Comment l'arnaque opère.
Le domaine reproduit fidèlement le nom associé à une interface de portefeuille Ethereum bien connue, accessible depuis un navigateur. Les opérations de ce type se présentent comme des outils pratiques et accessibles pour gérer des avoirs en Ether et interagir avec des tokens ERC-20, ciblant des utilisateurs déjà familiers du service légitime que le nom de domaine imite. L'extension de domaine de premier niveau peu courante (.abarth, une extension de marque enregistrée appartenant à un constructeur automobile) a peu de chances d'apparaître comme anormale à une victime accédant à un portefeuille dans le cours ordinaire de la gestion de ses actifs cryptographiques.
Le mécanisme opérationnel des domaines de cette catégorie est la récolte d'identifiants. Les utilisateurs se voient présenter une interface qui les invite à saisir une clé privée, une phrase de récupération ou un fichier keystore, sous prétexte d'accéder à un portefeuille ou de le restaurer. L'opérateur capture ces identifiants au lieu de les utiliser pour fournir une véritable fonctionnalité de portefeuille. Comme une clé privée ou une phrase de récupération confère une autorité complète sur le contenu d'un portefeuille, une seule interaction suffit à compromettre l'ensemble des fonds associés, sans qu'aucune implication supplémentaire de la victime ne soit nécessaire.
La découverte n'intervient généralement qu'a posteriori. Les victimes qui saisissent leurs identifiants peuvent ne constater aucun signe immédiat évident de compromission : l'interface peut ne pas se charger, rediriger ailleurs ou afficher une erreur générique. La perte réelle devient apparente lorsque la victime vérifie ensuite son solde sur une plateforme légitime et découvre le portefeuille vidé. À ce stade, le transfert est inscrit sur la blockchain et irréversible. Aucune intervention de l'opérateur, de la victime ou d'un tiers ne peut récupérer les actifs sans la coopération du destinataire, laquelle ne se produit jamais dans les opérations de ce type.
Drapeaux rouges que nous avons documentés.
- 01Wallet Name Impersonation PatternThe domain string reproduces a name strongly associated with an established Ethereum wallet service. This is a recognised pattern in phishing infrastructure: by adopting near-identical naming, the operator exploits trust users have already placed in a legitimate brand, reducing the friction required to induce credential entry.
- 02Atypical Top-Level Domain for Financial InfrastructureGenuine cryptocurrency wallet interfaces are not deployed under brand-specific or novelty top-level domains. Use of an unconventional TLD is consistent with opportunistic registration by operators who cannot secure a convincing match on standard extensions, a common trait in phishing infrastructure.
- 03CryptoScamDB Blacklist InclusionThe domain is recorded in the CryptoScamDB open-source blacklist, a community-maintained registry of cryptocurrency fraud infrastructure. Inclusion indicates the domain was reported and verified against blacklisting criteria. The registry is also integrated into browser security tooling used by some wallet providers.
- 04Credential Entry as Core InteractionAny web-based interface whose primary interaction requires entry of a private key, seed phrase, or keystore file should be treated with extreme scepticism. Reputable wallet infrastructure has moved away from this model precisely because of the exposure it creates; its presence here is a structural signal of credential-harvesting intent.
- 05Absence of Verifiable Organisational FootprintConfirmed-fraudulent domains in this category are invariably operated anonymously, with no registered company, regulatory filing, or identifiable team. The absence of a verifiable legal entity eliminates any avenue for civil recovery or regulatory complaint and leaves victims with no accountable party to whom losses can be attributed.
Ce que vous pouvez faire maintenant.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.