Wie die Masche funktioniert.
Diese Operation gibt sich als vertrauenswürdige Ethereum-Wallet-Oberfläche aus und nutzt den Bekanntheitsgrad einer weithin anerkannten Marke für selbstverwahrte Wallets aus. Die Konstruktion der Domain ahmt jene eines legitimen Dienstes genau nach und hängt ein nicht standardmäßiges Suffix an, um die Namensverwechslung zu maximieren und zugleich eine glaubhafte Abstreitbarkeit zu wahren. Die anvisierte Zielgruppe sind Ethereum-Inhaber, insbesondere jene, die einen Wallet-Dienst aus dem Gedächtnis oder über einen ungeprüften Link ansteuern.
Das Betrugsmuster beruht auf Typosquatting und dem Abgreifen von Zugangsdaten. Nutzern, die über eine falsch getippte URL, einen Phishing-Link oder ein gesponsertes Suchergebnis ankommen, wird eine Nachbildung einer vertrauten Wallet-Oberfläche präsentiert. Das Ziel des Betreibers besteht darin, die Seed-Phrase oder den privaten Schlüssel des Besuchers im Moment der Eingabe zu erfassen. Sind diese Zugangsdaten einmal übermittelt, verschaffen sie dem Betreiber die vollständige und unumkehrbare Kontrolle über die zugehörige Wallet, ohne dass über die Plattform selbst irgendein Rechtsmittel zur Verfügung steht.
Der Zusammenbruch wird offenkundig, wenn ein Opfer versucht, auf seine legitime Wallet zuzugreifen, und das Guthaben an eine unbekannte Adresse überwiesen vorfindet. Zu diesem Zeitpunkt ist die On-Chain-Transaktion unumkehrbar. Der Betreiber wird die Mittel typischerweise über weitere Adressen geleitet haben, um die Nachverfolgung zu erschweren. Die betrügerische Domain wird häufig kurz, nachdem sich Beschwerden in öffentlichen Blacklist-Verzeichnissen häufen, offline genommen oder umgeleitet, sodass den Ermittlern kaum operative Spuren bleiben, denen sie nachgehen könnten.
Warnsignale, die wir dokumentiert haben.
- 01Domain Impersonation PatternThe domain closely replicates the name of a well-established Ethereum wallet service, appending a non-standard suffix. This is a textbook typosquatting construction designed to intercept users who navigate slightly off-course or follow an unverified link, relying entirely on borrowed brand trust rather than any legitimate service offering.
- 02Listed on CryptoScamDB BlacklistThe domain appears in the CryptoScamDB maintained blacklist, a community-verified registry of fraudulent cryptocurrency addresses and domains. Inclusion follows a review process and is used as a primary indicator by wallet providers, browser security extensions, and anti-phishing tools.
- 03Credential Harvesting OperationAny wallet interface that solicits a seed phrase or private key over the internet represents a recognised vector for total, irreversible asset loss. Legitimate self-custody wallet software does not transmit these values to any external server under any circumstances; a platform that does is operating against the user's interests.
- 04No Verifiable Operator IdentityThe operation presents no auditable business registration, no named team, and no regulatory authorisation in any jurisdiction. The absence of accountable ownership is structurally consistent with fraudulent intent and renders post-loss civil or criminal recovery significantly more difficult.
- 05Appended Trust Signal on DomainThe suffix appended to the domain translates as 'safety' or 'security' in Mandarin, a linguistic device sometimes used to reassure users from Chinese-speaking communities or to add an air of legitimacy through a term that appears authoritative to an unfamiliar reader.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.