Comment l'arnaque opère.
L'opération se présente comme une interface fonctionnelle de wallet Ethereum. En enregistrant un domaine dont l'encodage Punycode (xn--metherwallet-3ml.com) s'affiche de façon quasi identique à un service de wallet Ethereum largement utilisé dans certains navigateurs, l'opérateur place le site de manière à intercepter le trafic d'utilisateurs qui saisissent mal l'adresse légitime ou qui suivent un lien falsifié. La présentation de surface imite la disposition attendue d'un outil de wallet auto-hébergé, ciblant les détenteurs d'Ether et de jetons ERC-20.
Le mécanisme repose sur une attaque par homographe IDN, une technique dans laquelle un ou plusieurs caractères Unicode remplacent des lettres ASCII visuellement similaires dans un nom de domaine. La barre d'adresse du navigateur peut afficher la forme décodée du domaine, le faisant paraître authentique à un utilisateur qui n'inspecte pas la chaîne Punycode sous-jacente. Les victimes qui accèdent à un wallet ou le restaurent via l'interface sont généralement invitées à saisir une seed phrase ou une clé privée, que l'opérateur capture en temps réel avant la fin de la session.
Le moment de la découverte survient le plus souvent lorsqu'une victime tente de transférer des fonds et constate que son solde a déjà été vidé. Parce que la soumission d'une seed phrase est irréversible et accorde un accès complet à un wallet, la récupération des actifs à ce stade dépend entièrement du traçage forensique au niveau de la blockchain, et non d'une quelconque forme d'annulation directe. Les opérateurs derrière les infrastructures de domaines homographes abandonnent généralement le domaine peu après un cycle de collecte, ne laissant aucun canal d'assistance client, aucune entité enregistrée ni aucun interlocuteur identifiable à poursuivre.
Drapeaux rouges que nous avons documentés.
- 01Punycode prefix signals homograph intentThe xn-- prefix in the domain name is not a formatting quirk; it is the technical marker that this domain contains Unicode characters. Its presence in a wallet-adjacent domain name is a near-universal indicator of a lookalike or impersonation operation rather than a legitimate service.
- 02Listed on CryptoScamDB community blacklistThe domain appears in the CryptoScamDB blacklist, a widely-referenced dataset of confirmed malicious cryptocurrency addresses and URLs maintained through community contribution and ongoing verification. Inclusion is a hard signal, not a probabilistic one.
- 03Seed-phrase solicitation is an absolute loss signalAny web interface requesting a wallet seed phrase or private key operates outside all legitimate norms. No genuine non-custodial wallet service requires this for standard access. Submission to an unverified site constitutes an immediate, total, and irreversible transfer of wallet control to the operator.
- 04No legitimate wallet platform uses IDN homograph domainsEstablished cryptocurrency wallet services do not register their primary interfaces under internationalised domain names that incorporate Unicode lookalike characters. Such registrations have no plausible commercial purpose other than deception.
- 05Disposable infrastructure with no verifiable operatorHomograph-domain operations are low-cost to create and trivial to abandon. No corporate identifiers, regulatory licences, or verifiable operator details are associated with this domain, which is consistent with infrastructure designed for a single harvest cycle rather than a sustainable service.
Ce que vous pouvez faire maintenant.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.