Comment l'arnaque opère.
Le site se présente comme un service de wallet Ethereum légitime, empruntant son nom directement à l'une des interfaces de wallet non dépositaire les plus reconnues dans l'univers des cryptomonnaies. Les signaux de la marque sont conçus pour rassurer les utilisateurs habitués au produit authentique, dans l'attente qu'une terminologie familière baisse leur garde. Le public visé est constitué de détenteurs d'Ethereum gérant des wallets en auto-conservation, susceptibles d'arriver via des résultats de recherche, des liens sur les réseaux sociaux ou des messages de phishing pointant vers le domaine.
Les opérations de ce type fonctionnent généralement en présentant une réplique de l'interface qui réclame la clé privée ou la phrase de récupération de l'utilisateur sous prétexte d'accès au compte ou de restauration. Une fois ces données saisies, l'opérateur obtient un contrôle irrévocable du wallet associé. Les transactions Ethereum étant immuables et ne nécessitant aucune autorisation d'un tiers, les fonds peuvent être vidés immédiatement et sans recours. L'usurpation est renforcée par le nom de domaine lui-même, qui reproduit la marque ciblée caractère par caractère avant d'y ajouter un suffixe de domaine de premier niveau fabriqué de toutes pièces.
Le point de rupture devient manifeste lorsque l'utilisateur tente d'accéder à son wallet via le service légitime et constate que ses actifs ont disparu. À ce stade, le site de phishing a généralement cessé de répondre, et aucune coordonnée d'opérateur n'est disponible. Du point de vue du réseau, les identifiants ayant été saisis volontairement, les transactions sur la blockchain n'offrent aucun mécanisme d'annulation. Les victimes se retrouvent avec une preuve du transfert inscrite sur la chaîne, mais sans moyen concret de remonter jusqu'à l'adresse destinataire sans une investigation spécialisée.
Drapeaux rouges que nous avons documentés.
- 01Non-standard domain suffix signals an illegitimate operationThe '.active' top-level domain is not recognised by the Internet Assigned Numbers Authority, which maintains the authoritative registry of valid TLDs. A legitimate wallet service would not operate on a non-standard or fabricated domain extension. This alone is sufficient grounds for immediate suspicion.
- 02Name mimics a recognised Ethereum wallet platformThe domain reproduces the exact name of an established Ethereum wallet interface, differing only in the top-level domain. This pattern, known as brand impersonation or typosquatting, is consistently associated with credential-harvesting operations that rely on users recognising the name without inspecting the full domain.
- 03Listed on the CryptoScamDB blacklistThe domain appears in the CryptoScamDB blacklist, a community-maintained registry of confirmed fraudulent cryptocurrency addresses and domains. Inclusion indicates the site has been reported and verified as malicious by independent reviewers, placing it in confirmed rather than suspected territory.
- 04Credential-entry interface carries irreversible riskAny interface requesting a private key or seed phrase outside of a hardware wallet signing flow should be treated as a hostile surface. There is no legitimate operational reason for a web-based wallet interface to require this information. Entry of these credentials constitutes immediate and total loss of wallet control.
- 05No traceable operator or regulatory registrationNothing in the available record indicates this operation is registered with any financial authority, has a disclosed legal entity, or provides verifiable contact information. The absence of operator transparency is consistent with a disposable phishing asset rather than a legitimate service.
Ce que vous pouvez faire maintenant.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.