Wie die Masche funktioniert.
myetherwallet.info gibt sich als funktionsfähige Ethereum-Wallet-Oberfläche aus und zielt auf Nutzer ab, die nach einem Wallet-Zugang suchen oder eine vertraute Adresse in ihrem Browser falsch eintippen. Die Domain ahmt jene eines anerkannten Anbieters von Kryptowährungs-Wallets eng nach und setzt auf die optische Ähnlichkeit zwischen ihrer .info-Endung und dem etablierten .com-Gegenstück, um einen Eindruck von Seriosität zu erzeugen. Die anvisierte Zielgruppe sind Ethereum-Inhaber, die der nachgeahmten Marke bereits vertrauen und die Domain-Endung kaum prüfen dürften.
Operationen dieser Art reproduzieren in der Regel das visuelle Design des echten Dienstes mit hoher Genauigkeit und fordern Besucher auf, Wallet-Zugangsdaten wie Private Keys, Seed Phrases oder Keystore-Dateien einzugeben, um Zugriff auf ihre Bestände zu erhalten. Da die Oberfläche dem authentischen Produkt gleicht, geben Nutzer häufig ihr sensibelstes kryptografisches Material ohne Argwohn preis. Der Betreiber erfasst diese Daten serverseitig und nutzt sie, um die zugehörigen Wallets zu leeren, oft innerhalb von Minuten nach der Eingabe.
Der kritische Moment tritt ein, wenn ein Opfer versucht, eine Transaktion abzuschließen oder einen Kontostand abzurufen, und die Oberfläche nicht reagiert, oder feststellt, dass seine echte Wallet von einer externen, ihm unbekannten Adresse aus geleert wurde. Zu diesem Zeitpunkt hat der Betreiber die Zugangsdaten bereits abgegriffen. Die Wiederbeschaffung von Vermögenswerten, die aus einer kompromittierten Self-Custody-Wallet abgeflossen sind, ist technisch äußerst schwierig, da die Transaktion durch den eigenen Private Key des Opfers authentifiziert wird und sich daher On-Chain nicht von einer freiwilligen Überweisung unterscheiden lässt.
Warnsignale, die wir dokumentiert haben.
- 01Domain Mimics a Recognised Wallet BrandThe .info domain closely replicates a well-established .com wallet address, a pattern consistent with typosquatting designed to intercept users who mistype or follow a malicious link. No affiliation with the original service exists, and the choice of extension appears deliberate.
- 02Listed on CryptoScamDB Community BlacklistThe domain appears in the CryptoScamDB blacklist, a community-maintained registry of confirmed malicious cryptocurrency sites. Inclusion reflects prior community-verified harm and is treated by security tooling as grounds for automatic blocking.
- 03Credential Entry Pattern Signals Harvesting OperationWallet impersonation platforms of this type solicit private keys, seed phrases, or keystore files. Legitimate non-custodial wallet interfaces do not require these credentials to be entered on a website under any circumstances. Any platform that does should be treated as hostile.
- 04No Verifiable Operator or Regulatory StandingThe domain carries no documented organisational identity, regulatory authorisation, or verifiable legal presence. Legitimate custodial or financial services are required to disclose these details in most jurisdictions; their absence is a material signal of illegitimacy.
- 05Asset Exposure is Immediate and IrreversibleOnce credentials are submitted to a harvesting operation, the operator can drain associated wallets within minutes. Blockchain transactions are irreversible and carry no chargeback mechanism. The window for any meaningful intervention is extremely narrow.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.