Wie die Masche funktioniert.
Die Seite gibt sich als legitime Self-Custody-Schnittstelle für eine Ethereum-Wallet aus und richtet sich an Inhaber von Ether und ERC-20-Token. Ihre Domain nutzt Punycode-Kodierung (erkennbar am Präfix xn--), um Nicht-ASCII-Unicode-Zeichen einzubetten, die in der Adressleiste eines Browsers eine URL erzeugen, die optisch nicht von einem weithin bekannten Wallet-Dienst zu unterscheiden ist. Nutzer gelangen auf die Seite in dem Glauben, ein vertrauenswürdiges Ziel erreicht zu haben.
Der operative Mechanismus ist der IDN-Homograph-Angriff: Unicode-Zeichen, die ASCII-Buchstaben in einem vertrauten Dienstnamen optisch entsprechen, werden auf Kodierungsebene in die Domain eingebettet. Opfer, die über einen Phishing-Link, ein manipuliertes Suchergebnis oder einen knapp danebenliegenden Tippfehler gelangen, treffen auf eine Schnittstelle, die ein legitimes Wallet-Werkzeug nachbildet. Die Seite fordert eine Seed-Phrase, einen privaten Schlüssel oder eine Keystore-Datei an, um angeblich eine Wallet zu entsperren; diese Zugangsdaten werden beim Absenden an den Betreiber übermittelt und verschaffen ihm die volle Kontrolle über jede zugehörige Adresse.
Der Angriff verläuft in der Regel unbemerkt. Die Seite simuliert möglicherweise einen kurzen Ladevorgang, bevor sie leer bleibt oder eine Fehlermeldung ausgibt; ein ausdrückliches Signal für den Diebstahl wird nicht angezeigt. Opfer bemerken den Verlust meist erst Stunden oder Tage später, wenn die Gelder auf eine unbekannte Adresse abgezogen wurden. Zu diesem Zeitpunkt sind die Vermögenswerte üblicherweise bereits über mehrstufige Transfers verschoben worden, die die Nachverfolgung erschweren sollen, und das Zeitfenster für eine On-Chain-Intervention ist geschlossen.
Warnsignale, die wir dokumentiert haben.
- 01IDN Homograph Domain ConstructionThe xn-- prefix identifies this as an Internationalized Domain Name using Punycode to embed non-ASCII characters that produce a visual clone of a legitimate service URL. This technique has no genuine application in consumer financial services; its documented use in this context is credential phishing.
- 02CryptoScamDB Blacklist InclusionThe domain is recorded on the CryptoScamDB community blacklist, a reference used by wallet developers, browser security extensions, and anti-phishing infrastructure. Independent third-party identification of this kind reflects active recognition of the domain as harmful.
- 03Credential Solicitation Through a Web InterfaceLegitimate self-custody wallet tools do not accept seed phrases or private keys through a browser form connected to a remote server. Any platform requesting these credentials via a web interface is operating contrary to foundational cryptographic security practice.
- 04Complete Operator AnonymityNo company registration, named personnel, regulatory licence, or auditable operational record has been documented for this site. Structural anonymity of this kind is a deliberate feature of phishing infrastructure, not an administrative oversight.
- 05A Pattern That Defeats Standard Safety PrecautionsUnlike phishing that relies on social engineering alone, an IDN homograph operation defeats a specific precaution: verifying the URL bar. Victims who follow standard safety guidance and check the domain before entering credentials may still be deceived, as the threat operates at the character-encoding level rather than the content level.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.