Scammers Are Now Impersonating Compliance Tools to Get You to Sign the Drain
Fake crypto AML checking services are luring users into approving transactions that hand over their assets. The pitch works because it borrows the language of safety.
A new class of wallet drainer is dressing itself up as a compliance product. Scammers are impersonating crypto anti-money-laundering checking services and using them to trick users into approving transactions that put their holdings at risk, according to Decrypt.
The mechanic is worth understanding because it is not a private key theft. When you interact with a smart contract from a self-custody wallet, you sign a message. Some of those messages are transfers. Others are approvals, which grant a contract permission to move a particular token out of your wallet in future, often without a cap on the amount and without a further prompt. A drainer does not need your seed phrase. It needs one approval signature, and then it can withdraw at its leisure.
Why the compliance costume works
The specific choice of disguise is the clever part. AML checkers are real products. They exist because exchanges and off-ramps screen incoming deposits against sanctions lists and known illicit clusters, and users who have received funds from an unknown counterparty have a genuine reason to want to know whether their address is tainted before they deposit somewhere.
That anxiety is the attack surface. A site offering to check whether your wallet is clean is speaking directly to a fear the user already has, and it arrives wearing the vocabulary of regulation rather than the vocabulary of profit. There is no promised yield, no airdrop, no urgency about a price. It looks like due diligence. Then it asks you to connect and sign something to run the check, and the signature is the whole product.
The tell
A genuine address screening service does not need a signature. Checking whether an address appears on a sanctions list or in a flagged cluster is a read operation performed against public blockchain data and public lists. It requires the address, which you can paste in as text, and nothing else. Any tool that asks you to connect a wallet and approve a transaction in order to tell you about your own wallet is asking for something it does not need to do the stated job.
The general defensive posture applies here as it does to every drainer. Read what you are signing rather than the site that is asking. Wallet interfaces that decode approvals will tell you which token and which spender is involved, and an unlimited approval to an address you have never heard of is not a compliance check. Existing approvals can be reviewed and revoked, and periodically doing so limits the blast radius of anything you signed on a bad day.
Where this fits
This paper does not republish claim links, contract addresses or domains from unverified sources, and we are not naming the fake services here, because naming them mostly serves to spread them. The pattern is the transferable information: the current generation of drainers has moved past greed as a hook and is now working the safety instinct instead.
Expect the costume to keep improving. Compliance, insurance, wallet recovery and revocation tools all share the same rhetorical advantage, in that they present themselves as the thing that protects you from the last scam. The signature request at the end is unchanged.
We report facts in our own words and link to the reporting we drew them from. We do not reproduce a source's prose, headline or images. Nothing here is investment advice.