How the scam operates.
Operasi ini memanfaatkan nama dan identitas yang tampak sah dari sebuah layanan dompet swakelola (self-custody) Ethereum yang dikenal luas. Domain tersebut mencantumkan nama merek yang ditiru hampir sama persis, sehingga situs ini diposisikan untuk menjaring pengunjung yang salah mengetik URL, mengikuti tautan dalam pesan phishing, atau menemukannya melalui hasil pencarian yang dimanipulasi. Domain tingkat atas .airforce adalah satu-satunya penyimpangan yang kentara dari merek yang ditirunya, sebuah detail yang cenderung terlewatkan oleh pengguna awam yang sedang terburu-buru atau sedikit lengah.
Operasi semacam ini menampilkan replika dari antarmuka sasaran dan meminta pengunjung untuk melakukan autentikasi dengan menyerahkan kunci privat (private key), frasa pemulihan (seed phrase), atau berkas keystore. Inilah mekanisme intinya: antarmuka tersebut tidak perlu berfungsi sebagai dompet untuk berhasil. Ia hanya perlu meyakinkan pengguna untuk memasukkan kredensial satu kali saja. Kredensial tersebut dikirimkan kepada operator, yang kemudian dapat mengakses dompet terkait secara mandiri dan pada waktu yang dipilihnya sendiri. Situs ini dapat menyimulasikan keberhasilan login untuk menunda kecurigaan.
Korban biasanya menyadari penipuan ini ketika mereka mendapati saldo dompet mereka terkuras setelah apa yang tampak seperti proses login rutin. Karena transfer di rantai (on-chain) bersifat tidak dapat dibatalkan, rentang waktu antara penyerahan kredensial dan penarikan dana sering kali menjadi satu-satunya titik di mana intervensi secara teoretis masih mungkin dilakukan, dan rentang itu menutup dengan cepat. Pada saat keluhan diajukan, operator biasanya telah memproses dana melalui sejumlah alamat tambahan, dan infrastruktur phishing itu sendiri mungkin telah dinonaktifkan atau dipindahkan ke domain baru.
Red flags we documented.
- 01Brand impersonation in the domain nameThe domain reproduces the name of a legitimate, well-established Ethereum wallet service with no meaningful alteration. This is a deliberate tactic: the closer a fraudulent domain sits to a trusted name, the less cognitive effort a victim needs to expend to accept it as genuine.
- 02Anomalous top-level domain for a financial interfaceLegitimate cryptocurrency wallet services operate under conventional TLDs. The use of .airforce for what purports to be a wallet interface has no plausible commercial rationale and is a recognised marker of opportunistic phishing infrastructure assembled quickly and cheaply.
- 03CryptoScamDB blacklist inclusionThe domain appears on the CryptoScamDB community blacklist, a collaboratively maintained register of confirmed malicious cryptocurrency addresses and domains. Inclusion indicates the site has been independently identified as a threat by researchers outside CryptoLeek.
- 04Credential-request pattern inconsistent with legitimate wallet operationAny web-based interface that requests a private key or seed phrase to grant wallet access is operating outside the security model of self-custody. Legitimate wallet interfaces of the type being impersonated here do not require server-side submission of these credentials under any normal circumstances.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.