Fake wallet safety checks are draining wallets — the tell is the connect button
Malwarebytes has warned that a wave of fake crypto compliance sites is tricking people into connecting their wallets and…
Malwarebytes has warned that a wave of fake crypto compliance sites is tricking people into connecting their wallets and approving transactions. The sites pose as anti-money-laundering checkers — tools that report whether a wallet has touched stolen, hacked or sanctioned funds — with some copying the name and look of the real service AMLBot and others using generic labels such as AML Check. The security firm's point is blunt: a genuine check needs nothing but your public wallet address, so being asked to connect is itself the warning sign.
A real AML lookup reads a wallet's public transaction history, which anyone can see. The fake versions instead ask you to connect, then put on a convincing show of progress messages, a scan and a result. One site asked for a small top-up to cover a supposed fee and then returned a clean, low-risk verdict regardless of whether any check had actually happened. Malwarebytes found the same layout and script running under several different names and logos, which suggests a single template being rebranded and reused.
Connecting a wallet does not by itself hand over your coins. What it hands over is information: your address, and with it the list of what you hold. That is enough for the site to build a transaction shaped around your assets and put it in front of you to approve. The theft happens at the approval step, which is exactly the moment most people click through, because the page has spent the previous minute looking official.
None of this is new, only newly dressed. Earlier this month the hardware wallet makers Trezor and Foundation warned about phishing emails pointing to a cloned Coldcard website. In March, Malwarebytes found a fake version of the Pudgy Penguins game Pudgy World built to steal wallet passwords, and the exchange CoinDCX said it had identified more than 1,200 sites impersonating its platform between April 2024 and January 2026.
If you have already approved something, Malwarebytes advises revoking suspicious token permissions straight away, and treating the wallet as compromised — moving everything to a fresh one — if you typed a recovery phrase or private key anywhere. Confirmed crypto transactions generally cannot be reversed, so the speed of your response matters more here than in most online scams. The rule worth memorising as a beginner: any page that offers to check, verify or clear your wallet and then asks you to connect it is asking for something the job does not require.