The progress bar says "Checking wallet history". Then "Verifying compliance". Then, partway through, a small error: the wallet needs a top-up to cover the fee before the check can finish. Malwarebytes threat intelligence researchers have documented a cluster of sites running exactly this script, all of them offering to screen a crypto wallet for links to crime, and all of them built to get one thing out of the visitor: an approved transaction.
A real check never touches your keys
Anti-money laundering screening is a genuine service. In crypto it means checking whether a wallet address shows links to hacks, scams or sanctioned entities, based on its public transaction history. The important detail is that it is a lookup. A legitimate screening service needs the wallet's public address and nothing else. You do not connect a wallet, you do not sign anything, and you do not approve a transaction.
That single fact is the whole defense. Malwarebytes' guidance is blunt: if a wallet checker asks you to connect your wallet rather than paste a public address, that is the warning sign, and everything after it is the scam.
Connecting is not the theft, approving is
The sites are polished. Several impersonate AMLBot, a real wallet-screening company that is itself a victim here, copying its logo, layout and wording; others operate under generic names such as "AML Check". The visitor picks a cryptocurrency, clicks a check button, and is prompted to connect a wallet.
Connecting alone does not hand over the funds. What it does is reveal the public address, which lets the site see what assets are there and tailor what comes next. The scammers then construct a transaction aimed at that specific wallet and push it to the victim for approval. Every piece of stagecraft around it, the animated progress bar, the plausible fee error, the retry that replays the same animation, and the reassuring "Clean, Low Risk" verdict with a downloadable report at the end, exists to make approving that transaction feel like a routine step in a security process rather than the point of the exercise. Malwarebytes notes the same layout and flow appearing under several different names and logos, which points at one reused template rather than several independent crews.
The cruelty of the design is that it selects for careful people. Someone running an AML check on a wallet is already trying to do the responsible thing, and the scam borrows that caution as cover. It is the same trust-laundering IntelFusions saw when fake stars and reviews pushed a crypto-stealing clipboard hijacker, and when a counterfeit BlueWallet app swapped wallet addresses mid-copy.
What to do if you already clicked
The response depends on how far it went. If you only connected a wallet, disconnect the site. If you approved access to tokens, open your wallet's approval checker, look for permissions you do not recognize and revoke them. If you confirmed a transaction or signed something you did not understand, review recent activity and move remaining funds to a new wallet. If you entered a recovery phrase or private key, treat the wallet as fully compromised and migrate to a new one with a new phrase. If you downloaded a file from one of these sites, delete it without opening it and run a scan. Crypto transactions generally cannot be reversed once confirmed, so speed matters. Anyone who contacts you afterwards offering to recover the money for a fee is running the follow-on scam.
Malwarebytes published the following domains as indicators, defanged here: amlbot-clear[.]com, audittrust[.]shop, bitget-aml[.]com, search-aml[.]net and swapstoken[.]app. The original write-up includes screenshots of the fake and genuine sites side by side. Given the template is being rebranded repeatedly, the domain list will age faster than the rule that produced it: a wallet screening that asks for anything more than a public address is not a screening.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.