Comment l'arnaque opère.
nnyetherwallet.com se présente comme une interface de wallet Ethereum fonctionnelle, conçue pour imiter MyEtherWallet, un service de wallet auto-hébergé largement reconnu. Le domaine ne diffère du service authentique que par un préfixe modifié, substituant « nny » à « my ». Il s'agit d'un piège typographique délibéré : le site est conçu pour intercepter les utilisateurs qui saisissent incorrectement l'adresse légitime ou suivent un lien trompeur, et pour paraître indiscernable de la plateforme authentique au premier coup d'œil.
L'opération relève de la catégorie du phishing par collecte d'identifiants. Les visiteurs se voient généralement présenter une interface de wallet qui invite à saisir une clé privée, une phrase de récupération mnémonique ou un fichier keystore, prétendument pour accéder à un wallet existant ou le restaurer. Ces identifiants sont captés par l'opérateur plutôt que traités localement. Parce que les clés privées et les phrases de récupération confèrent un contrôle inconditionnel et irrévocable sur l'ensemble des actifs on-chain associés, l'opérateur peut vider les avoirs de la victime immédiatement et sans autre interaction.
Le point de défaillance n'apparaît qu'après la soumission. L'accès au wallet n'est pas restauré ; au contraire, la victime peut constater que des transactions sortantes qu'elle n'a pas autorisées ont déjà été validées on-chain. À ce stade, les fonds ont généralement été déplacés vers des adresses intermédiaires contrôlées par l'opérateur. Les transactions blockchain sont irréversibles, sans mécanisme de rétrofacturation ni autorité administrative en mesure de geler ou de récupérer les actifs. La récupération, lorsqu'elle a lieu, dépend du traçage d'enquête et de la coopération avec les plateformes d'échange ou les forces de l'ordre.
Drapeaux rouges que nous avons documentés.
- 01Typosquat domain targeting a recognised wallet brandThe domain 'nnyetherwallet.com' deviates from MyEtherWallet's address by a single character substitution. This construction is not coincidental. It is engineered to intercept users who make minor typographical errors, placing a malicious interface in the path of traffic intended for a legitimate service.
- 02CryptoScamDB blacklist confirmationThe domain is listed in the CryptoScamDB blacklist, a community-maintained registry of verified fraudulent cryptocurrency sites. Inclusion reflects reported victim activity and analysis of the domain's operational purpose, and constitutes a recognised industry-level fraud signal.
- 03Solicitation of private credentials via web interfaceNo legitimate self-custody wallet service requires users to enter private keys, seed phrases, or keystore files into a browser-based form. Any platform that does so is operating a credential-harvesting interface. This is the defining behavioural signal for this class of fraudulent operation.
- 04Anonymous operator with no regulatory footprintThere is no disclosed business entity, registered operator, or regulatory filing associated with this domain. Operational anonymity is a consistent feature of platforms designed to defraud without accountability, as it forecloses any civil or regulatory avenue for victim recourse.
- 05Immediate and irreversible asset exposure on credential entryOnce private credentials are submitted, the operator holds unconditional access to all associated on-chain assets. Transfers initiated by a malicious holder of these credentials cannot be reversed or intercepted. There is no escrow period, no dispute window, and no custodial protection of any kind.
Ce que vous pouvez faire maintenant.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.