Skip to main content
AVOID.NET

Fake Crypto AML Checker Drainer Campaign

avoid.net/fake-crypto-aml-checker-drainer-campaign1/100·75% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

A coordinated campaign of fraudulent websites impersonating cryptocurrency AML (anti-money-laundering) compliance-check services — most prominently the legitimate provider AMLBot, alongside generic "AML Check" branding — has been documented by cybersecurity firm Malwarebytes and corroborated by multiple crypto and security news outlets since August 2026. The sites lure users into connecting wallets under the pretext of a compliance scan and then induce them to approve malicious transactions or token permissions that drain their assets. This is an assessment of the scam campaign and its known malicious infrastructure, not of AMLBot itself, which appears to be an impersonated victim brand rather than a perpetrator.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Fake Crypto AML Checker Drainer Campaign?

Timeline(4 events)

June 2026

A malware-removal reference site (PCRisk) first published a guide describing an "AMLBot Crypto Checking Scam" impersonating the AMLBot brand, cataloguing associated fraudulent domains.

PCRisk

19 August 2026

Malwarebytes published a threat intelligence report, "Scammers are using fake crypto AML checkers to drain your wallet," detailing the campaign's mechanics and listing malicious domains.

Malwarebytes

August 2026

Crypto and tech news outlets, including Decrypt, Cryptopolitan, and KuCoin's news flash service, republished and summarized the Malwarebytes findings, extending public awareness of the campaign.

Decrypt

1 September 2026

Security Boulevard published a follow-up article featuring additional expert commentary (Sectigo, DataVisor, Black Duck) framing the campaign as a consent-phishing-style social engineering attack.

Security Boulevard
Provenance & Audit Trail
5 Wayback Archives

5 of 6 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 9/19/2026, 12:22:26 PM

last updated: 9/19/2026, 2:10:19 PM

avoid.net — verified advice for a post-truth world