How the scam operates.
etherwallet.online のような運営は、機能的な Ethereum ウォレットのインターフェースを装い、Ethereum エコシステム全体で広く利用されている自己管理型ツールとの見た目および名称上の親近感を悪用します。当該ドメインは、検索結果、ブラウザのオートコンプリート、そしてソーシャルメディア、電子メール、メッセージングプラットフォームを通じて拡散されるフィッシングリンクにおいて、信頼できるものに見えるよう配置されています。表面的な見せ方は通常、正規のウォレットサービスのレイアウトや用語を、ざっと確認した程度では見抜けないほど忠実に模倣しています。
その運用モデルは、認証情報の窃取というパターンに従います。訪問者は、ウォレットへのアクセスや復元のために秘密鍵、キーストアファイル、またはシードフレーズの入力を求められます。これらの認証情報はローカルで処理されるのではなく、運営者が管理するインフラへと送信されます。秘密鍵を入手すると、運営者は対応するアドレスへの取り消し不能なアクセス権を握り、被害者によるそれ以上の操作を要することなく全保有資産を移転できます。この一連の処理は数秒で完了し、被害者には即座に何の兆候も示されません。
欺瞞が明らかになるのは、資金が移動された後になってからです。認証情報を送信した被害者は、多くの場合ページから移動するよりも前に、数分のうちに自身のウォレットが空にされていることに気づきます。暗号資産の取引は仕様上取り消すことができず、また運営者をドメイン登録記録だけから特定できる可能性は低いため、従来型の救済手段は著しく限られます。その後、調査の焦点は、流出した資金の流れを追跡し、当該資産を受け取った取引所やミキシングのインフラを特定することへと移ります。
Red flags we documented.
- 01Domain name mimics established wallet nomenclatureThe domain adopts 'etherwallet' as its core identifier, closely echoing the naming conventions of legitimate self-custody platforms. This pattern is characteristic of typosquatting and brand-impersonation operations designed to capture traffic from users who mistype or misremember a trusted service address.
- 02CryptoScamDB blacklist listingThe domain appears on the CryptoScamDB community blacklist, a collaboratively maintained registry of addresses and domains associated with confirmed or credible fraud. Inclusion indicates the domain has been reviewed and flagged by the wider blockchain security community, not merely auto-detected.
- 03Non-standard top-level domain for a wallet-branded platformLegitimate self-custody interfaces are typically hosted on well-established TLDs. The .online TLD combined with wallet-themed branding is a recurring pattern in phishing infrastructure, where operators register low-cost domains to stand up short-lived fraudulent interfaces before abandoning them.
- 04Private-key solicitation is a critical warning signalLegitimate wallet software processes private keys, seed phrases, and keystore files locally on the user's device. Any web interface that transmits these credentials over a network connection is either fraudulent or fundamentally insecure. Victims who enter credentials into such a form should treat the associated address as compromised immediately.
- 05No verifiable organisational identityOperations of this type carry no company registration, no regulatory disclosure, and no traceable team. The absence of these markers, combined with the blacklist listing and impersonation-style domain, is consistent with infrastructure designed for rapid deployment and abandonment rather than sustained, accountable service provision.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.