Skip to main content
AVOID.NET

Fake Crypto AML Checker Infrastructure

avoid.net/fake-crypto-aml-checker-infrastructure→0/100·88% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5uy4PR…9zjw
last updated 2026-08-25

Summary

A coordinated network of fraudulent websites impersonating legitimate anti-money laundering (AML) compliance tools — most prominently AMLBot — was publicly documented by Malwarebytes on August 19, 2026. The sites simulate wallet-risk screening workflows to social-engineer users into connecting wallets and signing drainer transactions, in some cases also charging small upfront 'verification fees.' The campaign is notable for targeting security-conscious users who are actively trying to verify their own wallet safety, and for the systematic reuse of a shared malicious site template rebranded under multiple names and logos.

Connected Entities

3 entities · 60 linked investigations
Organizations
□Solana62□Fake Crypto AML Checker Infrastructure
Exchanges
Relationships
  • Fake Crypto AML Checker Infrastructure→mentioned with→Jupiter Exchange(60%)
  • Fake Crypto AML Checker Infrastructure→mentioned with→Solana(60%)
  • Jupiter Exchange→mentioned with→Solana(80%)

Connected Through

2 shared actors · 361 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about Fake Crypto AML Checker Infrastructure?

Timeline(6 events)

16 April 2025

AMLBot publishes initial warning on its official blog about fraudulent sites and Telegram accounts impersonating its brand, requesting wallet access and upfront payments.

AMLBot Blog

26 March 2025

PCrisk publishes removal guide for fake AMLBot website scam, identifying domains including amlbot.seize[.]report, amlbot[.]sale, amlbotchecks[.]com, and aml-safety[.]app, with IP 104.26.9.244.

PCrisk

26 June 2025

PCrisk publishes second removal guide documenting a distinct cluster of fake AMLBot domains including amlbotchecking[.]com, aml-bot.co[.]com, aml-safety[.]one, amlnix[.]com, and amlbot[.]club, with IP 104.21.15.211.

PCrisk

10 November 2025

AMLBot updates its official warning blog post, indicating the impersonation campaign has persisted for at least seven months.

AMLBot Blog

2 June 2026

PCrisk updates its second removal guide, confirming the second domain cluster remains active.

PCrisk

19 August 2026

Malwarebytes threat researcher Stefan Dasic publishes a report on the active fake AML checker campaign, documenting AMLBot impersonation, 'AML Check' generic branding, fake progress indicators, fabricated scan results, small upfront verification fees, and wallet drainer mechanics. Report corroborated same day by Decrypt, Security Boulevard, Cryptopolitan, and Coin-Turk.

Malwarebytes
Provenance & Audit Trail

Decision Log

  • #3review revise-13Recorded on Solana ✓8/25/2026, 2:47:05 AM
    slot 443510258 · hash 6zHNS1fCJzmsQctuzJQ6DsM6nCdQnh4pn5xKmhYK6xi6
  • #2reviewRecorded on Solana ✓8/25/2026, 2:47:05 AM
    slot 443510256 · hash 5xspGLCvnbJ4SjNHxQEmzw5CTcKbtJUMZKbWisVqoxqj
  • #1publishRecorded on Solana ✓8/24/2026, 11:04:14 PM
    slot 443510163 · hash 8yHLLNRvtdyAk188DoJGRsNkfvxZZ6trG7yX8iEr26aN

This investigation is cryptographically anchored to the Solana blockchain (3 decisions). 8 of 9 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/24/2026, 11:04:04 PM

last updated: 8/25/2026, 2:47:05 AM

4 views

avoid.net — verified advice for a post-truth world