Cómo opera la estafa.
El dominio está registrado como un nombre de dominio internacionalizado (IDN) mediante el prefijo de codificación punycode xn--, una técnica que hace que ciertos navegadores y herramientas de previsualización de enlaces muestren la dirección como una copia visual casi idéntica de un servicio de wallet de Ethereum de uso generalizado. Para un observador casual que revisa una URL en un mensaje o en un resultado de búsqueda, nada parece estar fuera de lugar. La operación apunta a tenedores de criptomonedas que creen estar accediendo a una interfaz familiar y confiable.
Las víctimas suelen llegar a través de enlaces de phishing difundidos mediante publicaciones en redes sociales, resultados de búsqueda patrocinados o mensajes directos. El sitio presenta una réplica convincente de la interfaz de la wallet suplantada, e invita a los visitantes a introducir su frase mnemónica de recuperación, su clave privada o sus credenciales de acceso. Cualquier dato enviado se transmite al operador en lugar de procesarse localmente. Dado que las frases de recuperación otorgan acceso incondicional a todos los fondos asociados en cualquier dispositivo, una sola captura exitosa basta para vaciar la wallet por completo.
El punto de falla suele descubrirse solo después de que la víctima intenta acceder a sus activos a través del servicio genuino y comprueba que el saldo ha sido transferido. En esa etapa, el operador ya ha movido por lo general los fondos a través de una o más direcciones intermediarias, y el dominio de phishing puede estar ya inactivo o reemplazado. La plataforma no ofrece ningún canal de soporte, ninguna identidad del operador ni mecanismo alguno de disputa o recuperación.
Banderas rojas que documentamos.
- 01Punycode IDN construction signals homograph operationThe xn-- prefix identifies this as an internationalised domain name encoding one or more non-ASCII Unicode characters. This technique is routinely used to register addresses that are visually indistinguishable from trusted domains in browser address bars, link previews, and messaging apps.
- 02No legitimate wallet platform uses punycode addressingEstablished cryptocurrency wallet services operate on plain ASCII domains. A wallet interface accessible only through a punycode address has no credible operational justification, and no legitimate provider directs users to access their funds via such an address.
- 03CryptoScamDB blacklist confirmationThe domain is listed explicitly in the CryptoScamDB community blacklist, a maintained and publicly audited registry of addresses reported in connection with theft and fraud. Independent blacklist inclusion is a reliable signal of confirmed malicious activity.
- 04Seed-phrase harvesting as the operative patternWallet impersonation sites exist for a single purpose: capturing recovery phrases or private keys. Any web-based interface requesting these credentials outside of a locally installed application presents an unacceptable risk, regardless of how the interface appears.
- 05No operator identity or registration transparencyThere are no documented aliases, corporate registrations, regulatory disclosures, or support channels associated with this domain. This absence of verifiable identity is consistent with ephemeral phishing infrastructure designed to be discarded once exposure occurs.
Lo que puedes hacer ahora.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.