Wie die Masche funktioniert.
Die Operation gibt sich als legitime Ethereum-Wallet-Oberfläche aus und nutzt die optische Ähnlichkeit zu einem weit verbreiteten Wallet-Dienst für Kryptowährungen aus. Die beiden bestätigten Domains, myetherwallte.com und myetherwalelt.com, unterscheiden sich vom echten Dienst nur durch vertauschte oder eingefügte Buchstaben und sind darauf ausgelegt, Nutzer abzufangen, die sich bei einer vertrauten Adresse vertippen. Der erkennbare Zweck besteht darin, die Oberfläche einer vertrauenswürdigen Self-Custody-Wallet so genau nachzubilden, dass ein unaufmerksamer Besucher die Vertauschung nicht bemerkt.
Der zugrunde liegende Mechanismus folgt einem gut dokumentierten Phishing-Muster, das auf Inhaber von Kryptowährungen abzielt. Besucher, die auf der Seite landen, typischerweise über eine falsch eingetippte URL oder ein manipuliertes Suchergebnis, sehen eine Wallet-Oberfläche, die ihren Private Key, ihre Seed-Phrase oder ihre Zugangsdaten abfragt. Sobald diese Angaben übermittelt sind, erhält der Betreiber vollständigen und unwiderruflichen Zugriff auf alle damit verbundenen Wallets. Blockchain-Transaktionen lassen sich nicht zurückrufen, sodass die Bewegung von Vermögenswerten aus einer kompromittierten Wallet auf herkömmlichem Wege keinen praktikablen Weg zur Wiederbeschaffung offenlässt.
Der Punkt des Scheiterns wird offensichtlich, wenn das Opfer versucht, auf seine legitime Wallet zuzugreifen, und feststellt, dass entweder die Zugangsdaten nicht mehr funktionieren oder die Gelder bereits ohne seine Genehmigung verschoben wurden. Operationen nach diesem Muster handeln typischerweise innerhalb von Minuten nach dem Abgreifen der Zugangsdaten und leeren die Wallets, bevor das Opfer überhaupt bemerkt, was geschehen ist. Spätere Kontaktversuche bleiben ergebnislos: Die Infrastruktur wird in der Regel aufgegeben oder ausgetauscht, sobald sie gemeldet wurde oder genügend Opfer durch sie hindurchgeschleust wurden.
Warnsignale, die wir dokumentiert haben.
- 01Typosquat Domain ArchitectureBoth confirmed domains are deliberate transpositions of a widely-recognised Ethereum wallet service name. The misspellings require no social engineering beyond exploiting routine typing errors, allowing the operation to harvest victims passively from organic navigation mistakes.
- 02Multiple Alias Domains RegisteredThe operation maintains at least two confirmed alias domains, indicating coordinated infrastructure rather than an isolated incident. Multiple domains extend reach and provide redundancy if one address is taken down or blacklisted by browser security tools.
- 03CryptoScamDB Blacklist InclusionBoth domains appear in the CryptoScamDB community blacklist, referenced by wallet providers and browser extensions to block access to known phishing infrastructure. Inclusion across two separate entries reflects confirmed, community-verified evidence of fraudulent activity.
- 04Credential-Harvesting Platform PatternSites impersonating cryptocurrency wallet interfaces serve a single operational purpose: collecting private keys or seed phrases. No legitimate wallet service solicits these credentials through a web form. Any interface doing so should be treated as hostile regardless of its visual presentation.
- 05No Verifiable Operator or Regulatory StandingThe operation presents no identifiable registered entity, public operator, or regulatory licence. Legitimate wallet services maintain public accountability structures. The absence of any such structure is consistent with the disposable infrastructure typical of short-cycle phishing campaigns.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.