Wie die Masche funktioniert.
nnyetherwallet.com gibt sich als funktionsfähige Ethereum-Wallet-Oberfläche aus und ist so konstruiert, dass es MyEtherWallet nachahmt, einen weithin bekannten Self-Custody-Wallet-Dienst. Die Domain unterscheidet sich vom echten Dienst durch ein einziges vertauschtes Präfix, indem sie 'nny' anstelle von 'my' verwendet. Dabei handelt es sich um eine gezielte Tippfehlerfalle: Die Seite ist darauf ausgelegt, Nutzer abzufangen, die sich bei der legitimen Adresse vertippen oder einem irreführenden Link folgen, und bei der ersten Betrachtung nicht von der echten Plattform unterscheidbar zu erscheinen.
Die Operation gehört zur Kategorie des Credential-Harvesting-Phishings. Besuchern wird in der Regel eine Wallet-Oberfläche präsentiert, die zur Eingabe eines privaten Schlüssels, einer mnemonischen Seed-Phrase oder einer Keystore-Datei auffordert, angeblich um auf ein bestehendes Wallet zuzugreifen oder es wiederherzustellen. Diese Zugangsdaten werden vom Betreiber erfasst und nicht lokal verarbeitet. Da private Schlüssel und Seed-Phrasen uneingeschränkte, unwiderrufliche Kontrolle über alle zugehörigen On-Chain-Vermögenswerte gewähren, kann der Betreiber die Bestände des Opfers unmittelbar und ohne weitere Interaktion abräumen.
Der Punkt des Scheiterns wird erst nach der Übermittlung sichtbar. Der Wallet-Zugang wird nicht wiederhergestellt; stattdessen bemerkt das Opfer möglicherweise, dass nicht autorisierte ausgehende Transaktionen bereits On-Chain abgewickelt wurden. In diesem Stadium sind die Gelder typischerweise an Zwischenadressen verschoben worden, die der Betreiber kontrolliert. Blockchain-Transaktionen sind unumkehrbar, ohne Rückbuchungsmechanismus und ohne eine administrative Instanz, die Vermögenswerte einfrieren oder zurückholen könnte. Eine Wiederbeschaffung hängt, sofern sie überhaupt gelingt, von investigativer Nachverfolgung und der Zusammenarbeit mit Börsen oder Strafverfolgungsbehörden ab.
Warnsignale, die wir dokumentiert haben.
- 01Typosquat domain targeting a recognised wallet brandThe domain 'nnyetherwallet.com' deviates from MyEtherWallet's address by a single character substitution. This construction is not coincidental. It is engineered to intercept users who make minor typographical errors, placing a malicious interface in the path of traffic intended for a legitimate service.
- 02CryptoScamDB blacklist confirmationThe domain is listed in the CryptoScamDB blacklist, a community-maintained registry of verified fraudulent cryptocurrency sites. Inclusion reflects reported victim activity and analysis of the domain's operational purpose, and constitutes a recognised industry-level fraud signal.
- 03Solicitation of private credentials via web interfaceNo legitimate self-custody wallet service requires users to enter private keys, seed phrases, or keystore files into a browser-based form. Any platform that does so is operating a credential-harvesting interface. This is the defining behavioural signal for this class of fraudulent operation.
- 04Anonymous operator with no regulatory footprintThere is no disclosed business entity, registered operator, or regulatory filing associated with this domain. Operational anonymity is a consistent feature of platforms designed to defraud without accountability, as it forecloses any civil or regulatory avenue for victim recourse.
- 05Immediate and irreversible asset exposure on credential entryOnce private credentials are submitted, the operator holds unconditional access to all associated on-chain assets. Transfers initiated by a malicious holder of these credentials cannot be reversed or intercepted. There is no escrow period, no dispute window, and no custodial protection of any kind.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.