Wie die Masche funktioniert.
Die Domain myetherwallet.airbus ist so aufgebaut, dass sie den Namen einer etablierten Open-Source-Ethereum-Wallet-Oberfläche genau nachahmt. Sie fügt eine Unternehmens-Top-Level-Domain an, die auf einen nicht verwandten Luftfahrthersteller registriert ist, und verleiht der Adresse damit oberflächlich den Anschein institutioneller Rückendeckung. Nutzer, die über ein Suchergebnis, einen Phishing-Link oder eine Empfehlung in sozialen Medien gelangen, halten die Domain ohne genauere Prüfung womöglich für legitim.
Operationen dieser Art reproduzieren in der Regel das visuelle Design des Dienstes, den sie imitieren, und übernehmen Layout, Farbschema und Wallet-Verbindungsabläufe der echten Plattform. Der Betrugsmechanismus besteht im Abgreifen von Zugangsdaten: Opfer werden aufgefordert, private Schlüssel oder Wiederherstellungs-Seed-Phrasen einzugeben oder Transaktionen zu signieren, die dem Betreiber Zugriff auf den Wallet-Inhalt gewähren. Eine einzige Interaktion reicht oft aus, um eine gesamte Wallet zu kompromittieren, da die Zugangsdaten der Selbstverwahrung die einzige Authentifizierungsebene sind, die die zugehörigen Mittel schützt.
Opfer entdecken den Verlust im Allgemeinen erst, nachdem die Mittel ihre Wallets verlassen haben, zu welchem Zeitpunkt die Transaktion auf der öffentlichen Blockchain unumkehrbar ist. Der Betreiber kann die betrügerische Seite nach Belieben offline nehmen oder umleiten, wodurch der zentrale Kontaktpunkt entfällt und ein Großteil der zugänglichen Beweise verschwindet. Sämtliche Support- oder Wiederherstellungskanäle, die auf der betrügerischen Domain dargestellt oder von ihr verlinkt werden, sollten als Teil der Operation selbst behandelt werden und nicht als legitimer Weg zur Schadensregulierung.
Warnsignale, die wir dokumentiert haben.
- 01Domain constructed to impersonate a recognised wallet serviceThe domain name reproduces the name of a well-known Ethereum wallet interface with a near-identical string, a textbook brand-impersonation pattern. Operators use this technique to intercept users who mistype a URL or arrive via deceptive links, exploiting the brand recognition of the legitimate service without any authorisation to do so.
- 02Misappropriated corporate top-level domainThe .airbus TLD is a brand top-level domain registered to a major aerospace corporation with no documented involvement in cryptocurrency services. Its use here appears intended to lend the domain a veneer of institutional legitimacy. No affiliation between the operator of this domain and the TLD's rightful registrant has been established.
- 03Listed on the CryptoScamDB community blacklistThe domain appears on the CryptoScamDB blacklist, a widely referenced registry used by browser extensions, wallet software, and security tooling to block known phishing and fraud infrastructure. Inclusion reflects community-sourced evidence of malicious activity and is consistent with the confirmed-scam verdict.
- 04Wallet credential harvesting patternPlatforms impersonating self-custody wallet interfaces are almost exclusively designed to capture private keys or seed phrases. Unlike exchange-based phishing, which may allow partial administrative recovery, the theft of a seed phrase grants full and permanent control over all associated assets, with no on-chain recovery mechanism available.
- 05No verifiable operator or regulatory presenceNo documented corporate registration, regulatory authorisation, or auditable team identity is associated with this domain. Legitimate wallet providers operating in recognised jurisdictions maintain verifiable legal identities. The absence of any such presence is consistent with the operational profile of a short-lived phishing asset designed to be discarded after use.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.