How the scam operates.
etherwallet.shop は、広く認知された暗号資産ウォレット・サービスに酷似したドメイン名を利用し、正規のイーサリアム・ウォレット・インターフェースを装っています。同サイトは、その正規サービスを探しているユーザーを、URLの打ち間違い、誤解を招く検索結果、あるいは共有されたリンクを通じて誘い込みます。.shop というトップレベル・ドメインは、本来のウォレット・サービスにとって明らかに不自然な要素ですが、時間に追われた状況でアクセスした被害者は、この食い違いに気づかない場合があります。
この種のサイトに共通する手口は、認証情報の窃取です。来訪者は通常、アカウントの復元やウォレットのインポートを名目として、シードフレーズ、秘密鍵、あるいはログイン認証情報の入力を求めるウォレット・インターフェースを提示されます。一度入力されると、それらの情報は運営者へ送信されます。イーサリアムの秘密鍵およびシードフレーズは、関連する資金に対する取り消し不能かつ無条件の支配権を付与するため、窃取が一度成功するだけでウォレット内の資金が完全に流出するには十分です。
被害が発生する瞬間は通常、即時でありながら目に見えません。被害者は、正規のウォレットから資金が消えていることに気づくまで、異常に気づかない場合があります。その時点では、ブロックチェーン上の取引はすでに取り消し不能であり、運営者は通常、当該ドメインを放棄しています。CryptoScamDB によるブラックリスト登録は、同サイトが脅威インテリジェンス・コミュニティによって特定されたことを裏付けていますが、個々の被害との時間的な前後関係については、利用可能な記録から判断することはできません。
Red flags we documented.
- 01Domain impersonation pattern targeting Ethereum usersThe domain closely mimics the name of a legitimate, widely used Ethereum wallet service. This is a textbook typosquat: close enough to attract misdirected traffic, different enough to be technically distinct. Legitimate wallet services do not register near-identical domains under commercial TLDs such as .shop.
- 02Commercial TLD inconsistent with wallet infrastructureThe .shop suffix has no functional relevance to a self-custody wallet service. Established Ethereum wallet providers use purpose-appropriate or branded domains. The choice of .shop suggests a registration optimised for disposability rather than operational credibility.
- 03CryptoScamDB blacklist entry confirms community-level flaggingThe domain appears in the CryptoScamDB blacklist, a community-maintained dataset used by browser extensions and security tools to warn users before they reach fraudulent sites. Inclusion requires identification by researchers or affected parties, indicating documented harmful activity.
- 04Seed phrase solicitation is an irreversible risk signalSites of this pattern typically request seed phrases or private keys under the guise of wallet import or recovery. No legitimate non-custodial wallet service requires a seed phrase to be entered on a web interface. Any platform making this request should be treated as hostile regardless of its visual presentation.
- 05No documented organisational presence or accountabilityThere are no aliases, registered entities, regulatory filings, or contact structures associated with this domain in available records. Operations lacking any verifiable organisational footprint are structurally designed to avoid accountability after funds are taken.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.