Wie die Masche funktioniert.
Der Domainname ist so konstruiert, dass er an einen großen Ethereum-Wallet-Dienst erinnert, kombiniert mit einer Top-Level-Domain, die mit einem weltweit bekannten Technologieunternehmen verbunden wird. Die Wirkung ist eine Außendarstellung, die den Opfern entweder als offizielle Produktintegration oder als genehmigte Partnerschaft zwischen zwei vertrauenswürdigen Marken erscheinen kann. Die Website repliziert wahrscheinlich das visuelle Design einer legitimen Wallet-Oberfläche und zielt auf Nutzer ab, die Ethereum-basierte Vermögenswerte halten oder verwalten und möglicherweise über Suchergebnisse, Links in sozialen Medien oder Phishing-E-Mails dorthin gelangen.
Websites dieses Musters fungieren als Schnittstellen zum Abgreifen von Zugangsdaten. Wenn ein Besucher versucht, auf eine Wallet zuzugreifen oder sie zu importieren, fordert die Plattform einen privaten Schlüssel, eine mnemonische Seed-Phrase oder eine verschlüsselte Keystore-Datei an. Diese Zugangsdaten werden nach der Übermittlung an den Betreiber übertragen, anstatt lokal auf dem Gerät verarbeitet zu werden. Der Betreiber nutzt die erfassten Zugangsdaten dann, um eigenständig auf die Wallet des Opfers zuzugreifen und sie zu leeren, in der Regel innerhalb weniger Minuten nach der Übermittlung und ohne weiteres Zutun des Opfers.
Der Betrug wird offensichtlich, wenn das Opfer eine Transaktion durchführen will und feststellt, dass das Guthaben bereits an eine unbekannte Adresse verschoben wurde. Zu diesem Zeitpunkt ist die Überweisung On-Chain unwiderruflich. Der Betreiber gibt die Domain in der Regel nach einer Phase aktiven Abgreifens von Zugangsdaten auf und hinterlässt keinen funktionierenden Kontaktpunkt, keinen Support-Kanal und keinen Mechanismus, über den das Opfer direkt mit der Plattform eine Beschwerde oder Wiederherstellung einleiten könnte.
Warnsignale, die wir dokumentiert haben.
- 01Domain constructed to mimic a recognised wallet brandThe domain combines a name closely associated with a well-established Ethereum wallet service with a top-level domain tied to a major technology company. This pairing is a deliberate impersonation signal, not an affiliation. No legitimate wallet provider operates under such a domain construction, and neither referenced brand has any documented connection to this property.
- 02Confirmed listing on CryptoScamDB community blacklistThe domain appears on the CryptoScamDB blacklist, a community-maintained repository used by wallet providers and browser security tools to flag known phishing infrastructure. Inclusion reflects reported harm, not merely theoretical risk, and indicates the domain has been reviewed and flagged by the fraud-monitoring community.
- 03No verifiable operator identity or regulatory standingThere is no verifiable company registration, regulatory disclosure, or terms of service associated with this domain. Legitimate wallet services, whether custodial or non-custodial, maintain auditable legal identities. This operation presents none of those attributes, which is consistent with infrastructure designed for short-term exploitation rather than sustained legitimate service.
- 04Credential solicitation is the central operational patternPhishing platforms of this category are built around a single objective: capturing wallet credentials. Any interface that requests a private key, seed phrase, or keystore file outside of a locally-verified, open-source application environment should be treated as a hostile data collection point, regardless of how legitimate the visual presentation appears.
- 05No operational history, community presence, or audit trailThe domain has no documented operational history, independent security audit, or active user community. Operations that carry no verifiable track record and simultaneously appear on fraud databases are consistent with short-lived phishing infrastructure, deployed quickly, exploited, and abandoned before victims can coordinate a response.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.