Cómo opera la estafa.
my-ethwallet.com se presenta como una interfaz legítima de wallet de Ethereum, imitando el lenguaje visual y la estructura de dominio de un servicio de wallet de Ethereum establecido y ampliamente reconocido. La sustitución deliberada por un guion y la abreviación de 'ether' a 'eth' en el nombre de dominio es coherente con el typosquatting, una técnica diseñada para interceptar a usuarios que escriben mal o recuerdan mal una URL de confianza, así como a quienes llegan al sitio a través de enlaces de phishing o anuncios fraudulentos.
Una vez en el sitio, a los visitantes se les suele presentar una interfaz que replica de cerca un servicio de wallet genuino, invitándolos a introducir una frase semilla, una clave privada o un archivo keystore para 'acceder' a su wallet. En operaciones de este tipo, cualquier credencial enviada queda capturada por el operador. El sitio no funciona como una wallet real: es una fachada de recolección. Los usuarios que se autentican no reciben acceso real a ninguna wallet; el operador obtiene todo lo necesario para vaciar las direcciones asociadas.
El punto de quiebre se hace evidente cuando las víctimas intentan acceder a sus activos y los descubren transferidos a direcciones que no controlan. Para entonces, el sitio puede haber sido dado de baja o reemplazado, y el operador resulta inalcanzable. Las transferencias de criptomonedas son irreversibles, lo que significa que cualquier vía de recuperación realista depende de rastrear el movimiento posterior de los fondos a través de la blockchain, no de recurrir a la propia plataforma fraudulenta.
Banderas rojas que documentamos.
- 01Typosquatting domain targeting a recognised wallet brandThe domain my-ethwallet.com approximates the URL of a well-established Ethereum wallet service by abbreviating 'ether' to 'eth' and inserting a hyphen. This is a deliberate construction, not a coincidence, typosquatting domains require active registration and are purpose-built to intercept misdirected or deceived traffic.
- 02Credential-harvesting operation patternWallet impersonation platforms of this type derive their value entirely from capturing authentication credentials at point of entry. Any interface requesting a seed phrase, private key, or keystore file outside of locally-run, auditable open-source software should be treated as a harvesting operation until independently verified.
- 03CryptoScamDB blacklist inclusionThe domain appears on the CryptoScamDB community blacklist, a widely referenced registry of confirmed malicious cryptocurrency sites. Inclusion reflects corroborated reporting and is a recognised signal used by browser security extensions and wallet providers to warn users before credential submission occurs.
- 04No verifiable operator identity or regulatory standingLegitimate wallet services operating at scale maintain verifiable legal identities and, in many jurisdictions, regulatory registrations. This platform presents none of these. The absence of any traceable operator makes post-fraud recourse through conventional legal or financial channels structurally unavailable to victims.
- 05No auditable code or custody transparencyGenuine open-source wallet platforms publish verifiable source repositories and make custody arrangements explicit. A site mimicking this presentation without providing auditable code or independent security attestation offers users no means of confirming that submitted credentials are handled with any integrity.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.