Wie die Masche funktioniert.
Der Betrieb tritt unter einem Domainnamen auf, der an einen bekannten Ethereum-Wallet-Dienst erinnern soll, ergänzt um ein Suffix, das offizielle Analyse- oder Kontoverwaltungswerkzeuge suggerieren soll. Die Konstruktion ist bewusst gewählt: Nutzer, die nach Wallet-Dashboards, Guthabenabfragen oder Transaktionsverläufen suchen, treffen wahrscheinlich auf diese Domain als scheinbar plausible Erweiterung einer Marke, der sie bereits vertrauen. Die angesprochene Zielgruppe sind Inhaber von Ether und ERC-20-Token, die einen seriösen ergänzenden Dienst suchen.
Wallet-Betriebe dieser Art, die auf Markenimitation setzen, reproduzieren Oberflächenelemente des seriösen Dienstes, den sie nachahmen, um die Misstrauensschwelle der Nutzer zu senken. Anschließend fordert der Betreiber Authentifizierungsdaten ein: Private Keys, Seed Phrases oder Genehmigungen für Wallet-Verbindungen. Bei Varianten mit Drain-Contract überträgt eine einzige signierte Transaktion sämtliche Vermögenswerte an Adressen unter der Kontrolle des Betreibers. Das nicht standardmäßige TLD-Suffix erzeugt eine scheinbare Distanz zu plumpen Nachahmungsmustern, während es zugleich von der Markenbekanntheit profitiert.
Der Moment des Verlusts geht dem Bewusstsein des Opfers in der Regel voraus. Werden Private Keys oder Seed Phrases übermittelt, erlangt der Betreiber dauerhaften, unwiderruflichen Zugriff auf alle zugehörigen Wallet-Adressen. Bei Varianten mit Drain-Contract wird die Entleerung der Vermögenswerte möglicherweise erst bemerkt, wenn das Opfer sein Guthaben prüft. Es gibt keinen Support-Kanal, keine dokumentierte Organisation und keine erreichbare Gegenpartei. Domains dieser Art werden regelmäßig aufgegeben, sobald die Erkennungsraten steigen, und lassen die Opfer ohne nachvollziehbare operative Spur zurück.
Warnsignale, die wir dokumentiert haben.
- 01Domain constructed to impersonate a recognised wallet brandThe domain name combines the exact string of a well-known Ethereum wallet service with an appended suffix, a pattern consistent with impersonation operations designed to capture traffic from users mistyping or misremembering a legitimate address. The legitimate service has no affiliation with this domain.
- 02Non-standard top-level domain used as a legitimacy signalThe use of a non-standard TLD suffix mimicking a professional-sounding category is a recognised tactic for creating apparent distance from crude typosquat patterns while still exploiting brand recognition. Legitimate wallet services do not distribute functionality across speculative or unrecognised top-level domains.
- 03Listed on the CryptoScamDB community blacklistThe domain appears in the CryptoScamDB blacklist, a publicly maintained registry of addresses associated with fraudulent cryptocurrency operations. Inclusion reflects reported user harm or structural characteristics consistent with credential harvesting or asset theft.
- 04No documented operator, registration, or legal entityOperations of this type carry no verifiable corporate identity, no regulatory registration, and no auditable organisational structure. The absence of a recoverable entity removes any legal or contractual recourse for victims once assets have been transferred on-chain.
- 05Credential-harvesting pattern consistent with phishing infrastructureWallet impersonation sites in this category are structurally designed to elicit private keys, seed phrases, or on-chain approvals rather than to provide genuine services. Once any such credential is submitted, the victim's assets are at immediate and irreversible risk regardless of any subsequent action taken.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.