Comment l'arnaque opère.
Cette opération se présente comme une interface légitime de wallet Ethereum, en reproduisant délibérément le nom et la fonctionnalité implicite d'un service de wallet crypto largement utilisé et reconnu par la communauté. La construction du domaine associe une marque de wallet identifiable au domaine de premier niveau ".amex", un TLD de marque rattaché à American Express, afin de donner une impression de crédibilité institutionnelle. Le public visé est constitué d'utilisateurs Ethereum cherchant à accéder à leurs wallets en ligne, à les importer ou à les gérer.
La méthode opérationnelle caractéristique de cette catégorie de fraude est la collecte d'identifiants. Loin de fonctionner comme une véritable interface de wallet, le site est conçu pour intercepter les clés privées, les phrases de récupération (seed phrases) ou les fichiers keystore soumis par les utilisateurs au cours d'un processus simulé de connexion ou d'importation de wallet. Une fois les identifiants saisis, l'opérateur acquiert un contrôle unilatéral sur l'ensemble des adresses de wallet associées. Les fonds détenus sur ces adresses peuvent être transférés vers des adresses contrôlées par l'opérateur, sans aucun recours possible pour la victime.
La défaillance devient généralement apparente dans les heures ou les jours qui suivent la saisie des identifiants, lorsque les victimes constatent des transactions sortantes non autorisées depuis des wallets qu'elles n'ont pas initiées. Au moment où la perte est identifiée, l'opérateur a déjà fait transiter les actifs par une ou plusieurs adresses intermédiaires. Le domaine n'offre aucun canal d'assistance légitime, aucune identité d'entreprise vérifiable et aucun mécanisme de récupération. Les victimes se retrouvent avec une trace immuable du vol inscrite sur la blockchain, mais sans contrepartie identifiable contre qui agir.
Drapeaux rouges que nous avons documentés.
- 01Brand-name impersonation in the domainThe domain reproduces the name of a well-established Ethereum wallet service almost exactly, a classic impersonation technique designed to intercept users who mistype a URL or follow a fraudulent link. This pattern is consistently associated with credential-harvesting operations rather than legitimate services.
- 02Unauthorised use of a corporate brand TLDThe ".amex" top-level domain is a sponsored TLD associated with American Express. Its use here is almost certainly unauthorised and is engineered to project institutional backing. Legitimate wallet services do not operate under third-party corporate brand TLDs.
- 03CryptoScamDB blacklist listing confirmedThe domain appears explicitly in the CryptoScamDB community blacklist, a collaboratively maintained register of URLs and addresses linked to crypto fraud. Blacklist inclusion reflects prior evidence of malicious activity reported by independent researchers or affected users.
- 04No verifiable operator identityOperations of this type consistently omit any verifiable corporate registration, regulatory disclosure, or named personnel. The absence of an auditable organisational identity is a strong signal that accountability has been deliberately engineered out of the operation.
- 05Credential input as the core interactionAny platform that requests a private key, seed phrase, or keystore file in order to access or import a wallet is, by design, collecting credentials it has no legitimate need to see. A genuine non-custodial wallet interface never requires these materials to be transmitted to a remote server.
Ce que vous pouvez faire maintenant.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.