Cómo opera la estafa.
La operación se presenta como una interfaz legítima de monedero de Ethereum y explota la similitud visual con un servicio de monedero de criptomonedas ampliamente utilizado. Los dos dominios confirmados, myetherwallte.com y myetherwalelt.com, se diferencian del servicio auténtico solo por letras transpuestas o insertadas, diseñados para interceptar a usuarios que escriben mal una dirección conocida. El propósito aparente es replicar la interfaz de un monedero de autocustodia de confianza con la suficiente fidelidad para que un visitante distraído no advierta la sustitución.
El mecanismo subyacente sigue un patrón de phishing bien documentado dirigido a tenedores de criptomonedas. A los visitantes que llegan al sitio, normalmente mediante una URL mal escrita o un resultado de búsqueda manipulado, se les presenta una interfaz de monedero que solicita su clave privada, su frase semilla o sus credenciales de acceso. Una vez enviados esos datos, el operador obtiene acceso completo e irreversible a cualquier monedero asociado. Las transacciones de blockchain no se pueden revertir, de modo que el movimiento de activos desde un monedero comprometido no deja una vía práctica de recuperación por medios convencionales.
El punto de fallo se hace evidente cuando la víctima intenta acceder a su monedero legítimo y comprueba que las credenciales ya no funcionan o que los fondos ya se han movido sin su autorización. Las operaciones que siguen este patrón suelen actuar pocos minutos después de la captura de credenciales, vaciando los monederos antes de que la víctima advierta lo ocurrido. Los intentos posteriores de contacto no producen resultados: la infraestructura suele abandonarse o rotarse una vez que se la señala o una vez que ha pasado por ella un número suficiente de víctimas.
Banderas rojas que documentamos.
- 01Typosquat Domain ArchitectureBoth confirmed domains are deliberate transpositions of a widely-recognised Ethereum wallet service name. The misspellings require no social engineering beyond exploiting routine typing errors, allowing the operation to harvest victims passively from organic navigation mistakes.
- 02Multiple Alias Domains RegisteredThe operation maintains at least two confirmed alias domains, indicating coordinated infrastructure rather than an isolated incident. Multiple domains extend reach and provide redundancy if one address is taken down or blacklisted by browser security tools.
- 03CryptoScamDB Blacklist InclusionBoth domains appear in the CryptoScamDB community blacklist, referenced by wallet providers and browser extensions to block access to known phishing infrastructure. Inclusion across two separate entries reflects confirmed, community-verified evidence of fraudulent activity.
- 04Credential-Harvesting Platform PatternSites impersonating cryptocurrency wallet interfaces serve a single operational purpose: collecting private keys or seed phrases. No legitimate wallet service solicits these credentials through a web form. Any interface doing so should be treated as hostile regardless of its visual presentation.
- 05No Verifiable Operator or Regulatory StandingThe operation presents no identifiable registered entity, public operator, or regulatory licence. Legitimate wallet services maintain public accountability structures. The absence of any such structure is consistent with the disposable infrastructure typical of short-cycle phishing campaigns.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.