How is this "disguised as a security tool" scam fundamentally different from typical fake-exchange or fake-NFT phishing sites?
Typical phishing sites exploit greed or urgency — time-limited airdrops, guaranteed returns, discounted rare NFTs — luring users into lowering their guard while excited or rushed. Fake AML checker sites exploit the opposite psychological mechanism: they target people who are already engaged in defensive behavior, actively trying to confirm whether their wallet is safe.
That distinction is what makes fake AML sites especially hard to guard against. The user's mental state going in isn't "I might be getting a deal" — it's "I'm protecting myself." That self-perception actually lowers vigilance for every subsequent step, because the whole flow is framed as part of a security check rather than as a transaction.
What does it mean that the same scam template keeps reappearing under different brand names?
Malwarebytes' report specifically notes that while these fake sites vary in branding and naming, their underlying design and flow logic are highly consistent — the progress bar, the fake error message, the "low risk" result, the downloadable report. This entire component set is likely being deployed as a ready-made template rather than built from scratch by each individual attacker.
This reflects phishing attacks evolving toward templated, quickly rebrandable operations: attackers don't need to redesign the entire psychological-manipulation flow — they just need a new logo and a new domain to redeploy the same already-validated script. It's the same underlying logic as the Drainer-as-a-Service industrialization trend covered elsewhere: attack tooling itself is becoming a rentable, reproducible commodity, which keeps lowering the barrier to running a scam.
If I'm already careful and never click on suspicious links, how else might I encounter one of these fake AML sites?
The report specifically warns that these fake sites often surface through search engine ads, social media posts, messaging platforms, and mixed in among organic search results — meaning a user doesn't necessarily land on one by clicking a suspicious link. They may simply be searching for terms like "AML checker" or "wallet risk check" and click a site that ranks highly but is actually an impersonation.
This is exactly why "be careful about suspicious links" isn't a sufficient rule anymore. For any tool you plan to use to verify your own asset safety, the correct approach is to find that service's officially announced URL — from its verified social account or an existing bookmark you already trust — rather than relying on search engine rankings or a link received in a message, since both the rankings and the message itself can already be compromised by scammers.
Beyond "avoid fake sites," does this incident suggest any concrete, ongoing habit for managing my wallet's approvals?
Yes — one concrete, repeatable habit: periodically (say, monthly) use an approval-checking tool you already trust, whose official URL you've verified, to review which sites or contracts currently have access to your wallet, and revoke anything you no longer use or don't remember authorizing. The reason this matters is that even if you never fall for a fake AML site, old approvals left behind from other DeFi platforms or NFT marketplaces are themselves a standing risk — an attacker doesn't need to trick you "this time" if an approval you granted at some point in the past is still active.
Put differently, the real takeaway from this incident isn't "watch out for this one scam type" — it's that approval management should be a routine habit, not something you only think about after something goes wrong. Treating approval revocation like a periodic password change is what actually reduces risk over the long run.
On August 19, 2026, security firm Malwarebytes exposed a wave of phishing sites impersonating crypto wallet anti-money-laundering (AML) checking services — copying the branding, interface, and language of the legitimate service AMLBot, or operating under neutral-sounding generic names like "AML Check." The goal is to lure users into connecting their wallets and then approving a transaction that drains their funds. This incident is worth studying alongside approval phishing, because it shows how scammers can turn a user's own instinct to protect themselves into the entry point for an attack.
A legitimate crypto AML check is, at its core, a simple lookup: you provide a wallet's public address, and the service checks its transaction history for links to hacks, scams, sanctioned entities, or other suspicious activity. The entire process only requires a public address — no wallet connection, no transaction approval, and certainly no recovery phrase or Private Key. Malwarebytes was explicit on this point: if an AML checker asks you to connect your wallet rather than simply enter its address, treat that as a warning sign.
One version researchers reviewed was built to look highly professional — users select their cryptocurrency, click a "Check Wallet" button, and are then prompted to connect their wallet. Connecting alone isn't enough to steal funds, but it does reveal the user's public address, which lets the attacker craft a malicious transaction tailored specifically to that wallet and send it back for approval. The site displays progress-bar messages like "Checking wallet history…" and "Verifying compliance…" to make the process feel like a genuine check is underway. Partway through, a fake error appears claiming the wallet needs a small top-up to "cover the fee" before the check can finish — nudging the user to send a small transaction. Clicking "Retry" plays the same animation again before producing a reassuring "Clean, Low Risk" result, complete with a downloadable report, regardless of whether any genuine check ever took place.
Malwarebytes' analysis points to a key psychological mechanism: people who go looking for an AML checker in the first place are already security-conscious and actively trying to protect themselves. These fake sites exploit exactly that caution — every step is designed to feel like part of a normal security process: the progress bar suggests real analysis is happening, the fee explanation makes the interruption seem plausible, and the "low risk" result makes it seem like the check actually worked. Researchers also found the same underlying design and flow reused under multiple different names and logos, indicating this is a single scam template being repeatedly rebranded rather than separate attackers independently building their own tools. Known malicious domains identified so far include amlbot-clear[.]com, audittrust[.]shop, bitget-aml[.]com, search-aml[.]net, and swapstoken[.]app.
Malwarebytes' recommended response scales with how far the interaction went. If you only connected your wallet without approving anything, disconnect the site — connecting alone shouldn't grant it permission to move funds. If you approved tokeTokeness, check your wallet for permissions you don't recognize and revoke them; most wallet providers include a built-in approval checker for this. If you confirmed a transaction you didn't fully understand, review your recent wallet activity and, if you believe your assets are at risk, move remaining funds to a new wallet. If you entered a recovery phrase or private key, treat that wallet as fully compromised and move everything to a brand-new wallet with a new seedSeed Phraseypto transactions generally can't be reversed once confirmed, which is exactly why response speed matters so much in incidents like this.
The lesson worth keeping from this incident isn't "AMLBot got impersonated" — it's a broader principle: any service that asks you to connect a wallet, approve a transaction, sign a message, or provide a recovery phrase deserves a second of hesitation, even when it's dressed up as a "security check" or "compliance verification." Before using any AML lookup, approval-revocation, or security-scanning tool, type the official URL in manually rather than clicking the first search result or a link from a message, and hold onto one simple rule: a legitimate lookup service only needs your public address. The moment it asks for more than that, it isn't performing a lookup anymore — it's asking you to sign an authorization.