Wie die Masche funktioniert.
Die Operation gibt sich als legitime Ethereum-Wallet-Oberfläche aus, indem sie einen Domainnamen verwendet, der das Branding eines weithin bekannten Selbstverwahrungs-Wallet-Dienstes nahezu exakt nachbildet und sich lediglich in der Top-Level-Domain unterscheidet. Die Website scheint darauf ausgelegt, Nutzer abzufangen, die über Phishing-Kanäle wie soziale Medien, E-Mail-Kampagnen oder Suchmaschinenanzeigen auf einen betrügerischen Link stoßen, anstatt über die organische Navigation zum legitimen Dienst.
Wallet-Imitationsplattformen dieser Art fordern private Zugangsdaten direkt von den Besuchern an: typischerweise eine Seed Phrase, einen Private Key oder eine verschlüsselte Keystore-Datei, vorgeblich zum Zweck des Wallet-Imports, der Kontowiederherstellung oder der Transaktionsautorisierung. Sobald ein Nutzer diese Zugangsdaten über die Weboberfläche übermittelt, erlangt der Betreiber vollen Zugriff auf alle Wallets, die diese Zugangsdaten kontrollieren. Gelder werden in der Regel rasch aus den kompromittierten Wallets abgezogen, und zwar mithilfe automatisierter Prozesse, die Abhebungen innerhalb von Minuten nach Erfassung der Zugangsdaten ausführen.
Der entscheidende Schwachpunkt ist unumkehrbar. Da Transaktionen im Ethereum-Netzwerk nicht zurückgerufen oder rückgängig gemacht werden können, sobald sie on-chain bestätigt sind, sind alle aus einer kompromittierten Wallet abgezogenen Vermögenswerte mit technischen Mitteln dauerhaft unwiederbringlich. Opfer entdecken den Verlust in der Regel erst beim Versuch, auf ihre echte Wallet zuzugreifen, wobei das Guthaben zu diesem Zeitpunkt bereits geleert ist und die betrügerische Plattform keinerlei Möglichkeit zur Anfechtung oder Wiedergutmachung gelassen hat.
Warnsignale, die wir dokumentiert haben.
- 01Exact brand impersonation via TLD substitutionThe domain reproduces the full name of a well-known Ethereum wallet platform, substituting only the top-level domain. This is a deliberate impersonation pattern intended to exploit user familiarity and typographical error. Visitors navigating to this address may reasonably believe they have reached the legitimate service.
- 02Non-standard TLD outside recognised registrar oversightThe ".aigo" extension does not correspond to any ICANN-recognised top-level domain. Legitimate financial services platforms do not operate from unrecognised TLDs. This choice of domain signals disposable infrastructure designed to evade conventional takedown processes.
- 03Presence on CryptoScamDB community blacklistThe domain is listed on CryptoScamDB's community-maintained blacklist, a database of addresses and URLs associated with documented cryptocurrency fraud. Inclusion reflects reported harmful activity and community verification of the warning.
- 04Credential-harvesting attack surfaceWallet impersonation operations solicit private keys and seed phrases through web forms. No legitimate wallet service requests these credentials via a browser interface. Any platform that does so should be treated as a credential-harvesting operation; submission results in total and irreversible loss of associated assets.
- 05No verifiable operator or regulatory identityThere is no documented company registration, regulatory licence, or verifiable operator identity associated with this domain, consistent with the anonymous, disposable infrastructure typically used in phishing campaigns targeting cryptocurrency holders.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.