A new exchanger quotes a good rate, then asks one thing before the swap: pass an AML check on a separate site. The site wants your wallet connected and a transaction confirmed. The check is theatre. The confirmation is the theft. Published for Cybersecurity Awareness Month 2026.
Scammers use “AML verification” as the pretext for a wallet drainer: a fake exchanger sends you to a separate “compliance” site that asks you to connect a wallet and approve a transaction, and the approval lets them move your tokens. A genuine screening needs only your public address, which is all that Address Check in the SimpleSwap Customer Account asks for.
The exchanger that wants your wallet checked somewhere else
The sequence reported across crypto communities this autumn runs like this. You find an exchanger, often through an ad or a search result, with a clean interface and a rate slightly better than the ones you know. You enter the amount. Before the deposit address appears, a message explains that the service must confirm your wallet is “clean,” and a button opens an AML check on another domain. That site asks you to connect your wallet, shows a progress bar over your transaction history, and returns a verdict: “Clean, Low Risk.” One more click to “confirm,” and you are sent back to the exchange. The swap never happens. Later, within minutes or within days, the wallet empties.
Nothing was hacked. The “confirm” was a token approval or a signature that let a contract spend what you hold.
A real check is a lookup. A fake one is a transaction.
On August 19, 2026, Malwarebytes published an analysis of fake AML checker sites, and its description of the genuine product is the whole defense in one line. A wallet screening looks at a public address’s transaction history for links to hacks, scams, sanctioned entities, or other suspicious activity, and in the researchers’ words, “it’s just a lookup.” The fakes prompt visitors to connect a wallet, simulate a scan with fake progress messages and results, then push an approval or a transaction. Some impersonate a legitimate screening service, AMLBot, copying its logo, layout, and language; others use generic names such as “AML Check.” Malwarebytes found the same template reused under different brands and listed domains such as bitget-aml[.]com and search-aml[.]net.
Decrypt summarized why the connection step matters even before anything is signed: connecting reveals the wallet’s public address, letting the operators see what is inside and craft a transaction worth asking for. Malwarebytes listed the moments to stop: an AML checker that asks you to connect your wallet, approve unexpected access to your tokens, confirm a transaction, send crypto to complete a check, or share a recovery phrase or private key. Security Boulevard quoted Sectigo’s Jason Soroko on the design: “This scam turns compliance into the lure.”
Why compliance works as a lure
It works because the audience is already careful. Someone who agrees to a wallet check is trying to do the right thing, and the scam borrows the vocabulary of the people who usually protect them. It also rides a wider wave. Chainalysis’s 2026 Crypto Crime Report estimated 2025 scam losses at roughly $17 billion, with impersonation scams up 1,400% year over year and the average scam payment rising from $782 to $2,764. Clone infrastructure is cheap: the Indian exchange CoinDCX said it had identified more than 1,200 websites impersonating its platform between April 2024 and January 2026, according to Decrypt.
What a genuine review looks like, and what it never looks like
Legitimate exchanges do run checks. A service that applies risk-based checks screens the deposit or the address, which it can do with the public address alone, because every transaction is already on-chain. If something needs a closer look, the service pauses that specific order and asks, through its own support channel and against the order ID, for information about the transaction or its source of funds; where identity verification is required, it happens inside the service’s own account flow, with documents rather than signatures. A genuine review never involves a link to a third-party site, a request to connect your wallet, a message or approval to sign, a fee to “release” the swap, or any question about a recovery phrase.
What a real check looks like in practice: Address Check
The same logic is available to you as a tool. Address Check, in the SimpleSwap Customer Account, takes an address you paste in, screens it through third-party services, and returns a risk level and the connections it finds. It asks for nothing else: no wallet connection, no signature, no fee. Account holders get a monthly number of checks set by their Loyalty Program tier. It is the opposite of the scam in every detail that matters, and it has the limits every real screening has: it doesn't replace your own checks and may not catch every issue.
What gives it away
The exchanger has no history you can verify, or a history that lives on another domain. The check happens on a different site from the exchange. The site asks you to connect rather than to paste an address. A verdict appears for whatever address you give it. The last step is a wallet prompt with words like Approve, Permit, Set Allowance or Confirm, naming a contract you do not recognize.
“Years of security education taught people one reflex: check before you send. This scam is built on that reflex. It hands you a fake check so you will skip the real one. The real one costs nothing and asks for nothing, which is exactly how you tell them apart,” said Rick Cramer.
The check: five steps
-
Close the page and sign nothing. An exchanger that sends you to another service to “verify your wallet” has told you what it is.
-
Use services with a history you can inspect: years online, a support channel that answers, a published account of how paused orders are handled. Reach them through a bookmark you created from a typed address, not through an ad or a search result.
-
Read the domain right to left before the first slash, every time. Clones copy the design; they cannot copy the domain. Our ten-second check shows how.
-
If you already connected and confirmed, act in this order: revoke the approval with your wallet’s own tools or a reputable revocation service, then move whatever remains to a fresh wallet. The approval phishing entry explains why both steps are needed and why minutes matter.
-
Report the domain to the impersonated brand and to the platform that showed you the ad.
What the check does not prove
A “Low Risk” verdict on any site proves nothing about the site. Revoking an approval protects what hasn't been taken yet; it cannot recall a transfer already mined. A familiar design, a padlock icon, and a convincing progress bar are available to anyone with a template, so the domain and the behavior are the only two things left to judge.
Where this meets your swap
SimpleSwap is a self-custodial, wallet-to-wallet swap aggregator that has run since 2018. You receive a deposit address on the order page, send from your own wallet, and the result arrives in a wallet you own. There is no wallet connection in that flow, and nothing to sign except your own outgoing transaction in your own wallet. Most crypto-to-crypto swaps need no account. KYC covers fiat purchases through payment partners and the optional one-time verification at registration, and KYC may be required for transaction security and compliance, as set out in the Anti-Financial Crime and KYC Policy. Transaction screening, where it applies, works from the addresses the chain already shows. If an order needs a closer look, its status will say so, and you can provide any requested information through live chat on simpleswap.io using your order ID. We never send you to another site to verify a wallet, ask you to connect one, or ask for a fee to release a swap.
We handle paused orders in live chat, never on a third-party site, and Address Check is available if you want to screen the other side before you send. The Safety Academy keeps the current list of tells. Our only official domain is simpleswap.io.
FAQ
What is the fake AML check scam?
A fake exchanger, or a clone of a real one, tells you your wallet must pass an AML check before a swap and sends you to a separate site. That site asks you to connect your wallet and confirm a transaction, which is a token approval or signature that lets the operators drain it. Malwarebytes documented the template in August 2026.
Does a real AML check require connecting my wallet?
No. A real screening reads the public transaction history of an address you paste in, and Malwarebytes describes it as “just a lookup.” Address Check in the SimpleSwap Customer Account works the same way. Any check that asks you to connect, sign, approve, or pay a fee is the scam.
I connected my wallet to a fake AML site. What should I do?
Revoke the approval immediately using your wallet’s tools or a reputable revocation service, then move remaining funds to a new wallet with a fresh seed phrase. Revocation protects only what hasn’t been taken yet, so speed matters. Report the domain to the impersonated brand.
Does SimpleSwap send users to another site for an AML check?
No. SimpleSwap never asks you to connect a wallet or visit a third-party site to verify it, and most crypto-to-crypto swaps need no account. KYC covers fiat purchases through payment partners and the optional verification at registration, and KYC may be required for transaction security and compliance. If an order needs additional review, you provide the requested information through the live chat on simpleswap.io using your order ID.
What comes next
This entry sits between two earlier ones: approval phishing, which explains the signature that does the damage, and the crypto scam map, which shows where clone sites fit among the rest. Check Before You Swap continues through October under #KnowTheScam.
This article is for educational purposes only and is not financial or investment advice. The services and tools named here are examples, not endorsements, and none replace your own judgment. SimpleSwap’s only official domain is simpleswap.io.