Cómo opera la estafa.
Esta operación se presenta como una interfaz confiable de wallet de Ethereum, aprovechando el reconocimiento de marca de un servicio de wallet de autocustodia ampliamente conocido. La construcción del dominio imita de cerca la de un servicio legítimo, añadiendo un sufijo no estándar para maximizar la confusión con el nombre y mantener cierta apariencia de plausibilidad. El público objetivo son los tenedores de Ethereum, en particular quienes acceden a un servicio de wallet de memoria o a través de un enlace no verificado.
El patrón de fraude se basa en el typosquatting y la captura de credenciales. A los usuarios que llegan mediante una URL mal escrita, un enlace de phishing o un resultado de búsqueda patrocinado se les presenta una réplica de una interfaz de wallet conocida. El objetivo del operador es capturar la frase semilla o la clave privada del visitante en el momento de su introducción. Una vez enviadas, esas credenciales otorgan al operador un control completo e irreversible sobre la wallet asociada, sin posibilidad de recurso a través de la propia plataforma.
El colapso se hace evidente cuando una víctima intenta acceder a su wallet legítima y descubre que el saldo ha sido transferido a una dirección desconocida. En ese punto, la transacción on-chain es irreversible. El operador habitualmente habrá enrutado los fondos a través de direcciones adicionales para complicar el rastreo. El dominio fraudulento suele retirarse o redirigirse poco después de que se acumulen denuncias en los repositorios públicos de listas negras, dejando escaso rastro operativo que los investigadores puedan seguir.
Banderas rojas que documentamos.
- 01Domain Impersonation PatternThe domain closely replicates the name of a well-established Ethereum wallet service, appending a non-standard suffix. This is a textbook typosquatting construction designed to intercept users who navigate slightly off-course or follow an unverified link, relying entirely on borrowed brand trust rather than any legitimate service offering.
- 02Listed on CryptoScamDB BlacklistThe domain appears in the CryptoScamDB maintained blacklist, a community-verified registry of fraudulent cryptocurrency addresses and domains. Inclusion follows a review process and is used as a primary indicator by wallet providers, browser security extensions, and anti-phishing tools.
- 03Credential Harvesting OperationAny wallet interface that solicits a seed phrase or private key over the internet represents a recognised vector for total, irreversible asset loss. Legitimate self-custody wallet software does not transmit these values to any external server under any circumstances; a platform that does is operating against the user's interests.
- 04No Verifiable Operator IdentityThe operation presents no auditable business registration, no named team, and no regulatory authorisation in any jurisdiction. The absence of accountable ownership is structurally consistent with fraudulent intent and renders post-loss civil or criminal recovery significantly more difficult.
- 05Appended Trust Signal on DomainThe suffix appended to the domain translates as 'safety' or 'security' in Mandarin, a linguistic device sometimes used to reassure users from Chinese-speaking communities or to add an air of legitimacy through a term that appears authoritative to an unfamiliar reader.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.