Cómo opera la estafa.
etherwallets.nl se presenta como una plataforma de billeteras de Ethereum, aprovechando la familiaridad visual y semántica de las interfaces de billeteras de autocustodia de uso extendido. La construcción del dominio sigue un patrón ampliamente documentado en el fraude cripto: pluralizar o modificar levemente el nombre de un servicio reconocido para registrar una dirección confusamente similar. El dominio de nivel superior con código de país .nl añade una apariencia superficial de legitimidad institucional, dando a entender una operación registrada en los Países Bajos sin requerir ninguna posición regulatoria real ni divulgación corporativa.
En la práctica, las operaciones de este tipo funcionan como plataformas de robo de credenciales más que como billeteras funcionales. A los visitantes se les suele mostrar una interfaz diseñada para parecerse a la de un proveedor legítimo de billeteras, solicitándoles que ingresen una clave privada, una frase semilla o un archivo keystore para 'acceder' o 'restaurar' su billetera. Estos datos constituyen las credenciales de autorización completas de una dirección de Ethereum. Una vez enviados, el operador obtiene acceso irrestricto a cualquier fondo retenido en las direcciones asociadas. No se presta ningún servicio real de billetera; la interfaz existe únicamente para recopilar dichas credenciales.
El punto de fallo es inmediato e irreversible. Una vez que una frase semilla o una clave privada ha sido transmitida al servidor del operador, todos los activos controlados por esas credenciales corren el riesgo de ser transferidos a direcciones controladas por el atacante. Las víctimas suelen descubrir la pérdida solo después de notar que sus tenencias han sido movidas sin su instrucción. Dado que las transacciones de Ethereum son definitivas y seudónimas, no existe ningún mecanismo dentro del protocolo para revertir o congelar la transferencia. Lo que sigue es una búsqueda de recursos en un panorama en el que existen pocas soluciones directas.
Banderas rojas que documentamos.
- 01Typosquat domain pattern targeting a recognised wallet brandThe domain name closely mirrors that of a well-established Ethereum wallet service, differing only in pluralisation. This is a textbook typosquat construction: it intercepts users who mistype a URL, follow a malicious link, or encounter the domain in search results, exploiting brand recognition to lower suspicion before any interaction begins.
- 02CryptoScamDB blacklist listingThe domain appears on the CryptoScamDB community blacklist, a structured, publicly maintained register of sites associated with cryptocurrency fraud. Inclusion reflects a documented community determination that the site poses a material risk to users, and it serves as the primary evidentiary basis for the confirmed-scam verdict assigned to this entry.
- 03Credential-harvesting interface patternWallet impersonation sites of this type request private keys or seed phrases under the guise of wallet access or recovery. No legitimate wallet platform requires a user to submit these credentials to a remote server. Any platform making such a request should be treated as hostile, regardless of its visual presentation.
- 04No verifiable operator or regulatory disclosureThere is no documented corporate identity, registered business address, or regulatory authorisation associated with this domain. Legitimate custodial and non-custodial wallet services operating in European jurisdictions are subject to disclosure obligations. The absence of any such information is a consistent feature of fraudulent operations designed to operate without accountability.
- 05Country-code TLD used as a credibility signalThe .nl top-level domain is often interpreted by users as evidence of a Netherlands-based, and therefore regulated, operation. In practice, .nl registration carries no financial conduct requirements. Its use here appears intended to create an impression of institutional grounding that the underlying operation does not possess.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.