How the scam operates.
Operasi seperti etherwallet.online menampilkan dirinya sebagai antarmuka wallet Ethereum yang fungsional, memanfaatkan kemiripan visual dan penamaan dengan perkakas self-custody yang banyak digunakan di seluruh ekosistem Ethereum. Domain ini diposisikan agar tampak kredibel dalam hasil pencarian, pelengkapan otomatis peramban, dan tautan phishing yang disebarkan melalui media sosial, surel, atau platform perpesanan. Tampilan permukaannya umumnya meniru tata letak dan terminologi layanan wallet yang sah secara cukup mirip untuk lolos dari pemeriksaan sepintas.
Model operasinya mengikuti pola pemanenan kredensial. Pengunjung diminta memasukkan private key, file keystore, atau seed phrase untuk mengakses atau memulihkan sebuah wallet. Kredensial ini dikirimkan ke infrastruktur yang dikendalikan operator, bukan diproses secara lokal. Begitu menguasai sebuah private key, operator memegang akses yang tidak dapat dicabut atas alamat terkait dan dapat memindahkan seluruh kepemilikan tanpa tindakan lebih lanjut dari korban. Prosesnya selesai dalam hitungan detik, tanpa sinyal langsung kepada korban.
Tipuan ini baru tampak setelah dana dipindahkan. Korban yang menyerahkan kredensial mendapati wallet mereka terkuras dalam beberapa menit, sering kali sebelum mereka beranjak dari halaman tersebut. Karena transaksi mata uang kripto secara rancangan bersifat tidak dapat dibalik, dan operator kemungkinan besar tidak dapat diidentifikasi hanya dari catatan registrasi domain, upaya pemulihan konvensional sangat terbatas. Fokus investigasi kemudian beralih ke penelusuran aliran dana keluar dan pengidentifikasian infrastruktur exchange atau mixing yang menerima aset tersebut.
Red flags we documented.
- 01Domain name mimics established wallet nomenclatureThe domain adopts 'etherwallet' as its core identifier, closely echoing the naming conventions of legitimate self-custody platforms. This pattern is characteristic of typosquatting and brand-impersonation operations designed to capture traffic from users who mistype or misremember a trusted service address.
- 02CryptoScamDB blacklist listingThe domain appears on the CryptoScamDB community blacklist, a collaboratively maintained registry of addresses and domains associated with confirmed or credible fraud. Inclusion indicates the domain has been reviewed and flagged by the wider blockchain security community, not merely auto-detected.
- 03Non-standard top-level domain for a wallet-branded platformLegitimate self-custody interfaces are typically hosted on well-established TLDs. The .online TLD combined with wallet-themed branding is a recurring pattern in phishing infrastructure, where operators register low-cost domains to stand up short-lived fraudulent interfaces before abandoning them.
- 04Private-key solicitation is a critical warning signalLegitimate wallet software processes private keys, seed phrases, and keystore files locally on the user's device. Any web interface that transmits these credentials over a network connection is either fraudulent or fundamentally insecure. Victims who enter credentials into such a form should treat the associated address as compromised immediately.
- 05No verifiable organisational identityOperations of this type carry no company registration, no regulatory disclosure, and no traceable team. The absence of these markers, combined with the blacklist listing and impersonation-style domain, is consistent with infrastructure designed for rapid deployment and abandonment rather than sustained, accountable service provision.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.