Cómo opera la estafa.
El nombre del dominio está construido para evocar un importante servicio de wallet de Ethereum, combinado con un dominio de nivel superior asociado a una empresa de tecnología reconocida a nivel mundial. El efecto es una presentación superficial que puede parecerle a las víctimas como una integración oficial de producto o una alianza autorizada entre dos marcas de confianza. Es probable que el sitio replique el diseño visual de una interfaz de wallet legítima, dirigiéndose a usuarios que poseen o gestionan activos basados en Ethereum y que pueden llegar a través de resultados de búsqueda, enlaces en redes sociales o correos de phishing.
Los sitios de este patrón funcionan como interfaces de captura de credenciales. Cuando un visitante intenta acceder a una wallet o importarla, la plataforma solicita una clave privada, una frase semilla mnemónica o un archivo keystore cifrado. Estas credenciales, una vez enviadas, se transmiten al operador en lugar de procesarse localmente en el dispositivo. El operador utiliza entonces las credenciales capturadas para acceder a la wallet de la víctima y vaciarla de forma autónoma, normalmente en cuestión de minutos tras el envío y sin ninguna otra interacción por parte de la víctima.
El fraude se hace evidente cuando la víctima intenta realizar una transacción y descubre que el saldo ya ha sido trasladado a una dirección desconocida. Para ese momento, la transferencia es irreversible en la cadena. El operador suele abandonar el dominio tras un período de captura activa de credenciales, sin dejar un punto de contacto funcional, ni un canal de soporte, ni ningún mecanismo para que la víctima inicie directamente con la plataforma alguna forma de disputa o recuperación.
Banderas rojas que documentamos.
- 01Domain constructed to mimic a recognised wallet brandThe domain combines a name closely associated with a well-established Ethereum wallet service with a top-level domain tied to a major technology company. This pairing is a deliberate impersonation signal, not an affiliation. No legitimate wallet provider operates under such a domain construction, and neither referenced brand has any documented connection to this property.
- 02Confirmed listing on CryptoScamDB community blacklistThe domain appears on the CryptoScamDB blacklist, a community-maintained repository used by wallet providers and browser security tools to flag known phishing infrastructure. Inclusion reflects reported harm, not merely theoretical risk, and indicates the domain has been reviewed and flagged by the fraud-monitoring community.
- 03No verifiable operator identity or regulatory standingThere is no verifiable company registration, regulatory disclosure, or terms of service associated with this domain. Legitimate wallet services, whether custodial or non-custodial, maintain auditable legal identities. This operation presents none of those attributes, which is consistent with infrastructure designed for short-term exploitation rather than sustained legitimate service.
- 04Credential solicitation is the central operational patternPhishing platforms of this category are built around a single objective: capturing wallet credentials. Any interface that requests a private key, seed phrase, or keystore file outside of a locally-verified, open-source application environment should be treated as a hostile data collection point, regardless of how legitimate the visual presentation appears.
- 05No operational history, community presence, or audit trailThe domain has no documented operational history, independent security audit, or active user community. Operations that carry no verifiable track record and simultaneously appear on fraud databases are consistent with short-lived phishing infrastructure, deployed quickly, exploited, and abandoned before victims can coordinate a response.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.