Wie die Masche funktioniert.
Diese Operation gibt sich als legitime Ethereum-Wallet-Oberfläche aus. Die Domain ist mithilfe der Kodierung für internationalisierte Domainnamen (IDN) konstruiert, einer Technik, die bestimmte Browser dazu veranlasst, statt der zugrunde liegenden Punycode-Zeichenfolge eine Unicode-Adresse anzuzeigen, die von einer weithin bekannten Wallet-Plattform optisch nicht zu unterscheiden ist. Zielgruppe ist jeder Nutzer von Kryptowährungen, der die Seite in dem Glauben aufruft, es handele sich um den echten Dienst, sei es über einen kopierten Link, ein Suchergebnis oder eine Weiterleitung.
Opfer gelangen typischerweise über Phishing-Links in E-Mails, Beiträgen in sozialen Medien oder bezahlten Suchplatzierungen auf die Seite. Die Oberfläche bildet ein vertrauenswürdiges Wallet-Produkt so genau nach, dass Nutzer private Schlüssel, Seed-Phrasen oder Kontozugangsdaten eingeben, ohne eine Unregelmäßigkeit zu vermuten. Diese Eingaben werden vom Betreiber abgefangen und nicht legitim verarbeitet. Der Mechanismus beruht darauf, dass Rendering-Engines bestimmte Unicode-Codepunkte als normale lateinische Buchstaben darstellen, wodurch die Domain für das menschliche Auge korrekt erscheint.
Die Täuschung wird in der Regel erst dann offenkundig, wenn das Opfer versucht, auf seine Wallet zuzugreifen, und nach Eingabe der Zugangsdaten feststellt, dass die Gelder fehlen oder die Oberfläche nicht reagiert. Zu diesem Zeitpunkt verfügt der Betreiber bereits über das private Schlüsselmaterial, und die Verluste auf der Blockchain sind unumkehrbar. Es gibt keinen Emittenten, der die Transaktion rückgängig machen könnte, keinen Rückbuchungsmechanismus und keinen Verwahrer, der die Vermögenswerte treuhänderisch hält. Spätere Versuche, einen Betreiber ausfindig zu machen oder Rechtsmittel einzulegen, erreichen niemanden, da die Infrastruktur von Anfang an darauf ausgelegt ist, keine überprüfbare Identität zu tragen.
Warnsignale, die wir dokumentiert haben.
- 01Punycode homograph domain constructionThe domain uses internationalised domain name encoding so that it renders as a trusted platform name in browsers that display Unicode rather than punycode. Substituting visually identical Unicode characters for Latin letters in a domain has no legitimate commercial application; it is a documented credential-harvesting technique.
- 02CryptoScamDB blacklist presenceThe domain is listed on CryptoScamDB's community-maintained blacklist, a widely referenced aggregator of verified fraudulent cryptocurrency infrastructure. Inclusion reflects independent, third-party verification of fraudulent activity associated with this address.
- 03High-yield credential-harvesting target profileThe impersonated platform category is a self-custody Ethereum wallet interface, selected because users of such tools are conditioned to enter seed phrases and raw private keys. That input profile gives the operator immediate, irrevocable access to all associated funds without any further steps required.
- 04No identifiable operator or legal entityHomograph-attack infrastructure of this type consistently lacks any traceable registered business, named director, or accountable individual behind it. The absence of any legal identity is a structural feature of the operation, not an administrative oversight, and it is what makes recovery actions difficult to initiate.
- 05No regulatory authorisation or compliance recordThe operation carries no financial services authorisation from any recognised regulator, no published terms of service from an identifiable entity, and no verifiable compliance history. Legitimate wallet services operating in major jurisdictions are required to carry some form of registration or disclosure.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.