Scammers Weaponize AML Compliance to Drain Crypto Wallets
Fraudulent websites impersonate mandatory anti-money laundering checks to trick users into granting attackers full access to their assets.
Cybercriminals are deploying a sophisticated wave of fraudulent websites that impersonate cryptocurrency Anti-Money Laundering (AML) compliance services to steal digital assets. By mimicking legitimate verification portals, these sites trick users into connecting their wallets and approving malicious transactions that result in the total loss of funds.
According to reports from Malwarebytes Threat Intelligence and Decrypt, the attack begins when users are lured to a fake compliance portal. These sites claim a mandatory AML check is required to maintain account standing or verify the legitimacy of funds. Once a victim connects their wallet, the site prompts them to approve a transaction. Rather than performing a security check, this approval grants attackers unauthorized access to the wallet, allowing them to drain all available assets immediately.
The Compliance Lure
Anti-Money Laundering checks are standard operating procedures across the cryptocurrency industry. Most centralized exchanges and regulated financial services require these checks to ensure funds are not linked to illegal activities. Because users are accustomed to the friction of identity verification and compliance hurdles, they are less likely to question a request to "verify" their wallet for regulatory reasons. Scammers leverage this routine industry requirement to create a convincing lure that bypasses the typical skepticism users apply to unsolicited links.
Why This Attack is Effective
This campaign is particularly dangerous because it weaponizes a legitimate regulatory requirement to build trust. While many users are trained to avoid obvious phishing attempts, the impersonation of a necessary security step makes the request seem official and urgent. By framing the theft as a compliance necessity, attackers manipulate users into signing smart contract approvals—a technical action that often gives the attacker permanent permission to move tokens without further user interaction.
What to Watch
Users should remain vigilant and avoid connecting wallets to any third-party site claiming to perform "mandatory" compliance checks outside of a known, official exchange interface. Legitimate AML procedures typically involve providing identity documentation (KYC) to a platform rather than granting a website permission to interact with a private wallet's assets. Security experts continue to monitor the evolution of these drainers as they adapt to mimic different regulatory bodies and financial services.