Wie die Masche funktioniert.
Die Domain setzt einen Angriff über einen Internationalisierten Domainnamen (IDN) ein und nutzt die Punycode-Kodierung, um eine Webadresse darzustellen, die in den meisten Browsern nahezu identisch mit einer weithin vertrauten Ethereum-Wallet-Oberfläche erscheint. Der Betreiber präsentiert ein authentisch wirkendes Wallet-Frontend und verlässt sich darauf, dass Nutzer die ausgetauschten Unicode-Zeichen anstelle der üblichen ASCII-Buchstaben nicht bemerken. Weder eine Kontaktaufnahme noch Versprechen sind erforderlich, wenn die Seite dort zu liegen scheint, wo Nutzer bereits ein Konto unterhalten.
Opfer gelangen üblicherweise über eine vertippte URL, ein manipuliertes Suchergebnis oder einen auf sozialen Plattformen verbreiteten Phishing-Link auf die Seite. Da die dargestellte Domain in den meisten Adresszeilen der Browser korrekt aussieht, geben Nutzer die Seed-Phrase, private Schlüssel oder Anmeldedaten ihres Wallets arglos ein. Der Betreiber greift diese sofort ab. Im Kryptowährungskontext gewährt der Besitz einer Seed-Phrase die vollständige, unwiderrufliche Kontrolle über alle damit verbundenen Gelder. Es gibt keine Supportstruktur, keinen Wiederherstellungsmechanismus und keine identifizierbare Partei hinter der Operation.
Der Moment des Verlusts verläuft in der Regel lautlos. Nach Eingabe der Zugangsdaten wird der Nutzer möglicherweise weitergeleitet, sieht eine allgemeine Fehlermeldung oder verbleibt auf einer leeren Seite. Das Wallet erscheint unbeeinträchtigt, bis der Nutzer seine tatsächlichen Bestände prüft und das Guthaben geleert vorfindet. Da On-Chain-Transaktionen unwiderruflich sind, bleiben herkömmliche Wege zur Wiederbeschaffung versperrt. Die Aufnahme in die Sperrliste von CryptoScamDB bestätigt, dass die Domain von der Sicherheitsforschungsgemeinschaft als aktive Phishing-Infrastruktur identifiziert wurde.
Warnsignale, die wir dokumentiert haben.
- 01Punycode IDN Homograph ConstructionThe xn-- prefix identifies this as a Punycode-encoded Internationalised Domain Name, a class of address used in homograph attacks to substitute visually identical Unicode characters for standard ASCII letters. This construction has no legitimate purpose in a consumer-facing financial service and exists solely to deceive users who inspect the address bar.
- 02Wallet Credential Entry as the Target SurfaceDomains of this class are engineered to harvest seed phrases and private keys, the most irreplaceable credentials in cryptocurrency self-custody. Any interface soliciting these values outside of a verified, locally-installed wallet application should be treated as hostile, regardless of how familiar the address bar appears.
- 03CryptoScamDB Blacklist InclusionThe domain appears in the CryptoScamDB community blacklist, a widely referenced registry of confirmed malicious cryptocurrency addresses maintained through open-source community verification. Inclusion reflects reported harm and peer review by security researchers, not automated flagging alone.
- 04No Identifiable Operator or Regulatory PresenceThe domain presents no verifiable corporate entity, regulatory registration, or contact information consistent with a legitimate financial services operator. Anonymous infrastructure of this kind is a baseline characteristic of phishing operations and makes civil or regulatory recourse effectively unavailable.
- 05Irreversibility Exploited as a Structural FeatureOperations of this pattern deliberately target blockchain-based assets because on-chain transfers cannot be reversed, disputed, or charged back. The absence of consumer protection is not incidental to the design. It is the reason this class of operation targets cryptocurrency wallets rather than conventional payment accounts.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.