Press Enter to search · ESC to close

Crypto

Fake AML Checks Are Draining Crypto Wallets — Here’s How to Spot Them

A new phishing campaign is impersonating AML compliance reviews to trick crypto users into connecting wallets or revealing seed phrases, then draining their assets. Real AML checks never ask for private keys or transfers — here's how the scam works and what the industry must do about it.

Fake AML Checks Are Draining Crypto Wallets — Here’s How to Spot Them

A new wave of phishing scams is using the language of regulatory compliance to empty crypto wallets. Fraudsters are building convincing, official-looking “Anti-Money Laundering (AML) review” portals and pressuring users to connect wallets, enter seed phrases, or move funds into a “verification” address. Once a victim complies, the assets are swept away through a disguised backend within minutes.

Why the Scam Works

The pitch exploits a real trend: as global regulators tighten AML and KYC requirements for virtual asset service providers, users have grown accustomed to identity checks, source-of-funds questions, and transaction monitoring. Attackers weaponize that familiarity. The fake portals often mimic exchange interfaces, display realistic case numbers, countdown timers, and “compliance officer” chat windows, creating urgency that discourages users from verifying independently.

The mechanics are simple but effective:

  • Social engineering via Telegram, X, email, or fake customer-support accounts.
  • A cloned website with a legitimate-looking domain (often a homoglyph or subdomain trick).
  • A wallet-connect prompt or a request for a seed phrase/private key.
  • Malicious smart contracts that grant unlimited token approvals or drain via permit signatures.

The Iron Rule of AML

No genuine AML or KYC process ever requires a private key, seed phrase, or a transfer of funds to a “safe” or “verification” wallet. Regulated entities verify identity through official onboarding flows — they do not ask customers to prove innocence by moving assets. Any request that combines compliance language with wallet access is, by definition, a scam.

Industry Implications

The rise of compliance-themed phishing is a direct side effect of crypto’s regulatory maturation. As MiCA in Europe, VASP licensing in Asia, and FinCEN and SEC enforcement in the U.S. push more users through KYC funnels, the surface area for impersonation grows. Exchanges and wallet providers now face pressure to ship better anti-phishing tooling: domain verification, wallet-approval revokers, transaction simulation, and clear in-app warnings when a dApp requests unlimited allowances.

On-chain analytics firms are also racing to flag drainer contracts and blacklist addresses, but takedowns lag because attackers rotate domains and wallets daily. The result is an asymmetric fight where user education remains the most reliable defense.

What Comes Next

Expect regulators to add “anti-phishing” and “impersonation of compliance” to their consumer-protection guidance, and expect wallet vendors to make seed-phrase entry a hard-blocked action in mainstream interfaces. Until then, the burden falls on users: bookmark official URLs, never sign blind, revoke stale approvals, and treat any unsolicited “AML review” as hostile until proven otherwise. In crypto, the surest sign of a scam is a demand for the keys to your assets.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback