Fake crypto screening sites turn security checks into wallet theft
THE BRIEF
A genuine basic screening needs only a public wallet address. The suspicious sites instead learn which assets the wallet holds and generate a transaction or token-approval request tailored to that address. Fake progress bars, compliance messages, small “fee” errors and reassuring low-risk results make the process look like a normal check. The same design appeared under several names, suggesting a reusable scam kit. Connecting a wallet alone does not necessarily transfer funds. The danger increases when the user approves token access, signs an unexpected transaction, sends cryptocurrency or enters a recovery phrase or private key. A recovery phrase gives complete control and should never be entered into a screening site. The observed sites and behavior are confirmed by the primary security research. Public reporting does not establish how many people lost funds. Users who interacted should disconnect the site, review approvals, inspect transactions and move remaining assets to a new wallet if sensitive signing information was exposed.
WHY IT MATTERS
The scam exploits people precisely when they are trying to behave safely. Familiar compliance language and a polished interface can persuade a cautious user to authorize a transaction they would reject in another context. Because cryptocurrency transfers are usually irreversible, a brief moment of approval can create permanent loss. Banks, exchanges and wallet providers should explain the difference between entering a public address for analysis and granting a website permission to control tokens or request signatures. The result can be lost money, account disruption and long recovery work for affected people.
WHO SHOULD CARE
Cryptocurrency holders, exchange customers, compliance teams, wallet providers and families helping less-experienced investors should care because a fake safety check can lead directly to irreversible asset loss or full wallet compromise. They need clear steps because delays can increase financial, privacy or operational harm.
WHAT TO DO NOW
- Use only a public wallet address for a basic screening and do not connect the wallet.
- Reject unexpected token approvals, signatures, transfers or fee requests.
- Verify the service’s domain through an independent official source rather than an advertisement.
- Disconnect suspicious applications and revoke unknown token permissions.
- Move remaining funds to a new wallet if a recovery phrase, private key or unsafe transaction was exposed.
- Ignore paid recovery offers and preserve the fraudulent domain and transaction details for reporting.
VERIFICATION NOTE
Verified as primary security research from Malwarebytes, including observed impersonation domains, wallet-connection flows and fabricated result screens. The research demonstrates the theft mechanism but does not publish a confirmed victim count or total losses. The brief therefore distinguishes the documented scam infrastructure from any estimate of campaign scale. That limitation is reflected in this assessment.