Cómo opera la estafa.
Esta operación se aprovecha del nombre y la aparente identidad de un reconocido servicio de wallet de autocustodia de Ethereum. El dominio incorpora el nombre de la marca suplantada casi de forma textual, lo que posiciona al sitio para captar a visitantes que escriben mal una URL, siguen un enlace de un mensaje de phishing o lo encuentran a través de resultados de búsqueda manipulados. El dominio de nivel superior .airforce es la única desviación manifiesta respecto de la marca que imita, un detalle que los usuarios desprevenidos, bajo presión de tiempo o con una leve distracción, suelen pasar por alto.
Las operaciones de este tipo presentan una réplica de la interfaz objetivo y solicitan al visitante que se autentique enviando una clave privada, una frase semilla o un archivo keystore. Este es el mecanismo central: la interfaz no necesita funcionar como una wallet para tener éxito. Solo necesita convencer al usuario de que introduzca sus credenciales una vez. Esas credenciales se transmiten al operador, quien luego puede acceder a las wallets correspondientes de forma independiente y en el momento que elija. El sitio puede simular un inicio de sesión exitoso para retrasar las sospechas.
Las víctimas suelen descubrir el fraude cuando encuentran el saldo de su wallet vaciado tras lo que parecía un inicio de sesión rutinario. Dado que las transferencias on-chain son irreversibles, la ventana entre el envío de las credenciales y la sustracción de los fondos suele ser el único punto en el que teóricamente es posible intervenir, y se cierra con rapidez. Para cuando se presenta una denuncia, el operador por lo general ya ha procesado los fondos a través de direcciones adicionales y la propia infraestructura de phishing puede haber sido desconectada o migrada a un nuevo dominio.
Banderas rojas que documentamos.
- 01Brand impersonation in the domain nameThe domain reproduces the name of a legitimate, well-established Ethereum wallet service with no meaningful alteration. This is a deliberate tactic: the closer a fraudulent domain sits to a trusted name, the less cognitive effort a victim needs to expend to accept it as genuine.
- 02Anomalous top-level domain for a financial interfaceLegitimate cryptocurrency wallet services operate under conventional TLDs. The use of .airforce for what purports to be a wallet interface has no plausible commercial rationale and is a recognised marker of opportunistic phishing infrastructure assembled quickly and cheaply.
- 03CryptoScamDB blacklist inclusionThe domain appears on the CryptoScamDB community blacklist, a collaboratively maintained register of confirmed malicious cryptocurrency addresses and domains. Inclusion indicates the site has been independently identified as a threat by researchers outside CryptoLeek.
- 04Credential-request pattern inconsistent with legitimate wallet operationAny web-based interface that requests a private key or seed phrase to grant wallet access is operating outside the security model of self-custody. Legitimate wallet interfaces of the type being impersonated here do not require server-side submission of these credentials under any normal circumstances.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.