, a domain demanded a small top-up payment for an alleged fee, ultimately displaying a “Clean, Low Risk” rating without executing any real analysis.

“If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign,” Malwarebytes researchers wrote.

Merely linking a wallet does not immediately expose holdings to theft, but it surrenders the public address to attackers, allowing them to inspect asset balances and construct a malicious signature request for the user to approve.

Smart contract approvals—often called token allowances—grant designated external protocols permission to move funds on behalf of a wallet. Once an unverified site secures an approval signature, malicious smart contracts can drain tokens directly from the user’s balance up to the authorized limit, often without requiring any secondary confirmation.

Cybersecurity analysts identified identical site layouts and backend mechanisms circulating across multiple domains and logos, pointing to a single scam template being iteratively rebranded.

Experienced cryptocurrency participants are familiar with social engineering tactics, yet a recent surge in phishing operations utilizing fake websites continues to target asset holders.

Hardware wallet manufacturers Trezor and Foundation issued alerts earlier this month regarding deceptive emails guiding users toward a cloned Coldcard portal. Separately, Malwarebytes exposed a fraudulent copy of the Pudgy Penguins Pudgy World game in March aimed at stealing wallet credentials, while cryptocurrency exchange CoinDCX revealed that same month that it detected more than 1,200 websites impersonating its platform between April 2024 and January 2026.

Security guidance from Malwarebytes recommends that anyone who signed token allowances immediately revoke those permissions. In cases where a recovery phrase or private key was disclosed, users must treat the account as fully compromised and immediately transfer all remaining assets to an untouched wallet address.

Because immutable blockchain ledgers leave no mechanism for recovery once funds leave an address, cybersecurity experts stress that immediate mitigation remains the only effective response following an unauthorized signature. “Crypto transactions generally can’t be reversed once they’re confirmed, so acting quickly matters if you’ve approved something suspicious,” Malwarebytes said.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button