Cómo opera la estafa.
El sitio se presenta como un servicio legítimo de wallet de Ethereum, tomando su nombre directamente de una de las interfaces de wallet no custodial más reconocidas del ámbito de las criptomonedas. Las señales de marca están diseñadas para tranquilizar a los usuarios habituados al producto auténtico, con la expectativa de que la terminología familiar baje sus defensas. El público objetivo son los poseedores de Ethereum que gestionan wallets de autocustodia, quienes pueden llegar a través de resultados de búsqueda, enlaces en redes sociales o mensajes de phishing que apuntan al dominio.
Las operaciones de este tipo suelen funcionar presentando una interfaz réplica que solicita la clave privada o la frase semilla del usuario bajo el pretexto de acceder a la cuenta o de recuperarla. Una vez introducida, el operador obtiene el control irrevocable de la wallet asociada. Dado que las transacciones de Ethereum son inmutables y no requieren autorización de terceros, los fondos pueden vaciarse de inmediato y sin posibilidad de recurso. La suplantación se refuerza con el propio nombre del dominio, que reproduce la marca objetivo carácter por carácter antes de añadir un sufijo de dominio de nivel superior fabricado.
El punto de fallo se hace evidente cuando el usuario intenta acceder a su wallet a través del servicio legítimo y descubre que los activos ya no están presentes. En esa etapa, el sitio de phishing ha dejado de responder por lo general, y no hay datos de contacto del operador disponibles. Debido a que las credenciales se introdujeron de forma voluntaria desde la perspectiva de la red, las transacciones en la cadena de bloques no ofrecen ningún mecanismo de reversión. Las víctimas quedan con evidencia en cadena de la transferencia, pero sin medios prácticos para perseguir la dirección receptora sin una investigación especializada.
Banderas rojas que documentamos.
- 01Non-standard domain suffix signals an illegitimate operationThe '.active' top-level domain is not recognised by the Internet Assigned Numbers Authority, which maintains the authoritative registry of valid TLDs. A legitimate wallet service would not operate on a non-standard or fabricated domain extension. This alone is sufficient grounds for immediate suspicion.
- 02Name mimics a recognised Ethereum wallet platformThe domain reproduces the exact name of an established Ethereum wallet interface, differing only in the top-level domain. This pattern, known as brand impersonation or typosquatting, is consistently associated with credential-harvesting operations that rely on users recognising the name without inspecting the full domain.
- 03Listed on the CryptoScamDB blacklistThe domain appears in the CryptoScamDB blacklist, a community-maintained registry of confirmed fraudulent cryptocurrency addresses and domains. Inclusion indicates the site has been reported and verified as malicious by independent reviewers, placing it in confirmed rather than suspected territory.
- 04Credential-entry interface carries irreversible riskAny interface requesting a private key or seed phrase outside of a hardware wallet signing flow should be treated as a hostile surface. There is no legitimate operational reason for a web-based wallet interface to require this information. Entry of these credentials constitutes immediate and total loss of wallet control.
- 05No traceable operator or regulatory registrationNothing in the available record indicates this operation is registered with any financial authority, has a disclosed legal entity, or provides verifiable contact information. The absence of operator transparency is consistent with a disposable phishing asset rather than a legitimate service.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.