Comment l'arnaque opère.
Ce domaine se présente comme une interface web de gestion de portefeuille Ethereum. L'opérateur reproduit l'apparence d'un service de portefeuille de confiance, ciblant les utilisateurs qui arrivent via des liens de phishing, des publicités sosies ou des résultats de recherche faisant remonter le domaine frauduleux avant le domaine légitime. L'expérience de surface est conçue pour être indissociable du véritable service au premier coup d'œil, la tromperie étant intégrée au nom de domaine lui-même.
Le mécanisme repose sur une attaque homographe. L'encodage punycode permet qu'un ou plusieurs caractères du domaine soient tirés d'un jeu de caractères non ASCII tout en s'affichant, dans la plupart des navigateurs, comme une lettre ASCII familière. L'URL paraît identique à celle d'un service de portefeuille reconnu, mais pointe vers un hôte sous le contrôle de l'opérateur. Toute phrase de récupération (seed phrase), clé privée ou identifiant saisi est transmis à l'opérateur. L'interface du portefeuille peut fonctionner normalement pendant un bref instant afin de retarder la détection.
La défaillance devient manifeste lorsque les victimes tentent d'accéder à leurs fonds et constatent que les soldes ont été vidés ou que le site a disparu. À ce stade, toute phrase de récupération saisie a déjà servi à siphonner les portefeuilles associés. Ces opérations ne comportent aucune fonction de support ni aucune identité d'opérateur. Le domaine est un instrument jetable : une fois son utilité épuisée, il est généralement abandonné sans laisser de trace.
Drapeaux rouges que nous avons documentés.
- 01Punycode homograph construction in the domain nameThe xn-- prefix signals a punycode-encoded internationalised domain. A visually identical non-ASCII character substitutes for a standard letter, producing a URL that passes casual inspection but resolves to a host unrelated to the service it mimics. This is a deliberate evasion technique, not a registration accident.
- 02CryptoScamDB blacklist inclusionThe domain is indexed on CryptoScamDB's community-maintained blacklist of confirmed phishing and fraud infrastructure. Inclusion reflects a verified report from the security community, not an automated keyword filter.
- 03Wallet interface clone targeting seed phrase entryPlatforms that replicate wallet interfaces serve one primary purpose: capturing seed phrases or private keys. Any site requesting these inputs that cannot be verified as the canonical service should be treated as hostile. No legitimate wallet service requires a seed phrase entered via a web form.
- 04No verifiable operator or registration signalOperations built on homograph domains carry no regulatory filing, no published company details, and no accountable team. The structural anonymity is intentional; it ensures there is no entity to pursue if funds are lost.
- 05Arrival-path risk: links over direct navigationHomograph phishing relies on victims arriving via a link rather than typing an address. Users who click wallet links from emails, social media, or advertisements are exposed in ways that those who bookmark and type the canonical address directly are not.
Ce que vous pouvez faire maintenant.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.