Comment l'arnaque opère.
L'opération se présente comme une interface de portefeuille Ethereum, en s'appuyant sur la notoriété d'une plateforme de portefeuille open source largement utilisée. La construction du domaine suit un schéma courant des infrastructures d'usurpation de marque : le nom d'un service connu associé à un élément de domaine inconnu, afin de fabriquer une apparence de légitimité. Le public visé regroupe les utilisateurs de cryptomonnaies qui cherchent à accéder à des actifs basés sur Ethereum, à les gérer ou à les récupérer, en particulier ceux qui arrivent par des résultats de recherche, des liens sur les réseaux sociaux ou des messages de phishing plutôt que par une adresse connue, saisie manuellement.
Les opérations de ce type fonctionnent comme des plateformes de collecte d'identifiants. Les visiteurs voient une interface de portefeuille imitant le design visuel du service usurpé. L'interface sollicite des clés privées ou des phrases mnémoniques de récupération sous prétexte de connexion, d'importation de portefeuille ou de récupération de compte. Une fois ces données soumises, l'opérateur obtient un accès illimité et irrévocable au portefeuille de la victime et à l'ensemble des actifs associés. Aucun service de portefeuille légitime n'exige jamais la saisie d'une phrase de récupération dans une interface web.
Le point de rupture survient lorsque les victimes tentent d'accéder à leurs fonds par un canal légitime et constatent que les actifs ont déjà été transférés vers des adresses contrôlées par l'opérateur. Les transactions sur la blockchain sont irréversibles : il n'existe aucun mécanisme de contestation ni aucune contrepartie à contacter. Le site frauduleux est généralement mis hors ligne quelques jours après le pic d'activité, ne laissant aucune identité vérifiable ni aucun point de contact. Les victimes se retrouvent avec une perte confirmée et une piste forensique qui peut aider les enquêteurs mais permet rarement de récupérer les fonds.
Drapeaux rouges que nous avons documentés.
- 01Brand Impersonation in the Domain NameThe domain replicates the name of a widely recognised Ethereum wallet platform, with an unfamiliar component appended. This construction is a textbook impersonation signal, engineered to exploit name recognition rather than establish any independent credibility.
- 02Confirmed Listing on CryptoScamDB BlacklistThe domain appears in the CryptoScamDB blacklist, a collaboratively maintained registry of confirmed fraudulent cryptocurrency URLs. Inclusion reflects documented evidence of malicious behaviour, not a speculative or automated flag.
- 03Credential Solicitation as the Core MechanicWallet-interface impersonators of this type derive their entire value from the credentials users submit. Any platform requesting a seed phrase, private key, or keystore file outside of a verified, locally installed wallet application should be treated as hostile by default.
- 04Non-Standard Domain Structure Masking the OperatorThe use of an unusual domain construction alongside an established brand name is a recognised pattern in phishing infrastructure. Legitimate extensions of established services operate under the brand's primary, verifiable domain; they do not surface under unrelated alternative registrations.
- 05No Verifiable Operator Identity or DisclosureLegitimate wallet interfaces maintain verifiable corporate identity, open-source repositories, or regulatory disclosures. Operations of this type provide none of these, relying instead on visual similarity to a trusted service to establish false confidence before the credential harvest occurs.
Ce que vous pouvez faire maintenant.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.