Cómo opera la estafa.
Este dominio utiliza el sistema de nombres de dominio internacionalizados (IDN) basado en Punycode para construir una dirección web que, en la mayoría de los navegadores, se ve visualmente idéntica a un conocido servicio de billetera de Ethereum. El dominio subyacente, una vez decodificado, contiene una sustitución de caracteres invisible a simple vista en la barra de direcciones. El operador presenta el sitio como una plataforma de billetera de autocustodia confiable, posicionada para interceptar a los usuarios que llegan a través de una URL mal escrita, un resultado de búsqueda o un enlace de phishing compartido.
El modelo operativo es la recolección de credenciales. A los visitantes se les suele presentar una interfaz que replica un flujo de inicio de sesión o de recuperación de billetera, solicitando una frase semilla, una clave privada o un archivo keystore. Estos tres datos representan los únicos mecanismos que otorgan control total sobre una billetera de criptomonedas. Una vez enviada, la información se transmite al operador, momento en el cual los fondos de la víctima quedan accesibles sin necesidad de ninguna otra interacción. El ataque no requiere malware y no deja rastro en el dispositivo de la víctima.
El colapso suele estar retrasado de manera intencional. Algunas implementaciones redirigen a las víctimas al servicio genuino después de capturar las credenciales, manteniendo la ilusión de una sesión normal. Es posible que los usuarios no se den cuenta de que algo anda mal hasta que intentan realizar una transacción y descubren que su saldo está agotado. Para ese momento, los fondos suelen haberse movido a través de una o más direcciones intermedias, y el rastro en la cadena se enfría con rapidez. No existe ningún mecanismo para revertir la transferencia; la recuperación depende de la detección temprana y del rastreo investigativo de las billeteras de destino.
Banderas rojas que documentamos.
- 01IDN Homograph Domain PatternThe xn-- Punycode prefix indicates this domain contains a Unicode character substitution designed to mimic a legitimate wallet address. This is a recognised attack technique against cryptocurrency users; no genuine wallet service registers its primary domain in this encoding.
- 02CryptoScamDB Blacklist InclusionThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained registry of phishing infrastructure. Inclusion follows community review and indicates the domain has been verified as fraudulent by independent researchers.
- 03Seed Phrase Solicitation SignalWallet impersonation platforms of this type invariably request recovery phrases or private keys. No legitimate self-custody wallet requires a user to submit a seed phrase through a web interface to access an existing wallet. Any platform making this request should be treated as hostile.
- 04No Verifiable Operator IdentityThere is no documented corporate registration, regulatory standing, or named operator behind this domain. Legitimate wallet services, whether custodial or non-custodial, maintain transparent organisational identity and are reachable through official channels.
- 05Irreversible Loss ExposureCredential theft of this kind results in on-chain fund transfers that cannot be reversed or disputed. Unlike bank fraud, there is no institutional recourse. Recovery depends entirely on early detection and, in some cases, investigative tracing of destination addresses.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.