Cómo opera la estafa.
etherwallet.world se presenta como una interfaz legítima de wallet de Ethereum, tomando prestadas las convenciones de nomenclatura y la autoridad implícita de servicios de wallet reconocidos para atraer a usuarios que buscan acceder a una wallet o que han llegado a través de un enlace de phishing. El dominio está diseñado para parecer corriente, ofreciendo lo que aparenta ser un punto de entrada rutinario para gestionar activos de Ethereum. El público objetivo es cualquier tenedor de Ethereum que busque acceder a una wallet o recuperarla, en particular quienes no están familiarizados con la forma de verificar la autenticidad de una interfaz de wallet basada en la web.
Las operaciones de este tipo funcionan solicitando credenciales sensibles en el punto de entrada. Por lo general, a las víctimas se les muestra una pantalla de inicio de sesión o de importación de wallet que pide una frase semilla, una clave privada o un archivo keystore. Esas credenciales no se utilizan localmente para acceder a una wallet: se transmiten a una infraestructura controlada por el operador. Dado que las credenciales de una wallet de Ethereum bastan para autorizar todas las transacciones salientes sin verificación adicional, el operador obtiene control incondicional sobre cualquier fondo asociado en el momento en que se envía la frase o la clave.
El punto de fallo llega cuando las víctimas intentan interactuar con su wallet a través de una interfaz legítima y descubren que los activos han sido transferidos. Las transacciones de Ethereum son irreversibles por diseño, y las direcciones receptoras suelen hacerse circular por mezcladores o por múltiples wallets intermediarias para ocultar el rastro. A las víctimas les queda un registro del robo en la blockchain, pero ningún recurso práctico a través de la plataforma, que para entonces a menudo está fuera de línea o no responde.
Banderas rojas que documentamos.
- 01Listed on CryptoScamDB blacklistThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained registry of confirmed fraudulent cryptocurrency addresses and domains. Blacklist inclusion reflects reported harm, not merely suspicion.
- 02Domain name mirrors established wallet brandingThe name etherwallet.world closely replicates the naming conventions of legitimate Ethereum wallet services. This pattern, known as brandjacking, is a standard technique used by credential-harvesting operations to reduce victim scepticism before the point of credential entry.
- 03Non-standard TLD as a trust signal failureThe use of a .world top-level domain, rather than .com or .org, is atypical for any established financial or infrastructure service. Operators of impersonation platforms frequently register non-standard TLDs because canonical domains are already claimed by legitimate organisations.
- 04Credential request at entry is the attack surfaceAny platform asking for a seed phrase, private key, or keystore file through a web browser interface should be treated as high-risk by default. Legitimate non-custodial wallet software processes these credentials locally; transmission over a network connection is architecturally unnecessary and operationally dangerous.
- 05No documented operator, registration, or accountabilityNo verifiable operator identity, corporate registration, or regulatory standing is associated with this domain in available sources. Absence of accountability infrastructure is characteristic of operations designed to be abandoned once they have served their purpose.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.