Wie die Masche funktioniert.
Die Website gibt sich als legitime Ethereum-Wallet-Oberfläche aus und stützt sich dabei auf die Namenskonventionen von MyEtherWallet, einem weithin bekannten Self-Custody-Wallet-Werkzeug. Die Domain übernimmt den Namen MyEtherWallet innerhalb einer unkonventionellen Top-Level-Struktur und positioniert sich so, dass sie Nutzer abfängt, die über vertippte URLs oder manipulierte Suchergebnisse zum echten Dienst navigieren. Die offensichtliche Zielgruppe sind Ethereum-Inhaber, die Zugang zu einer Self-Custody-Wallet suchen.
Operationen dieses Musters funktionieren als Fassaden zum Abgreifen von Zugangsdaten. Eine nachgebildete Oberfläche fordert Nutzer auf, private Schlüssel, Seed-Phrasen oder Keystore-Dateien unter dem Vorwand des Wallet-Zugangs oder der Kontowiederherstellung einzugeben. Der Betreiber sammelt diese Zugangsdaten unbemerkt; der Nutzer sieht möglicherweise eine plausible Fehlermeldung oder einen Ladebildschirm, während die übermittelten Daten an eine vom Betreiber kontrollierte Infrastruktur weitergeleitet werden. Zu keinem Zeitpunkt erhält der Nutzer Zugang zu einer funktionierenden Wallet.
Der Moment der Entdeckung tritt typischerweise ein, wenn Nutzer zu ihrer echten Wallet zurückkehren und ihre Bestände nicht mehr vorfinden, oder wenn sie eine Transaktion versuchen und auf Fehler stoßen, die sich nicht durch die Netzwerkbedingungen erklären lassen. Zu diesem Zeitpunkt hat der Betreiber die Vermögenswerte bereits auf Adressen außerhalb der Kontrolle des Opfers übertragen. Wiederherstellungsbemühungen werden durch die pseudonyme Natur der On-Chain-Bewegungen und das völlige Fehlen einer überprüfbaren organisatorischen Identität hinter der betrügerischen Domain erschwert.
Warnsignale, die wir dokumentiert haben.
- 01Lookalike brand impersonation via domain nameThe domain reproduces the name of a well-known, legitimate Ethereum wallet service within an unconventional top-level structure. This is a recognised hallmark of phishing operations engineered to intercept users before they reach the genuine service. MyEtherWallet, the brand being imitated, has no association with this domain.
- 02Unconventional top-level domain signals no accountabilityEstablished wallet providers operate under standard, verifiable top-level domains with traceable registration histories. The use of a non-standard top-level identifier here provides no institutional accountability and no established trust signal. Legitimate financial services do not operate under structures of this kind.
- 03CryptoScamDB blacklist listingThe domain is listed on the CryptoScamDB community blacklist, a broadly referenced index maintained by security researchers who actively catalogue fraudulent cryptocurrency infrastructure. Inclusion reflects documented community reporting of harmful activity associated with the domain.
- 04Credential-harvesting risk profile consistent with wallet-impersonator patternWallet-interface impersonators of this type are built specifically to capture private keys or seed phrases, which grant irreversible access to all funds in the associated wallet. Any site presenting itself as a wallet login or recovery tool that is not the independently verified original carries a substantive theft risk.
- 05No verifiable operator identity or regulatory presenceNo company registration, regulatory filing, or traceable organisational identity is associated with this domain. Legitimate wallet services maintain public accountability channels and verifiable legal entities. The complete absence of any such presence removes any basis for trust or recourse.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.