How the scam operates.
Domain xn--mythrwallt-lsicf.com merupakan situs homograf nama domain terinternasionalisasi (internationalised domain name/IDN). Awalan xn-- menandakan bahwa terdapat karakter Unicode yang tertanam dalam bentuk tersandinya, sehingga domain ini ditampilkan secara visual nyaris identik dengan platform wallet mata uang kripto yang dikenal luas di banyak peramban dan aplikasi perpesanan. Operator menyajikan alamat ini sebagai antarmuka wallet yang sah, menyasar para pemegang aset kripto yang tiba melalui tautan phishing, hasil pencarian berbayar, atau kampanye pesan langsung yang dirancang untuk menanamkan rasa mendesak atau meniru komunikasi layanan rutin.
Mekanisme operasionalnya adalah pemanenan (harvesting) kredensial dan seed phrase. Pengunjung yang yakin telah mencapai layanan wallet asli disuguhi permintaan masuk (login) atau alur impor wallet yang meminta kunci privat, frasa pemulihan mnemonik, atau kata sandi akun. Masukan ini ditangkap oleh operator, bukan diproses oleh infrastruktur wallet yang sebenarnya. Situs ini tidak memerlukan back-end blockchain yang berfungsi; tipuan tersebut hanya perlu bertahan cukup lama hingga korban mengirimkan materi sensitif melalui apa yang tampak sebagai antarmuka yang familier.
Penipuan ini biasanya baru terungkap ketika korban berupaya mengakses aset mereka melalui layanan asli dan mendapati saldonya telah dipindahkan. Pada saat ketidaksesuaian itu disadari, aset umumnya telah dipindahkan ke alamat-alamat di luar kendali korban melalui serangkaian lompatan on-chain cepat yang menyulitkan pelacakan. Domain yang dibangun dengan model ini biasanya ditinggalkan atau dirotasi begitu volume keluhan memicu pencantuman dalam daftar hitam, selaras dengan pendekatan infrastruktur sekali pakai yang umum pada operasi phishing jenis ini.
Red flags we documented.
- 01Internationalised Domain Name Homograph TechniqueThe xn-- punycode prefix reveals that the domain encodes Unicode characters designed to produce a display string visually indistinguishable from a legitimate service in standard browsers. This technique is a documented method for defeating users' visual domain verification and is associated almost exclusively with credential-theft operations.
- 02CryptoScamDB Blacklist InclusionThe domain appears in the CryptoScamDB community blacklist, a maintained open-source registry of addresses associated with cryptocurrency fraud. Inclusion indicates the domain has been independently reported and reviewed by contributors to that project.
- 03Seed Phrase Harvesting Operation PatternSites constructed to mimic wallet interfaces have one primary operational purpose: capturing private keys, mnemonic phrases, or login credentials. No legitimate wallet infrastructure solicits a seed phrase through a web form. Any prompt requesting this material on a lookalike domain should be treated as an active theft attempt.
- 04Disposable Infrastructure SignalHomograph phishing domains are typically registered for short operational windows with no traceable corporate presence, no published terms of service, and no verifiable customer support. The absence of any organisational identity is itself a risk indicator, not merely a neutral omission.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.