Wie die Masche funktioniert.
Die Domain gibt sich als optisch nahezu identische Nachahmung eines bekannten Ethereum-Web-Wallet-Dienstes aus. Das Punycode-Label (das Präfix xn--) zeigt an, dass ein oder mehrere Zeichen in der angezeigten URL nicht aus dem standardmäßigen ASCII-Alphabet, sondern aus nicht-lateinischen Unicode-Bereichen stammen, eine Technik, die als Homograph-Angriff bekannt ist. In Kombination mit der bewussten Schreibweise des Wortes 'wallet' mit nur einem l ist die Adresse so konstruiert, dass sie einer flüchtigen Sichtprüfung durch jeden standhält, der eine vertraute Wallet-URL erwartet.
Operationen dieser Art werden in der Regel über Phishing-E-Mails, bösartige Suchanzeigen oder kompromittierte Social-Media-Beiträge verbreitet und leiten die Opfer auf eine Nachbildung der Oberfläche, die das visuelle Design des legitimen Dienstes widerspiegelt. Auf der Seite angekommen, wird der Nutzer aufgefordert, eine Seed-Phrase, einen privaten Schlüssel oder eine Keystore-Datei einzugeben, um sich 'anzumelden' oder ein Konto 'wiederherzustellen'. Diese Zugangsdaten sind die einzige Authentifizierungsebene, die zur Kontrolle einer Self-Custody-Wallet erforderlich ist; ihre Eingabe auf einer beliebigen Drittanbieter-Website überträgt die tatsächliche Kontrolle über die Wallet an den Betreiber.
In dem Moment, in dem die Zugangsdaten übermittelt werden, räumen automatisierte Skripte in der Regel innerhalb von Sekunden alle vorhandenen Mittel aus der Wallet ab, noch bevor der Nutzer den Browser-Tab geschlossen hat. Opfer, die später versuchen, zur Seite zurückzukehren, stellen häufig fest, dass diese nicht mehr erreichbar ist, da die Betreiber ihre Infrastruktur wechseln, sobald eine Domain gemeldet wird. Die Wiederbeschaffung von auf diese Weise verschobenen Vermögenswerten ist technisch und in Bezug auf die Zuständigkeit komplex, wobei die Ergebnisse von Blockchain-Forensik und der Geschwindigkeit abhängen, mit der die Mittel weitertransferiert wurden.
Warnsignale, die wir dokumentiert haben.
- 01Punycode encoding signals a homograph operationThe xn-- prefix in the domain name indicates Punycode encoding, meaning the address contains Unicode characters designed to look identical to Latin letters at normal reading speed. Legitimate wallet providers do not use Punycode in their primary domains. This pattern is a recognised marker of credential-phishing infrastructure.
- 02Deliberate misspelling of a recognised wallet brandThe domain 'myetherwalet' omits one letter from the name of a well-known Ethereum wallet service. Typosquat domains are a documented distribution vector for wallet-credential phishing, exploiting fast or autocomplete-assisted URL entry by users who do not verify addresses character by character.
- 03Presence on CryptoScamDB community blacklistThe domain appears in the CryptoScamDB blacklist, a publicly maintained registry of addresses associated with cryptocurrency fraud. Listing reflects community-sourced confirmation of malicious intent, not an unverified allegation.
- 04Seed phrase solicitation is categorically unsafeAny platform requesting a wallet seed phrase or private key to authenticate a user is structurally fraudulent. No legitimate self-custody wallet service requires these credentials to be transmitted to a web server; they are intended to remain exclusively within the user's own device.
- 05Infrastructure pattern typical of high-rotation phishingHomograph and typosquat domains targeting wallet services are typically deployed in short bursts, making them difficult to take down before significant harm occurs. The low barrier to registering near-identical replacement domains means a blocked address can be substituted quickly by the same operator.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.