Cómo opera la estafa.
El sitio se presenta como la interfaz de una wallet de Ethereum de autocustodia, la categoría de herramienta que permite a los usuarios generar, importar e interactuar con direcciones de Ethereum directamente en un navegador. Los operadores de este tipo de plataformas de imitación suelen replicar el diseño visual y el lenguaje de servicios de wallet consolidados para proyectar legitimidad, apuntando a usuarios que escriben mal una URL o que llegan a través de anuncios en motores de búsqueda y enlaces de phishing.
El mecanismo operativo es la sustracción de credenciales. Cuando un visitante intenta importar o acceder a una wallet existente, normalmente al introducir una clave privada, un archivo keystore o una frase semilla mnemónica, esos datos se transmiten de forma silenciosa a una infraestructura controlada por el operador en lugar de procesarse localmente. El usuario no advierte nada inusual en el momento de la entrada; la interfaz incluso puede mostrar saldos de la wallet extraídos de la blockchain pública para mantener la ilusión de un servicio en funcionamiento.
El punto de fallo llega cuando la víctima intenta realizar una transacción y descubre que su wallet ya ha sido vaciada, o cuando un retiro iniciado a través de la interfaz nunca se materializa en la cadena. A esas alturas el operador ya tiene el control total de cualquier material de clave privada enviado. Los fondos transferidos a direcciones generadas por la plataforma corren un riesgo similar, ya que es probable que el operador posea las claves privadas correspondientes. La recuperación de activos sustraídos a través de una interfaz de robo de credenciales está técnicamente limitada por la irreversibilidad de las transferencias en la cadena.
Banderas rojas que documentamos.
- 01Hyphenated domain mimicking a recognised wallet brandThe domain my-ether-wallet.com inserts hyphens into a string visually identical to a well-established Ethereum wallet service. This typosquatting technique is a documented method for intercepting users who make minor address-bar errors or follow links without inspecting the full URL.
- 02CryptoScamDB blacklist confirmationThe domain appears in CryptoScamDB's publicly maintained blacklist, a community-vetted registry of addresses and URLs associated with confirmed crypto-fraud operations. Inclusion is based on reported evidence, not automated heuristics alone.
- 03Self-custody interface pattern invites key disclosurePlatforms that replicate self-custody wallet interfaces are a high-risk category because their core function, importing a wallet, requires the user to disclose the most sensitive possible credential: a private key or seed phrase. Legitimate self-custody tools process these locally and never transmit them.
- 04No verifiable operational history or responsible entityPhishing sites in this category are typically registered anonymously, hosted behind privacy-preserving infrastructure, and replaced rapidly after blacklisting. The absence of a verifiable legal entity, auditable codebase, or consistent operational history is consistent with a short-lived credential-harvesting operation.
- 05Arrival via misdirection rather than organic trustSites of this pattern rarely acquire users through legitimate reputation-building. Traffic typically originates from typos, lookalike search advertisements, or social-media phishing campaigns, signals that the operator is not competing on merit but on deception.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.