How the scam operates.
Domain ini didaftarkan sebagai nama domain terinternasionalisasi (IDN) menggunakan awalan penyandian punycode xn--, sebuah teknik yang menyebabkan peramban dan perangkat pratinjau tautan tertentu menampilkan alamat tersebut sebagai salinan visual yang nyaris identik dengan layanan dompet Ethereum yang banyak digunakan. Bagi pengamat awam yang sekilas memindai URL dalam sebuah pesan atau hasil pencarian, tidak ada yang tampak ganjil. Operasi ini menyasar pemegang mata uang kripto yang meyakini bahwa mereka sedang menuju ke antarmuka yang familier dan tepercaya.
Korban umumnya tiba melalui tautan phishing yang disebarkan lewat unggahan media sosial, hasil pencarian bersponsor, atau pesan langsung. Situs ini menyajikan replika meyakinkan dari antarmuka dompet yang ditiru, mendorong pengunjung untuk memasukkan frasa pemulihan mnemonik, kunci privat, atau kredensial masuk mereka. Setiap data yang dikirimkan diteruskan kepada operator, bukan diproses secara lokal. Karena frasa pemulihan memberikan akses tanpa syarat ke seluruh dana terkait di setiap perangkat, satu kali penangkapan yang berhasil sudah cukup untuk menguras dompet sepenuhnya.
Titik kegagalan biasanya baru terungkap setelah korban mencoba mengakses asetnya melalui layanan asli dan mendapati saldonya telah dipindahkan. Pada tahap itu, operator biasanya telah memindahkan dana melalui satu atau lebih alamat perantara, dan domain phishing tersebut mungkin sudah tidak aktif atau telah diganti. Platform ini tidak menyediakan saluran dukungan, tidak mengungkap identitas operator, dan tidak memiliki mekanisme apa pun untuk sengketa atau pemulihan.
Red flags we documented.
- 01Punycode IDN construction signals homograph operationThe xn-- prefix identifies this as an internationalised domain name encoding one or more non-ASCII Unicode characters. This technique is routinely used to register addresses that are visually indistinguishable from trusted domains in browser address bars, link previews, and messaging apps.
- 02No legitimate wallet platform uses punycode addressingEstablished cryptocurrency wallet services operate on plain ASCII domains. A wallet interface accessible only through a punycode address has no credible operational justification, and no legitimate provider directs users to access their funds via such an address.
- 03CryptoScamDB blacklist confirmationThe domain is listed explicitly in the CryptoScamDB community blacklist, a maintained and publicly audited registry of addresses reported in connection with theft and fraud. Independent blacklist inclusion is a reliable signal of confirmed malicious activity.
- 04Seed-phrase harvesting as the operative patternWallet impersonation sites exist for a single purpose: capturing recovery phrases or private keys. Any web-based interface requesting these credentials outside of a locally installed application presents an unacceptable risk, regardless of how the interface appears.
- 05No operator identity or registration transparencyThere are no documented aliases, corporate registrations, regulatory disclosures, or support channels associated with this domain. This absence of verifiable identity is consistent with ephemeral phishing infrastructure designed to be discarded once exposure occurs.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.