Comment l'arnaque opère.
L'opération se présente comme une interface légitime de gestion de wallet Ethereum, s'appuyant sur une ressemblance visuelle superficielle avec un service de wallet auto-hébergé largement utilisé. Le nom de domaine, myelherwallel.com, parvient à ce résultat par transposition et substitution systématiques de caractères : « eth » devient « elh » et les dernières lettres de « wallet » sont modifiées. Il en résulte un domaine qui paraît plausible au premier coup d'œil, en particulier lorsqu'un utilisateur y arrive via une URL mal saisie, un lien redirigé ou un résultat de recherche positionné pour intercepter les erreurs de navigation.
Une fois la victime arrivée sur la plateforme, l'interface reproduit généralement l'identité visuelle du service qu'elle imite afin de réduire la méfiance. Les victimes sont invitées à restaurer l'accès à leur wallet en saisissant une phrase de récupération, une clé privée ou une phrase de passe de récupération. Ces identifiants ne servent pas à fournir un accès au wallet : ils sont transmis directement à l'opérateur. La plateforme n'a aucune fonction légitime ; son unique objectif est de capturer les informations nécessaires pour vider les actifs du véritable wallet de la victime.
La fraude ne devient apparente qu'après coup. Comme les identifiants de wallet accordent un accès on-chain irréversible, l'opérateur peut initier des transferts immédiatement ou après un délai délibéré, rompant tout lien apparent avec la session frauduleuse. Au moment où les transferts non autorisés sont identifiés, les actifs ont généralement déjà transité par des adresses intermédiaires. La fenêtre opérationnelle se referme dès que les identifiants sont soumis ; la plateforme peut disparaître ou devenir inaccessible peu après.
Drapeaux rouges que nous avons documentés.
- 01Typosquat construction using deliberate character transpositionThe domain myelherwallel.com reproduces the cadence of a recognised wallet brand through systematic letter-level manipulation, transposing "eth" to "elh" and altering the terminal characters of "wallet." This is a studied construction, not coincidental similarity. Domains engineered in this way serve no purpose other than interception of misdirected users.
- 02Blacklisted by CryptoScamDBThe domain appears in the CryptoScamDB community blacklist, a collaboratively maintained registry of confirmed-fraudulent cryptocurrency sites. Inclusion is a concrete, third-party signal that the domain has been independently identified as malicious and is not a disputed or borderline case.
- 03Seed-phrase entry is an irreversible exposure eventAny platform that requests a wallet seed phrase or private key outside of a locally-installed, verified client is collecting credentials, not providing a service. Entering this information on any web-based interface constitutes full and permanent transfer of control over the associated wallet and all assets held within it.
- 04Single-session operational pattern signals impersonation intentCredential-harvesting operations of this type are architecturally simple and disposable. They require only that a victim submits credentials once; there is no incentive to maintain ongoing engagement or customer support, in contrast to legitimate wallet providers, which depend on sustained user trust and long-term platform integrity.
- 05Domain structure indicates deliberate misdirectionThe gap between myelherwallel.com and the legitimate domain it approximates is not attributable to trademark coincidence. The specific alterations, preserving recognisable syllabic rhythm while evading exact-match detection, are characteristic of domains registered with misdirection as their primary design criterion.
Ce que vous pouvez faire maintenant.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.