Comment l'arnaque opère.
Le nom de domaine est construit pour évoquer un service de wallet Ethereum majeur, associé à un domaine de premier niveau lié à une entreprise technologique mondialement reconnue. L'effet produit est une présentation de surface qui peut apparaître aux victimes soit comme une intégration de produit officielle, soit comme un partenariat sanctionné entre deux marques de confiance. Le site reproduit vraisemblablement le design visuel d'une interface de wallet légitime, ciblant les utilisateurs qui détiennent ou gèrent des actifs basés sur Ethereum et qui peuvent y accéder via des résultats de recherche, des liens sur les réseaux sociaux ou des e-mails de phishing.
Les sites de ce type fonctionnent comme des interfaces de récolte d'identifiants. Lorsqu'un visiteur tente d'accéder à un wallet ou de l'importer, la plateforme l'invite à fournir une clé privée, une phrase mnémonique de récupération ou un fichier keystore chiffré. Une fois soumis, ces identifiants sont transmis à l'opérateur au lieu d'être traités localement sur l'appareil. L'opérateur utilise ensuite les identifiants capturés pour accéder au wallet de la victime et le vider de manière autonome, généralement en quelques minutes après la soumission et sans aucune autre interaction de la part de la victime.
La fraude devient apparente lorsque la victime tente d'effectuer une transaction et constate que le solde a déjà été transféré vers une adresse inconnue. À ce stade, le transfert est irréversible sur la blockchain. L'opérateur abandonne généralement le domaine après une période de récolte active d'identifiants, ne laissant aucun point de contact fonctionnel, aucun canal d'assistance, et aucun mécanisme permettant à la victime d'engager directement avec la plateforme une quelconque forme de litige ou de recouvrement.
Drapeaux rouges que nous avons documentés.
- 01Domain constructed to mimic a recognised wallet brandThe domain combines a name closely associated with a well-established Ethereum wallet service with a top-level domain tied to a major technology company. This pairing is a deliberate impersonation signal, not an affiliation. No legitimate wallet provider operates under such a domain construction, and neither referenced brand has any documented connection to this property.
- 02Confirmed listing on CryptoScamDB community blacklistThe domain appears on the CryptoScamDB blacklist, a community-maintained repository used by wallet providers and browser security tools to flag known phishing infrastructure. Inclusion reflects reported harm, not merely theoretical risk, and indicates the domain has been reviewed and flagged by the fraud-monitoring community.
- 03No verifiable operator identity or regulatory standingThere is no verifiable company registration, regulatory disclosure, or terms of service associated with this domain. Legitimate wallet services, whether custodial or non-custodial, maintain auditable legal identities. This operation presents none of those attributes, which is consistent with infrastructure designed for short-term exploitation rather than sustained legitimate service.
- 04Credential solicitation is the central operational patternPhishing platforms of this category are built around a single objective: capturing wallet credentials. Any interface that requests a private key, seed phrase, or keystore file outside of a locally-verified, open-source application environment should be treated as a hostile data collection point, regardless of how legitimate the visual presentation appears.
- 05No operational history, community presence, or audit trailThe domain has no documented operational history, independent security audit, or active user community. Operations that carry no verifiable track record and simultaneously appear on fraud databases are consistent with short-lived phishing infrastructure, deployed quickly, exploited, and abandoned before victims can coordinate a response.
Ce que vous pouvez faire maintenant.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.