Wie die Masche funktioniert.
Diese Operation nutzt den Namen und die scheinbare Identität eines weithin bekannten Ethereum-Dienstes zur Selbstverwahrung von Wallets aus. Die Domain übernimmt den Namen der nachgeahmten Marke nahezu wortgleich und positioniert die Seite so, dass sie Besucher abfängt, die sich bei einer URL vertippen, einem Link in einer Phishing-Nachricht folgen oder über manipulierte Suchergebnisse auf die Seite gelangen. Die Top-Level-Domain .airforce ist die einzige offenkundige Abweichung von der imitierten Marke, ein Detail, das unaufmerksame Nutzer unter Zeitdruck oder bei leichter Ablenkung wahrscheinlich übersehen.
Operationen dieser Art präsentieren eine Nachbildung der nachgeahmten Oberfläche und fordern Besucher auf, sich durch Eingabe eines Private Keys, einer Seed Phrase oder einer Keystore-Datei zu authentifizieren. Dies ist der zentrale Mechanismus: Die Oberfläche muss nicht als Wallet funktionieren, um erfolgreich zu sein. Sie muss den Nutzer nur einmal davon überzeugen, seine Zugangsdaten einzugeben. Diese Zugangsdaten werden an den Betreiber übermittelt, der anschließend eigenständig und zu einem von ihm gewählten Zeitpunkt auf die entsprechenden Wallets zugreifen kann. Die Seite kann eine erfolgreiche Anmeldung vortäuschen, um den Verdacht hinauszuzögern.
Opfer entdecken den Betrug in der Regel, wenn sie nach einer scheinbar routinemäßigen Anmeldung feststellen, dass ihr Wallet-Guthaben aufgebraucht ist. Da On-Chain-Überweisungen unumkehrbar sind, ist das Zeitfenster zwischen der Eingabe der Zugangsdaten und dem Abzug der Gelder oft der einzige Punkt, an dem ein Eingreifen theoretisch möglich ist, und es schließt sich schnell. Bis eine Beschwerde eingereicht wird, hat der Betreiber die Gelder meist über weitere Adressen verschoben, und die Phishing-Infrastruktur selbst wurde möglicherweise bereits abgeschaltet oder auf eine neue Domain verlagert.
Warnsignale, die wir dokumentiert haben.
- 01Brand impersonation in the domain nameThe domain reproduces the name of a legitimate, well-established Ethereum wallet service with no meaningful alteration. This is a deliberate tactic: the closer a fraudulent domain sits to a trusted name, the less cognitive effort a victim needs to expend to accept it as genuine.
- 02Anomalous top-level domain for a financial interfaceLegitimate cryptocurrency wallet services operate under conventional TLDs. The use of .airforce for what purports to be a wallet interface has no plausible commercial rationale and is a recognised marker of opportunistic phishing infrastructure assembled quickly and cheaply.
- 03CryptoScamDB blacklist inclusionThe domain appears on the CryptoScamDB community blacklist, a collaboratively maintained register of confirmed malicious cryptocurrency addresses and domains. Inclusion indicates the site has been independently identified as a threat by researchers outside CryptoLeek.
- 04Credential-request pattern inconsistent with legitimate wallet operationAny web-based interface that requests a private key or seed phrase to grant wallet access is operating outside the security model of self-custody. Legitimate wallet interfaces of the type being impersonated here do not require server-side submission of these credentials under any normal circumstances.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.