Comment l'arnaque opère.
Cette opération se présente comme une interface de wallet Ethereum digne de confiance, en exploitant la notoriété d'une marque de wallet auto-hébergé largement reconnue. La construction du domaine reproduit étroitement celle d'un service légitime, en ajoutant un suffixe non standard afin de maximiser la confusion avec le nom tout en préservant une apparence de déni plausible. Le public visé est constitué de détenteurs d'Ethereum, en particulier ceux qui accèdent à un service de wallet de mémoire ou par l'intermédiaire d'un lien non vérifié.
Le schéma de fraude repose sur le typosquatting et la récolte d'identifiants. Les utilisateurs qui arrivent via une URL mal saisie, un lien de phishing ou un résultat de recherche sponsorisé se voient présenter une réplique d'une interface de wallet familière. L'objectif de l'opérateur est de capturer la phrase de récupération ou la clé privée du visiteur au moment de la saisie. Une fois soumis, ces identifiants confèrent à l'opérateur un contrôle complet et irréversible sur le wallet associé, sans aucun recours possible auprès de la plateforme elle-même.
La défaillance devient manifeste lorsqu'une victime tente d'accéder à son wallet légitime et constate que le solde a été transféré vers une adresse non reconnue. À ce stade, la transaction enregistrée sur la blockchain est irréversible. L'opérateur aura généralement fait transiter les fonds par des adresses supplémentaires afin de compliquer le traçage. Le domaine frauduleux est souvent mis hors ligne ou redirigé peu après l'accumulation de plaintes dans les répertoires publics de listes noires, ne laissant que peu de traces opérationnelles à exploiter pour les enquêteurs.
Drapeaux rouges que nous avons documentés.
- 01Domain Impersonation PatternThe domain closely replicates the name of a well-established Ethereum wallet service, appending a non-standard suffix. This is a textbook typosquatting construction designed to intercept users who navigate slightly off-course or follow an unverified link, relying entirely on borrowed brand trust rather than any legitimate service offering.
- 02Listed on CryptoScamDB BlacklistThe domain appears in the CryptoScamDB maintained blacklist, a community-verified registry of fraudulent cryptocurrency addresses and domains. Inclusion follows a review process and is used as a primary indicator by wallet providers, browser security extensions, and anti-phishing tools.
- 03Credential Harvesting OperationAny wallet interface that solicits a seed phrase or private key over the internet represents a recognised vector for total, irreversible asset loss. Legitimate self-custody wallet software does not transmit these values to any external server under any circumstances; a platform that does is operating against the user's interests.
- 04No Verifiable Operator IdentityThe operation presents no auditable business registration, no named team, and no regulatory authorisation in any jurisdiction. The absence of accountable ownership is structurally consistent with fraudulent intent and renders post-loss civil or criminal recovery significantly more difficult.
- 05Appended Trust Signal on DomainThe suffix appended to the domain translates as 'safety' or 'security' in Mandarin, a linguistic device sometimes used to reassure users from Chinese-speaking communities or to add an air of legitimacy through a term that appears authoritative to an unfamiliar reader.
Ce que vous pouvez faire maintenant.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.