Wie die Masche funktioniert.
Die Domain ist als internationalisierter Domainname (IDN) mit dem Punycode-Präfix xn-- registriert, eine Technik, die dazu führt, dass bestimmte Browser und Link-Vorschau-Tools die Adresse als nahezu identische visuelle Kopie eines weit verbreiteten Ethereum-Wallet-Dienstes darstellen. Einem flüchtigen Betrachter, der eine URL in einer Nachricht oder einem Suchergebnis überfliegt, fällt nichts Auffälliges auf. Die Operation zielt auf Kryptowährungsinhaber ab, die glauben, eine vertraute und vertrauenswürdige Oberfläche aufzurufen.
Opfer gelangen typischerweise über Phishing-Links auf die Seite, die über Social-Media-Beiträge, gesponserte Suchergebnisse oder Direktnachrichten verbreitet werden. Die Seite präsentiert eine überzeugende Nachbildung der nachgeahmten Wallet-Oberfläche und fordert Besucher auf, ihre mnemonische Wiederherstellungsphrase, ihren Private Key oder ihre Anmeldedaten einzugeben. Sämtliche übermittelten Daten werden an den Betreiber gesendet und nicht lokal verarbeitet. Da Wiederherstellungsphrasen bedingungslosen Zugriff auf alle zugehörigen Gelder über jedes Gerät hinweg gewähren, genügt eine einzige erfolgreiche Erfassung, um die Wallet vollständig zu leeren.
Der Schaden wird in der Regel erst entdeckt, nachdem das Opfer versucht, über den echten Dienst auf seine Vermögenswerte zuzugreifen, und feststellt, dass das Guthaben transferiert wurde. Zu diesem Zeitpunkt hat der Betreiber die Gelder üblicherweise bereits über eine oder mehrere Zwischenadressen verschoben, und die Phishing-Domain ist möglicherweise schon inaktiv oder ersetzt. Die Plattform bietet keinen Support-Kanal, keine Betreiberidentität und keinen Mechanismus für Streitfälle oder Wiederherstellung.
Warnsignale, die wir dokumentiert haben.
- 01Punycode IDN construction signals homograph operationThe xn-- prefix identifies this as an internationalised domain name encoding one or more non-ASCII Unicode characters. This technique is routinely used to register addresses that are visually indistinguishable from trusted domains in browser address bars, link previews, and messaging apps.
- 02No legitimate wallet platform uses punycode addressingEstablished cryptocurrency wallet services operate on plain ASCII domains. A wallet interface accessible only through a punycode address has no credible operational justification, and no legitimate provider directs users to access their funds via such an address.
- 03CryptoScamDB blacklist confirmationThe domain is listed explicitly in the CryptoScamDB community blacklist, a maintained and publicly audited registry of addresses reported in connection with theft and fraud. Independent blacklist inclusion is a reliable signal of confirmed malicious activity.
- 04Seed-phrase harvesting as the operative patternWallet impersonation sites exist for a single purpose: capturing recovery phrases or private keys. Any web-based interface requesting these credentials outside of a locally installed application presents an unacceptable risk, regardless of how the interface appears.
- 05No operator identity or registration transparencyThere are no documented aliases, corporate registrations, regulatory disclosures, or support channels associated with this domain. This absence of verifiable identity is consistent with ephemeral phishing infrastructure designed to be discarded once exposure occurs.
Was Sie jetzt tun können.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.