Cómo opera la estafa.
nnyetherwallet.com se presenta como una interfaz funcional de wallet de Ethereum, construida para imitar a MyEtherWallet, un servicio de wallet de autocustodia ampliamente reconocido. El dominio difiere del servicio genuino por un único prefijo alterado, sustituyendo 'my' por 'nny'. Se trata de una trampa tipográfica deliberada: el sitio está diseñado para interceptar a los usuarios que tecleen mal la dirección legítima o sigan un enlace engañoso, y para resultar indistinguible de la plataforma genuina a primera vista.
La operación pertenece a la categoría de phishing de recolección de credenciales. Por lo general, a los visitantes se les presenta una interfaz de wallet que solicita la introducción de una clave privada, una frase semilla mnemónica o un archivo keystore, aparentemente para acceder a una wallet existente o restaurarla. Estas credenciales son capturadas por el operador en lugar de procesarse localmente. Dado que las claves privadas y las frases semilla otorgan un control incondicional e irrevocable sobre todos los activos asociados en la cadena, el operador puede vaciar las tenencias de la víctima de inmediato y sin ninguna interacción adicional.
El punto de fallo solo se hace evidente después del envío. El acceso a la wallet no se restaura; en cambio, la víctima puede notar que transacciones salientes que no autorizó ya se han confirmado en la cadena. En esta etapa, los fondos suelen haber sido trasladados a direcciones intermedias controladas por el operador. Las transacciones en blockchain son irreversibles, sin mecanismo de contracargo y sin ninguna autoridad administrativa capaz de congelar o recuperar los activos. La recuperación, cuando ocurre, depende del rastreo investigativo y de la colaboración con intercambios o las fuerzas del orden.
Banderas rojas que documentamos.
- 01Typosquat domain targeting a recognised wallet brandThe domain 'nnyetherwallet.com' deviates from MyEtherWallet's address by a single character substitution. This construction is not coincidental. It is engineered to intercept users who make minor typographical errors, placing a malicious interface in the path of traffic intended for a legitimate service.
- 02CryptoScamDB blacklist confirmationThe domain is listed in the CryptoScamDB blacklist, a community-maintained registry of verified fraudulent cryptocurrency sites. Inclusion reflects reported victim activity and analysis of the domain's operational purpose, and constitutes a recognised industry-level fraud signal.
- 03Solicitation of private credentials via web interfaceNo legitimate self-custody wallet service requires users to enter private keys, seed phrases, or keystore files into a browser-based form. Any platform that does so is operating a credential-harvesting interface. This is the defining behavioural signal for this class of fraudulent operation.
- 04Anonymous operator with no regulatory footprintThere is no disclosed business entity, registered operator, or regulatory filing associated with this domain. Operational anonymity is a consistent feature of platforms designed to defraud without accountability, as it forecloses any civil or regulatory avenue for victim recourse.
- 05Immediate and irreversible asset exposure on credential entryOnce private credentials are submitted, the operator holds unconditional access to all associated on-chain assets. Transfers initiated by a malicious holder of these credentials cannot be reversed or intercepted. There is no escrow period, no dispute window, and no custodial protection of any kind.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.