Cómo opera la estafa.
La operación se presenta como una interfaz legítima de wallet de Ethereum al adoptar un nombre de dominio que reproduce casi exactamente la identidad de marca de un reconocido servicio de wallet de autocustodia, diferenciándose únicamente en su dominio de nivel superior. El sitio parece diseñado para interceptar a usuarios que encuentran un enlace fraudulento a través de canales de phishing como redes sociales, campañas de correo electrónico o anuncios en motores de búsqueda, en lugar de mediante la navegación orgánica hacia el servicio legítimo.
Las plataformas de suplantación de wallets de este tipo solicitan credenciales privadas directamente a los visitantes: por lo general una frase semilla, una clave privada o un archivo keystore cifrado, presentadas bajo el pretexto de importar la wallet, recuperar la cuenta o autorizar una transacción. Una vez que el usuario envía estas credenciales a través de la interfaz web, el operador obtiene acceso total a cualquier wallet que esas credenciales controlen. Los fondos suelen retirarse de las wallets comprometidas con rapidez, mediante procesos automatizados que ejecutan los retiros en cuestión de minutos tras la captura de las credenciales.
El punto crítico de falla es irreversible. Dado que las transacciones en la red de Ethereum no pueden anularse ni revertirse una vez confirmadas en la cadena, cualquier activo vaciado de una wallet comprometida queda permanentemente fuera del alcance de recuperación por medios técnicos. Las víctimas suelen descubrir la pérdida solo al intentar acceder a su wallet genuina, momento en el cual el saldo ya ha sido vaciado y la plataforma fraudulenta no ha dejado ninguna vía de reclamación ni reparación.
Banderas rojas que documentamos.
- 01Exact brand impersonation via TLD substitutionThe domain reproduces the full name of a well-known Ethereum wallet platform, substituting only the top-level domain. This is a deliberate impersonation pattern intended to exploit user familiarity and typographical error. Visitors navigating to this address may reasonably believe they have reached the legitimate service.
- 02Non-standard TLD outside recognised registrar oversightThe ".aigo" extension does not correspond to any ICANN-recognised top-level domain. Legitimate financial services platforms do not operate from unrecognised TLDs. This choice of domain signals disposable infrastructure designed to evade conventional takedown processes.
- 03Presence on CryptoScamDB community blacklistThe domain is listed on CryptoScamDB's community-maintained blacklist, a database of addresses and URLs associated with documented cryptocurrency fraud. Inclusion reflects reported harmful activity and community verification of the warning.
- 04Credential-harvesting attack surfaceWallet impersonation operations solicit private keys and seed phrases through web forms. No legitimate wallet service requests these credentials via a browser interface. Any platform that does so should be treated as a credential-harvesting operation; submission results in total and irreversible loss of associated assets.
- 05No verifiable operator or regulatory identityThere is no documented company registration, regulatory licence, or verifiable operator identity associated with this domain, consistent with the anonymous, disposable infrastructure typically used in phishing campaigns targeting cryptocurrency holders.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.