Wie die Masche funktioniert.
Die Website gibt sich als legitime Ethereum-Wallet-Oberfläche aus und borgt sich dabei den Namen sowie die unterstellte Reputation eines etablierten Wallet-Dienstes. Die operative Oberfläche, der Domainname, das mutmaßliche visuelle Design und die nutzerseitige Sprache sind so konstruiert, dass sie auf den ersten Blick nicht von der echten Plattform zu unterscheiden sind. Die Zielgruppe besteht aus Ethereum-Nutzern, die Zugang zu ihrer Wallet suchen, insbesondere aus jenen, die über Suchmaschinen, Social-Media-Links oder weitergeleitete URLs gelangen statt über manuell gesetzte Lesezeichen.
Die Mechanik folgt dem üblichen Modell des Abgreifens von Zugangsdaten, das bei Wallet-Phishing-Operationen verbreitet ist. Besucher werden aufgefordert, eine Seed-Phrase, einen privaten Schlüssel oder eine Keystore-Datei einzugeben, getarnt als Anmeldung oder Wiederherstellung des Kontozugangs. Der Betreiber erfasst diese Zugangsdaten serverseitig im Moment der Eingabe. Da private Ethereum-Schlüssel eine bedingungslose, unwiderrufliche Kontrolle über die zugehörigen Gelder gewähren, genügt eine einzige erfolgreiche Erfassung, um sämtliche in der betroffenen Wallet gehaltenen Vermögenswerte zu leeren; eine weitere Interaktion des Opfers ist nicht erforderlich.
Der Schaden wird typischerweise erst sichtbar, nachdem die Zugangsdaten bereits übermittelt wurden. Nutzer bemerken entweder, dass die Oberfläche einen Fehler ausgibt, unerwartet weiterleitet oder scheinbar normal funktioniert, während ein paralleler Prozess die Wallet im Stillen leert. Bis die Unstimmigkeit untersucht wird, hat der Betreiber die Gelder bereits über eine oder mehrere zwischengeschaltete Adressen verschoben, was eine Nachverfolgung auf der Blockchain ohne spezialisierte Werkzeuge erschwert. Innerhalb der Plattform existiert kein Wiederherstellungs- oder Beschwerdemechanismus, denn ein solcher war nie vorgesehen.
Warnsignale, die wir dokumentiert haben.
- 01TLD substitution as impersonation techniqueThe domain replicates the name of a recognised Ethereum wallet service while substituting a different top-level domain. This pattern, known as TLD spoofing, is a deliberate attempt to exploit typographical error and user inattention. Legitimate wallet providers do not operate across multiple conflicting TLDs.
- 02.su TLD registration patternThe .su ccTLD (administered for the former Soviet Union) remains operational and is disproportionately represented in fraud and phishing infrastructure due to minimal registration oversight and enforcement cooperation. Its use here provides no legitimate geographic or operational justification.
- 03CryptoScamDB blacklist confirmationThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained dataset used by wallet software, browser extensions, and security researchers to block known malicious addresses. Inclusion reflects documented community reports, not automated heuristics alone.
- 04Private-key harvest, irreversible loss exposureWallet phishing operations targeting seed phrases or private keys expose victims to total, permanent asset loss. Unlike payment card fraud, there is no chargeback mechanism and no custodial institution to contest with. Any platform requesting a private key or seed phrase outside of a locally-running, verifiable application should be treated as hostile.
- 05Absence of verifiable operational historyOperations of this type typically lack any auditable history, no company registration, no named team, no published security disclosures, and no track record predating the fraud campaign. The use of an impersonation domain further forecloses any legitimate identity claim the operator might otherwise make.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.