Wie die Masche funktioniert.
my-ethwallet.com gibt sich als legitime Ethereum-Wallet-Oberfläche aus und ahmt die visuelle Sprache und die Domainstruktur eines etablierten, weithin bekannten Ethereum-Wallet-Dienstes nach. Das gezielte Einfügen eines Bindestrichs und die Abkürzung von 'ether' zu 'eth' im Domainnamen entsprechen dem Muster des Typosquattings, einer Technik, die darauf ausgelegt ist, Nutzer abzufangen, die eine vertrauenswürdige URL falsch eintippen oder falsch in Erinnerung haben, ebenso wie solche, die über Phishing-Links oder betrügerische Anzeigen auf die Seite geleitet werden.
Auf der Seite angekommen, wird Besuchern in der Regel eine Oberfläche präsentiert, die einen echten Wallet-Dienst genau nachbildet und sie auffordert, eine Seed Phrase, einen privaten Schlüssel oder eine Keystore-Datei einzugeben, um auf ihre Wallet 'zuzugreifen'. Bei Operationen dieser Art werden sämtliche eingegebenen Zugangsdaten vom Betreiber erfasst. Die Seite funktioniert nicht als echte Wallet, sie ist eine Fassade zum Abgreifen von Daten. Nutzer, die sich authentifizieren, erhalten keinen tatsächlichen Wallet-Zugang; der Betreiber erhält alles, was nötig ist, um die zugehörigen Adressen leerzuräumen.
Der Punkt des Scheiterns wird offensichtlich, wenn Opfer versuchen, auf ihre Vermögenswerte zuzugreifen, und feststellen, dass diese an Adressen übertragen wurden, die sie nicht kontrollieren. Zu diesem Zeitpunkt ist die Seite möglicherweise bereits offline genommen oder ersetzt worden, und der Betreiber ist nicht erreichbar. Kryptowährungstransfers sind unumkehrbar, was bedeutet, dass jeder realistische Weg zur Wiedererlangung von der Nachverfolgung der weiteren Bewegung der Gelder über die Blockchain abhängt, nicht von einem Rückgriff auf die betrügerische Plattform selbst.
Warnsignale, die wir dokumentiert haben.
- 01Typosquatting domain targeting a recognised wallet brandThe domain my-ethwallet.com approximates the URL of a well-established Ethereum wallet service by abbreviating 'ether' to 'eth' and inserting a hyphen. This is a deliberate construction, not a coincidence, typosquatting domains require active registration and are purpose-built to intercept misdirected or deceived traffic.
- 02Credential-harvesting operation patternWallet impersonation platforms of this type derive their value entirely from capturing authentication credentials at point of entry. Any interface requesting a seed phrase, private key, or keystore file outside of locally-run, auditable open-source software should be treated as a harvesting operation until independently verified.
- 03CryptoScamDB blacklist inclusionThe domain appears on the CryptoScamDB community blacklist, a widely referenced registry of confirmed malicious cryptocurrency sites. Inclusion reflects corroborated reporting and is a recognised signal used by browser security extensions and wallet providers to warn users before credential submission occurs.
- 04No verifiable operator identity or regulatory standingLegitimate wallet services operating at scale maintain verifiable legal identities and, in many jurisdictions, regulatory registrations. This platform presents none of these. The absence of any traceable operator makes post-fraud recourse through conventional legal or financial channels structurally unavailable to victims.
- 05No auditable code or custody transparencyGenuine open-source wallet platforms publish verifiable source repositories and make custody arrangements explicit. A site mimicking this presentation without providing auditable code or independent security attestation offers users no means of confirming that submitted credentials are handled with any integrity.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.