Cómo opera la estafa.
El sitio se presenta como una interfaz legítima de billetera de Ethereum, apoyándose en las convenciones de nombre de MyEtherWallet, una herramienta de billetera de autocustodia ampliamente reconocida. El dominio reproduce el nombre de MyEtherWallet dentro de una estructura de dominio de nivel superior poco convencional, lo que lo posiciona para interceptar a usuarios que navegan hacia el servicio genuino mediante URLs mal escritas o resultados de búsqueda manipulados. El público objetivo aparente son los tenedores de Ethereum que buscan acceso a una billetera de autocustodia.
Las operaciones de este patrón funcionan como fachadas para el robo de credenciales. Una interfaz que replica el servicio solicita a los usuarios que ingresen claves privadas, frases semilla o archivos keystore bajo el pretexto de acceder a la billetera o recuperar la cuenta. El operador recopila estas credenciales de forma silenciosa; el usuario puede encontrarse con un mensaje de error verosímil o una pantalla de carga mientras los datos enviados se transmiten a infraestructura controlada por el operador. En ningún momento el usuario obtiene acceso a una billetera funcional.
El momento del descubrimiento suele llegar cuando los usuarios regresan a su billetera genuina y encuentran que sus fondos no están, o cuando intentan una transacción y se topan con fallos que no pueden explicarse por las condiciones de la red. Para entonces, el operador ya ha transferido los activos a direcciones fuera del control de la víctima. Los esfuerzos de recuperación se complican por la naturaleza seudónima de los movimientos en cadena y por la ausencia total de cualquier identidad organizacional verificable detrás del dominio fraudulento.
Banderas rojas que documentamos.
- 01Lookalike brand impersonation via domain nameThe domain reproduces the name of a well-known, legitimate Ethereum wallet service within an unconventional top-level structure. This is a recognised hallmark of phishing operations engineered to intercept users before they reach the genuine service. MyEtherWallet, the brand being imitated, has no association with this domain.
- 02Unconventional top-level domain signals no accountabilityEstablished wallet providers operate under standard, verifiable top-level domains with traceable registration histories. The use of a non-standard top-level identifier here provides no institutional accountability and no established trust signal. Legitimate financial services do not operate under structures of this kind.
- 03CryptoScamDB blacklist listingThe domain is listed on the CryptoScamDB community blacklist, a broadly referenced index maintained by security researchers who actively catalogue fraudulent cryptocurrency infrastructure. Inclusion reflects documented community reporting of harmful activity associated with the domain.
- 04Credential-harvesting risk profile consistent with wallet-impersonator patternWallet-interface impersonators of this type are built specifically to capture private keys or seed phrases, which grant irreversible access to all funds in the associated wallet. Any site presenting itself as a wallet login or recovery tool that is not the independently verified original carries a substantive theft risk.
- 05No verifiable operator identity or regulatory presenceNo company registration, regulatory filing, or traceable organisational identity is associated with this domain. Legitimate wallet services maintain public accountability channels and verifiable legal entities. The complete absence of any such presence removes any basis for trust or recourse.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.