canary

Scammers built fake wallet checkers. Here's how to check a wallet safely.

2026-08-30
what happened, plainly

What happened

This August, researchers at Malwarebytes documented a wave of fake wallet-checker sites — polished pages imitating legitimate AML and compliance services, at domains like amlbot-clear[.]com and bitget-aml[.]com. The pitch: check whether your wallet is linked to suspicious activity. The pages run fake progress bars — "Checking wallet history… Verifying compliance…" — and finish with a reassuring "Clean, Low Risk" (Malwarebytes).

The trap is in one step: the site asks you to connect your wallet to "get your results." The connection hands over nothing by itself — but the site then builds a transaction tailored to what your wallet holds and asks you to approve it. Approve, and you've signed away your tokens. The crueler variants skip the engineering and simply ask for your recovery phrase.

What makes this one sting: it preys precisely on the people doing the right thing. You were trying to check your wallet. So were we all — which is why the rule below matters more than any list of scam domains, because the domains change weekly.

The one rule for checking a wallet safely

A real wallet checker takes a public address. A trap asks for a connection.

Everything a legitimate checker needs is already public. Your address's history, balances, and standing token permissions are visible to anyone on the blockchain — reading them requires no connection, no signature, and certainly no seed phrase. If a "checker" asks you to connect a wallet, approve anything, pay an "unlock fee," or type a recovery phrase: close the tab. There is no legitimate reason a read-only check needs the ability to spend.

Three quick habits: type the checker's domain yourself rather than following an ad or a DM; treat "connect to see results" as the tell it is; and if you ever did approve something on a site like this, revoke that approval now — Revoke.cash is the right free tool for cancelling EVM token approvals.

check the safe way

Paste an address — never connect, never sign.

This check is read-only by construction: it takes the same public address you'd give anyone to receive money, and nothing else. No connection, no signature, no keys, no fee.

Public addresses only. Never a seed phrase, never a key.

Hold us to the same rule

Canary is itself a wallet checker, so hold us to the standard this post sets: we ask for a public address only, we never request a wallet connection or a signature, and an account here is a username and a password — not even an email. And honestly: no checker, ours included, can see what you sign inside your wallet at the moment you click. That protection has to live in the habit above. Exactly what we read, and what we can't see.