< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 3 sources · 12 days · First seen · Last updated

Cryptocurrency wallet theft via impersonation scams

Overview

Cybercriminals are employing various methods to drain cryptocurrency wallets by impersonating trusted services. Initially, malicious developers utilized major app stores, such as Apple and Google, to distribute counterfeit wallet applications. These clones, which impersonate brands like Wasabi Wallet and Ledger, exploit user trust to steal seed phrases and drain assets. Some developers bypass security by submitting harmless apps that only reveal malicious behavior after approval.

More recently, scammers have shifted toward fraudulent anti-money laundering (AML) screening websites. These sites, often impersonating services like AMLBot, prompt users to connect their wallets to view compliance reports. While connecting a wallet only reveals a public address, it allows attackers to identify held assets and craft specific, malicious transactions. Once a victim approves these unexpected transactions, their funds are transferred to the attackers.

Entities

Malwarebytes · AMLBot

Timeline

  1. 28 days ago

    [TECHNOLOGY] 3 sources
    Fake crypto AML checkers used to drain user wallets

    Scammers are using fake anti-money laundering (AML) websites to trick cryptocurrency users into approving transactions that drain their wallets.

  2. about 1 month ago

    [TECHNOLOGY] 2 sources
    Fake cryptocurrency wallet apps drain funds on major app stores

    Counterfeit cryptocurrency wallet apps on the Apple App Store and Google Play are draining user funds by impersonating trusted brands like Wasabi Wallet and Ledger to steal seed phrases.

Sources

bitcoinethereumnews.com · cryptopolitan.com · malwarebytes.org