Cómo opera la estafa.
etherwallet.it se presenta como una interfaz legítima de wallet de Ethereum, aprovechando un nombre de dominio con una fuerte similitud visual y fonética con uno de los servicios de wallet más reconocidos del ecosistema. La propuesta es simple: acceder a una wallet de Ethereum o administrarla. El público objetivo son los tenedores de ETH que tal vez no verifiquen el dominio exacto que utilizan, o que llegan a través de resultados de búsqueda, enlaces de phishing o publicaciones redirigidas en redes sociales.
La mecánica sigue un patrón común entre los suplantadores que recolectan credenciales. Se solicita a los visitantes que introduzcan una clave privada, una frase semilla o un archivo keystore para acceder a su wallet. Ninguna interfaz legítima de wallet no custodial exige esto mediante un formulario web. Una vez que el operador obtiene estas credenciales, dispone de acceso irrevocable a todos los fondos asociados. Es posible que la víctima vea brevemente una pantalla de wallet verosímil, sin recibir ninguna indicación inmediata de que algo ha salido mal.
El fraude se hace evidente cuando las víctimas intentan mover fondos y encuentran las wallets vacías, o regresan y descubren que el sitio ha sido modificado o está fuera de línea. Las transacciones en blockchain son irreversibles y el operador es seudónimo, de modo que los canales de recuperación convencionales ofrecen un recurso limitado. El registro del dominio fraudulento suele ser el único artefacto rastreable, sin ninguna contraparte identificada disponible para un proceso civil o penal.
Banderas rojas que documentamos.
- 01Typosquat domain targeting Ethereum wallet usersThe domain etherwallet.it is constructed to resemble a well-known Ethereum wallet service closely enough that users navigating quickly or arriving via a link may not notice the difference. This is a documented impersonation technique, not coincidental naming.
- 02Confirmed listing on CryptoScamDB blacklistThe site appears on CryptoScamDB's community-maintained blacklist, used by browser extensions, security tools, and exchange compliance teams to flag known fraudulent addresses. Inclusion is a material signal, not a provisional one.
- 03TLD inconsistent with the platform being imitatedLegitimate Ethereum wallet services do not operate under country-code TLDs such as .it for global product offerings. Use of a country-code domain for a service presenting as a general Ethereum wallet is a common signal of opportunistic registration by a fraudulent operator.
- 04Seed phrase or private key input as operational requirementAny platform that solicits a wallet's private key or seed phrase through a web form is operating outside every legitimate security standard in the industry. No genuine non-custodial wallet service requires this. A request of this kind is the definitive signal that the platform's purpose is credential theft.
- 05No verifiable organisational identityOperations of this pattern typically carry no auditable corporate registration, no named team, no regulatory licence, and no verifiable history. The anonymity is structural, not incidental; it is what makes the operation viable and exit straightforward for the operator.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.