Cómo opera la estafa.
La operación se presenta bajo un nombre de dominio diseñado para evocar a un conocido servicio de wallet de Ethereum, agregando un sufijo destinado a sugerir herramientas oficiales de analítica o de gestión de cuentas. La construcción es deliberada: los usuarios que buscan paneles de wallet, consultas de saldo o historial de transacciones tienden a encontrar este dominio como una extensión plausible de una marca en la que ya confían. El público implícito son los tenedores de Ether y tokens ERC-20 que buscan un servicio auxiliar legítimo.
Las operaciones de wallet basadas en la suplantación de marca de este tipo reproducen elementos de la interfaz del servicio legítimo que imitan para reducir el umbral de sospecha del usuario. El operador solicita luego credenciales de autenticación: claves privadas, frases semilla o aprobaciones de conexión de wallet. En las variantes con contratos de vaciado (drain contracts), una única transacción firmada transfiere todos los activos a direcciones bajo el control del operador. El sufijo de TLD no estándar genera una distancia plausible respecto de los patrones burdos de imitación, aunque sigue aprovechando el reconocimiento de la marca.
El momento de la pérdida suele preceder a que la víctima tome conciencia. Cuando se entregan claves privadas o frases semilla, el operador obtiene acceso permanente e irrecuperable a todas las direcciones de wallet asociadas. En las variantes con contratos de vaciado, el agotamiento de los activos puede no advertirse hasta que la víctima revisa su saldo. No existe canal de soporte, ni entidad documentada, ni contraparte recuperable. Los dominios de este tipo se abandonan de forma habitual una vez que aumentan las tasas de detección, dejando a las víctimas sin un rastro operativo que seguir.
Banderas rojas que documentamos.
- 01Domain constructed to impersonate a recognised wallet brandThe domain name combines the exact string of a well-known Ethereum wallet service with an appended suffix, a pattern consistent with impersonation operations designed to capture traffic from users mistyping or misremembering a legitimate address. The legitimate service has no affiliation with this domain.
- 02Non-standard top-level domain used as a legitimacy signalThe use of a non-standard TLD suffix mimicking a professional-sounding category is a recognised tactic for creating apparent distance from crude typosquat patterns while still exploiting brand recognition. Legitimate wallet services do not distribute functionality across speculative or unrecognised top-level domains.
- 03Listed on the CryptoScamDB community blacklistThe domain appears in the CryptoScamDB blacklist, a publicly maintained registry of addresses associated with fraudulent cryptocurrency operations. Inclusion reflects reported user harm or structural characteristics consistent with credential harvesting or asset theft.
- 04No documented operator, registration, or legal entityOperations of this type carry no verifiable corporate identity, no regulatory registration, and no auditable organisational structure. The absence of a recoverable entity removes any legal or contractual recourse for victims once assets have been transferred on-chain.
- 05Credential-harvesting pattern consistent with phishing infrastructureWallet impersonation sites in this category are structurally designed to elicit private keys, seed phrases, or on-chain approvals rather than to provide genuine services. Once any such credential is submitted, the victim's assets are at immediate and irreversible risk regardless of any subsequent action taken.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.